Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 5.4
CVE-2019-14481
AdRem NetCrunch 10.6.0.4587 has a Cross-Site Request Forgery (CSRF) vulnerability in the NetCrunch web client. Successful exploitation requires a log…
Netcrunch
No fix yet
HIGH 8.8
CVE-2020-25622
An issue was discovered in SolarWinds N-Central 12.3.0.670. The AdvancedScripts HTTP endpoint allows CSRF.
N Central
Mitigation only
HIGH 7.1
CVE-2020-14368
A flaw was found in Eclipse Che in versions prior to 7.14.0 that impacts CodeReady Workspaces. When configured with cookies authentication, Theia IDE…
Che
7.14.0+
HIGH 8.8
CVE-2019-19289
A vulnerability has been identified in XHQ (All Versions < 6.1). The web interface could allow a Cross-Site Request Forgery (CSRF) attack if an unsus…
Xhq
6.1.0.0+
HIGH 8.8
CVE-2020-8282
A security issue was found in EdgePower 24V/54V firmware v1.7.0 and earlier where, due to missing CSRF protections, an attacker would have been able …
Edgemax Edgepower 24v Firmware
after 1.7.0
HIGH 8.8
CVE-2020-28858
OpenAsset Digital Asset Management (DAM) through 12.0.19 does not correctly verify whether a request made to the application was intentionally made b…
Digital Asset Management
after 12.0.19
HIGH 8.8
CVE-2020-29254
TikiWiki 21.2 allows templates to be edited without CSRF protection. This could allow an unauthenticated, remote attacker to conduct a cross-site req…
Tikiwiki Cms\/groupware
No fix yet
HIGH 8.8
CVE-2020-35135
The ultimate-category-excluder plugin before 1.2 for WordPress allows ultimate-category-excluder.php CSRF.
Ultimate Category Excluder
1.2+
HIGH 8.1
CVE-2020-2321
A cross-site request forgery (CSRF) vulnerability in Jenkins Shelve Project Plugin 3.0 and earlier allows attackers to shelve, unshelve, or delete a …
Shelve Project
after 3.0
MEDIUM 6.3
CVE-2020-14369
This release fixes a Cross Site Request Forgery vulnerability was found in Red Hat CloudForms which forces end users to execute unwanted actions on a…
Cloudforms
after 5.11
HIGH 8.8
CVE-2020-29458
Textpattern CMS 4.6.2 allows CSRF via the prefs subsystem.
Textpattern
No fix yet
MEDIUM 6.5
CVE-2020-4127
HCL Domino is susceptible to a Login CSRF vulnerability. With a valid credential, an attacker could trick a user into accessing a system under anothe…
Hcl Domino
9.0.1 / 10.0.1+
MEDIUM 6.5
CVE-2020-17901
Cross-site request forgery (CSRF) in PbootCMS 1.3.2 allows attackers to change the password of a user.
Pbootcms
No fix yet
HIGH 8.8
CVE-2020-7780
This affects the package com.softwaremill.akka-http-session:core_2.13 before 0.5.11; the package com.softwaremill.akka-http-session:core_2.12 before …
Akka Http Session
after 0.5.11
HIGH 8.8
CVE-2020-26936
Cloudera Data Engineering (CDE) before 1.1 was vulnerable to a CSRF attack.
Data Engineering
1.1+
HIGH 8.8
CVE-2020-13620
Fastweb FASTGate GPON FGA2130FWB devices through 2020-05-26 allow CSRF via the router administration web panel, leading to an attacker's ability to p…
Fastgate Gpon Fga2130fwb Firmware
after 2020-05-26
MEDIUM 6.5
CVE-2020-25472
SimplePHPscripts News Script PHP Pro 2.3 is affected by a Cross Site Request Forgery (CSRF) vulnerability, which allows attackers to add new users.
News Script Php Pro
Mitigation only
MEDIUM 6.5
CVE-2020-5641
Cross-site request forgery (CSRF) vulnerability in GS108Ev3 firmware version 2.06.10 and earlier allows remote attackers to hijack the authentication…
Gs108ev3 Firmware
after 2.06.10
HIGH 8.8
CVE-2020-28649
The orbisius-child-theme-creator plugin before 1.5.2 for WordPress allows CSRF via orbisius_ctc_theme_editor_manage_file.
Child Theme Creator
1.5.2+
HIGH 8.8
CVE-2020-7332
Cross Site Request Forgery vulnerability in the firewall ePO extension of McAfee Endpoint Security (ENS) prior to 10.7.0 November 2020 Update allows …
Endpoint Security
10.6.1+
HIGH 8.8
CVE-2019-7357
Subrion CMS 4.2.1 has CSRF in panel/modules/plugins/. The attacker can remotely activate/deactivate the plugins.
Subrion Cms
Patch available
HIGH 8.8
CVE-2020-27146
The Core component of TIBCO Software Inc.'s TIBCO iProcess Workspace (Browser) contains a vulnerability that theoretically allows an unauthenticated …
Iprocess Workspace Browser
after 11.6.0
HIGH 8.8
CVE-2020-27016
Trend Micro InterScan Messaging Security Virtual Appliance (IMSVA) 9.1 is vulnerable to a cross-site request forgery (CSRF) vulnerability which could…
Interscan Messaging Security Virtual Appliance
after 9.1
HIGH 8.8
CVE-2020-15259
ad-ldap-connector's admin panel before version 5.0.13 does not provide csrf protection, which when exploited may result in remote code execution or c…
Ad\/ldap Connector
5.0.13+
HIGH 8.8
CVE-2020-27692
The Relish (Verve Connect) VH510 device with firmware before 1.0.1.6L0516 contains multiple CSRF vulnerabilities within its web management portal. At…
Verve Connect Vh510 Firmware
1.0.1.6l0516+
MEDIUM 6.5
CVE-2020-22273
Neoflex Video Subscription System Version 2.0 is affected by CSRF which allows the Website's Settings to be changed (such as Payment Settings)
Neoflex Video Subscription System
Mitigation only
HIGH 8.8
CVE-2020-11485
NVIDIA DGX servers, all DGX-1 with BMC firmware versions prior to 3.38.30, contains a Cross-Site Request Forgery (CSRF) vulnerability in the AMI BMC …
Bmc Firmware
3.38.30+
HIGH 8.8
CVE-2020-16256
The API on Winston 1.5.4 devices is vulnerable to CSRF.
Winston Firmware
No fix yet
HIGH 8.8
CVE-2020-27975
osCommerce Phoenix CE before 1.0.5.4 allows admin/define_language.php CSRF.
Oscommerce
1.0.5.4+
HIGH 8.8
CVE-2020-18129
A CSRF vulnerability in Eyoucms v1.2.7 allows an attacker to add an admin account via login.php.
Eyoucms
No fix yet