Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 8.8
CVE-2021-24179
The Business Directory Plugin – Easy Listing Directories for WordPress WordPress plugin before 5.11 suffered from a Cross-Site Request Forgery issue,…
Business Directory Plugin Easy Listing Directories
5.11+
MEDIUM 6.5
CVE-2021-24249
The Business Directory Plugin – Easy Listing Directories for WordPress WordPress plugin before 5.11.2 suffered from a Cross-Site Request Forgery issu…
Business Directory Plugin Easy Listing Directories
5.11.2+
HIGH 8.8
CVE-2020-23127
Chamilo LMS 1.11.10 is affected by Cross Site Request Forgery (CSRF) via the edit_user function by targeting an admin user.
Chamilo Lms
Patch available
HIGH 8.8
CVE-2020-36334
themegrill-demo-importer before 1.6.3 allows CSRF, as demonstrated by wiping the database.
Themegrill Demo Importer
1.6.3+
HIGH 8.8
CVE-2021-29238
CODESYS Automation Server before 1.16.0 allows cross-site request forgery (CSRF).
Automation Server
1.16.0+
HIGH 8.8
CVE-2021-30224
Cross Site Request Forgery (CSRF) in Rukovoditel v2.8.3 allows attackers to create an admin user with an arbitrary credentials.
Rukovoditel
Patch available
MEDIUM 6.1
CVE-2021-28280
CSRF + Cross-site scripting (XSS) vulnerability in search.php in PHPFusion 9.03.110 allows remote attackers to inject arbitrary web script or HTML
Phpfusion
Patch available
HIGH 8.8
CVE-2020-21989
HomeAutomation 3.3.2 is affected by Cross Site Request Forgery (CSRF). The application interface allows users to perform certain actions via HTTP req…
Homeautomation
No fix yet
HIGH 8.0
CVE-2020-22000
HomeAutomation 3.3.2 suffers from an authenticated OS command execution vulnerability using custom command v0.1 plugin. This can be exploited with a …
Homeautomation
No fix yet
HIGH 8.8
CVE-2021-31760EPSS 8%
Webmin 1.973 is affected by Cross Site Request Forgery (CSRF) to achieve Remote Command Execution (RCE) through Webmin's running process feature.
Webmin
No fix yet
HIGH 8.8
CVE-2021-31762EPSS 9%
Webmin 1.973 is affected by Cross Site Request Forgery (CSRF) to create a privileged user through Webmin's add users feature, and then get a reverse …
Webmin
No fix yet
HIGH 8.8
CVE-2021-31584
Sipwise C5 NGCP www_csc version 3.6.4 up to and including platform NGCP CE mr3.8.13 allows call/click2dial CSRF attacks for actions with administrati…
Next Generation Communication Platform
No fix yet
MEDIUM 5.4
CVE-2021-21644
A cross-site request forgery (CSRF) vulnerability in Jenkins Config File Provider Plugin 3.7.0 and earlier allows attackers to delete configuration f…
Config File Provider
after 3.7.0
HIGH 8.8
CVE-2021-27181
An issue was discovered in MDaemon before 20.0.4. Remote Administration allows an attacker to perform a fixation of the anti-CSRF token. In order to …
Mdaemon
20.0.4+
HIGH 8.8
CVE-2021-31152
Multilaser Router AC1200 V02.03.01.45_pt contains a cross-site request forgery (CSRF) vulnerability. An attacker can enable remote access, change pas…
Ac1200 Re018 Firmware
No fix yet
HIGH 8.1
CVE-2021-29436
Anuko Time Tracker is an open source, web-based time tracking application written in PHP. In Time Tracker before version 1.19.27.5431 a Cross site re…
Time Tracker
1.19.27.5431+
MEDIUM 6.5
CVE-2021-29435
trestle-auth is an authentication plugin for the Trestle admin framework. A vulnerability in trestle-auth versions 0.4.0 and 0.4.1 allows an attacker…
Trestle Auth
Patch available
MEDIUM 6.5
CVE-2021-21729
Some ZTE products have CSRF vulnerability. Because some pages lack CSRF random value verification, attackers could perform illegal authorization oper…
Zxhn H168n Firmware
Mitigation only
HIGH 8.1
CVE-2021-21731
A CSRF vulnerability exists in the management page of a ZTE product.The vulnerability is caused because the management page does not fully verify whe…
Zxcloud Irai
6.03.04+
HIGH 8.8
CVE-2021-29054
Certain Papoo products are affected by: Cross Site Request Forgery (CSRF) in the admin interface. This affects Papoo CMS Light through 21.02 and Papo…
Papoo
after 21.02
HIGH 8.1
CVE-2021-24230
The Jetpack Scan team identified a Cross-Site Request Forgery vulnerability in the Patreon WordPress plugin before 1.7.0, allowing attackers to make …
Patreon Wordpress
1.7.0+
MEDIUM 6.5
CVE-2021-24231
The Jetpack Scan team identified a Cross-Site Request Forgery vulnerability in the Patreon WordPress plugin before 1.7.0, allowing attackers to make …
Patreon Wordpress
1.7.0+
HIGH 8.8
CVE-2021-24218
The wp_ajax_save_fbe_settings and wp_ajax_delete_fbe_settings AJAX actions of the Facebook for WordPress plugin before 3.0.4 were vulnerable to CSRF …
Facebook
3.0.4+
HIGH 8.8
CVE-2020-21884
Unibox SMB 2.4 and UniBox Enterprise Series 2.4 and UniBox Campus Series 2.4 contain a cross-site request forgery (CSRF) vulnerability in /tools/netw…
Unibox U50 Firmware
Mitigation only
MEDIUM 5.4
CVE-2021-25326
Skyworth Digital Technology RN510 V.3.1.0.4 is affected by an incorrect access control vulnerability in/cgi-bin/test_version.asp. If Wi-Fi is connect…
Rn510 Firmware
No fix yet
MEDIUM 6.5
CVE-2021-25327
Skyworth Digital Technology RN510 V.3.1.0.4 contains a cross-site request forgery (CSRF) vulnerability in /cgi-bin/net-routeadd.asp and /cgi-bin/sec-…
Rn510 Firmware
No fix yet
MEDIUM 6.5
CVE-2021-22512
Cross-Site Request Forgery (CSRF) vulnerability in Micro Focus Application Automation Tools Plugin - Jenkins plugin. The vulnerability affects versio…
Application Automation Tools
after 6.7
CRITICAL 9.8
CVE-2020-23426
zzcms 201910 contains an access control vulnerability through escalation of privileges in /user/adv.php, which allows an attacker to modify data for …
Zzcms
No fix yet
MEDIUM 6.5
CVE-2021-30112
Web-School ERP V 5.0 contains a cross-site request forgery (CSRF) vulnerability that allows a remote attacker to create a student_leave_application r…
Enterprise Resource Planning
No fix yet
MEDIUM 6.5
CVE-2021-30114
Web-School ERP V 5.0 contains a cross-site request forgery (CSRF) vulnerability that allows a remote attacker to create a voucher payment request thr…
Enterprise Resource Planning
No fix yet