Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 8.1
CVE-2021-38342
The Nested Pages WordPress plugin <= 3.1.15 was vulnerable to Cross-Site Request Forgery via the `npBulkAction`s and `npBulkEdit` `admin_post` action…
Nested Pages
after 3.1.15
MEDIUM 6.5
CVE-2020-18123
A cross-site request forgery (CSRF) vulnerability in Indexhibit 2.1.5 allows attackers to arbitrarily delete admin accounts.
Indexhibit
No fix yet
MEDIUM 5.7
CVE-2020-18124
A cross-site request forgery (CSRF) vulnerability in Indexhibit 2.1.5 allows attackers to arbitrarily reset account passwords.
Indexhibit
No fix yet
HIGH 8.8
CVE-2021-24581
The Blue Admin WordPress plugin through 21.06.01 does not sanitise or escape its "Logo Title" setting before outputting in a page, leading to a Store…
Blue Admin
after 21.06.01
HIGH 8.8
CVE-2021-40172
Zoho ManageEngine Log360 before Build 5219 allows a CSRF attack on proxy settings.
Manageengine Log360
after 5.1
HIGH 8.8
CVE-2021-40173
Zoho ManageEngine Cloud Security Plus before Build 4117 allows a CSRF attack on the server proxy settings.
Manageengine Cloud Security Plus
after 4.0
HIGH 8.8
CVE-2021-40174
Zoho ManageEngine Log360 before Build 5224 allows a CSRF attack for disabling the logon security settings.
Manageengine Log360
after 5.1
HIGH 8.8
CVE-2021-3734
yourls is vulnerable to Improper Restriction of Rendered UI Layers or Frames
Yourls
after 1.8.1
HIGH 8.8
CVE-2020-18917
The plus/search.php component in DedeCMS 5.7 SP2 allows remote attackers to execute arbitrary PHP code via the typename parameter because the content…
Dedecms
No fix yet
HIGH 8.8
CVE-2021-23431
The package joplin before 2.3.2 are vulnerable to Cross-site Request Forgery (CSRF) due to missing CSRF checks in various forms.
Joplin
2.3.2+
MEDIUM 6.5
CVE-2021-3728
firefly-iii is vulnerable to Cross-Site Request Forgery (CSRF)
Firefly Iii
Patch available
MEDIUM 6.5
CVE-2021-3730
firefly-iii is vulnerable to Cross-Site Request Forgery (CSRF)
Firefly Iii
Patch available
HIGH 8.8
CVE-2021-24565
The Contact Form 7 Captcha WordPress plugin before 0.0.9 does not have any CSRF check in place when saving its settings, allowing attacker to make a …
Contact Form 7 Captcha
0.0.9+
HIGH 8.8
CVE-2021-24555
The daac_delete_booking_callback function, hooked to the daac_delete_booking AJAX action, takes the id POST parameter which is passed into the SQL st…
Diary Availability Calendar
after 1.0.3
MEDIUM 6.5
CVE-2021-39243
Cross-Site Request Forgery (CSRF) exists on Altus Nexto, Nexto Xpress, and Hadron Xtorm devices via any CGI endpoint. This affects Nexto NX3003 1.8.1…
Nexto Nx3003 Firmware
No fix yet
HIGH 8.1
CVE-2020-24130
A cross site request forgery (CSRF) vulnerability in the configure.html component of Ponzu 0.11.0 allows attackers to change user and administrator c…
Ponzu
No fix yet
HIGH 8.8
CVE-2020-20642
Cross Site Request Forgery (CSRF) vulnerability exists in EyouCMS 1.3.6 that can add an htm page to execute the js code via login.php?m=admin&c=Filem…
Eyoucms
No fix yet
HIGH 8.8
CVE-2021-28490
In OWASP CSRFGuard through 3.1.0, CSRF can occur because the CSRF cookie may be retrieved by using only a session token.
Csrfguard
after 3.1.0
HIGH 8.8
CVE-2021-34645
The Shopping Cart & eCommerce Store WordPress plugin is vulnerable to Cross-Site Request Forgery via the save_currency_settings function found in the…
Shopping Cart \& Ecommerce Store
after 5.1.0
HIGH 8.8
CVE-2020-19669
Cross Site Request Forgery (CSRF) vulnerability exists in Eyoucms 1.3.6 that can add an admin account via /login.php?m=admin&c=Admin&a=admin_add&lang…
Eyoucms
No fix yet
HIGH 8.0
CVE-2021-20758
Cross-site request forgery (CSRF) vulnerability in Message of Cybozu Garoon 4.0.0 to 5.0.2 allows a remote authenticated attacker to hijack the authe…
Garoon
after 5.0.2
MEDIUM 6.5
CVE-2020-28846
Cross Site Request Forgery (CSRF) vulnerability exists in SeaCMS 10.7 in admin_manager.php, which could let a malicious user add an admin account.
Seacms
No fix yet
MEDIUM 6.5
CVE-2020-4992
IBM DataPower Gateway 2018.4.1.0 through 2018.4.1.16 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious a…
Datapower Gateway
after 2018.4.1.16
MEDIUM 6.1
CVE-2021-24536
The Custom Login Redirect WordPress plugin through 1.0.0 does not have CSRF check in place when saving its settings, and do not sanitise or escape us…
Custom Login Redirect
after 1.0.0
MEDIUM 6.1
CVE-2021-24410
The తెలుగు బైబిల్ వచనములు WordPress plugin through 1.0 is lacking any CSRF check when saving its settings and verses, and do not sanitise or escape t…
Telugu Bible Verse Daily
after 1.0
MEDIUM 6.1
CVE-2021-24411
The Social Tape WordPress plugin through 1.0 does not have CSRF checks in place when saving its settings, and do not sanitise or escape them before o…
Social Tape
after 1.0
MEDIUM 6.1
CVE-2021-24466
The Verse-O-Matic WordPress plugin through 4.1.1 does not have any CSRF checks in place, allowing attackers to make logged in administrators do unwan…
Verse O Matic
after 4.1.1
MEDIUM 6.1
CVE-2021-24535
The Light Messages WordPress plugin through 1.0 is lacking CSRF check when updating it's settings, and is not sanitising its Message Content in them …
Light Messages
after 1.0
HIGH 8.8
CVE-2020-22403
Cross Site Request Forgery (CSRF) vulnerability in Express cart v1.1.16 allows attackers to add an administrator account, add discount code or other …
Express Cart
after 1.1.10
HIGH 8.0
CVE-2020-18458
Cross Site Request Forgery (CSRF) vulnerability exists in DamiCMS v6.0.6 that can add an admin account via admin.php?s=/Admin/doadd.
Damicms
No fix yet