Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 8.1
CVE-2020-4617
IBM Data Risk Manager (iDNA) 2.0.6 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized ac…
Data Risk Manager
2.0.6.4+
CRITICAL 9.6
CVE-2020-15182
The SOY Inquiry component of SOY CMS is affected by Cross-site Request Forgery (CSRF) and Remote Code Execution (RCE). The vulnerability affects vers…
Soy Cms
2.0.0.4 / 3.0.2.328+
HIGH 8.8
CVE-2020-24373
A CSRF vulnerability in the UPnP MediaServer implementation in Freebox Server before 4.2.3.
Freebox Revolution Firmware
4.2.3+
HIGH 8.8
CVE-2020-13259
A vulnerability in the web-based management interface of RAD SecFlow-1v os-image SF_0290_2.3.01.26 could allow an unauthenticated, remote attacker to…
Secflow 1v Firmware
No fix yet
MEDIUM 6.5
CVE-2020-25015
A specific router allows changing the Wi-Fi password remotely. Genexis Platinum 4410 V2-1.28, a compact router generally used at homes and offices wa…
Platinum 4410 Firmware
No fix yet
HIGH 8.8
CVE-2020-2268
A cross-site request forgery (CSRF) vulnerability in Jenkins MongoDB Plugin 1.3 and earlier allows attackers to gain access to some metadata of any a…
MongoDB
after 1.3
HIGH 8.8
CVE-2020-25453EPSS 6%
An issue was discovered in BlackCat CMS before 1.4. There is a CSRF vulnerability (bypass csrf_token) that allows remote arbitrary code execution.
Blackcat Cms
1.4+
HIGH 8.8
CVE-2020-23451
Spiceworks Version <= 7.5.00107 is affected by CSRF which can lead to privilege escalation via "/settings/v1/users" function.
Spiceworks
after 7.5.00107
HIGH 8.8
CVE-2020-10229
A CSRF issue in vtecrm vtenext 19 CE allows attackers to carry out unwanted actions on an administrator's behalf, such as uploading files, adding use…
Vtenext
No fix yet
HIGH 8.8
CVE-2020-23824
ArGo Soft Mail Server 1.8.8.9 is affected by Cross Site Request Forgery (CSRF) for perform remote arbitrary code execution. The component is the Admi…
Mail Server
No fix yet
MEDIUM 6.5
CVE-2018-19948
The vulnerability have been reported to affect earlier versions of Helpdesk. If exploited, this cross-site request forgery (CSRF) vulnerability could…
Helpdesk
3.0.3+
HIGH 8.8
CVE-2020-25252
An issue was discovered in Hyland OnBase through 16.0.2.83 and below, 17.0.2.109 and below, 18.0.0.37 and below, 19.8.16.1000 and below and 20.3.10.1…
Onbase
after 20.3.10.1000
MEDIUM 6.5
CVE-2020-24739
A CSRF vulnerability was found in iCMS v7.0.0 in the background deletion administrator account. When missing the CSRF_TOKEN and can still request nor…
Icms
No fix yet
HIGH 8.1
CVE-2020-15789
A vulnerability has been identified in Polarion Subversion Webclient (All versions). The web interface could allow a Cross-Site Request Forgery (CSRF…
Polarion Subversion Webclient
Mitigation only
HIGH 7.1
CVE-2020-23830
A Cross-Site Request Forgery (CSRF) vulnerability in changeUsername.php in SourceCodester Stock Management System v1.0 allows remote attackers to den…
Stock Management System
No fix yet
HIGH 8.8
CVE-2020-16208
The affected product is vulnerable to cross-site request forgery, which may allow an attacker to modify different configurations of a device by lurin…
N Tron 702 W Firmware
No fix yet
HIGH 8.8
CVE-2020-25070
USVN (aka User-friendly SVN) before 1.0.10 allows CSRF, related to the lack of the SameSite Strict feature.
Usvn
1.0.10+
HIGH 8.8
CVE-2020-5776EPSS 15%
Currently, all versions of MAGMI are vulnerable to CSRF due to the lack of CSRF tokens. RCE (via phpcli command) is possible in the event that a CSRF…
Magmi
Mitigation only
HIGH 8.8
CVE-2020-23836
A Cross-Site Request Forgery (CSRF) vulnerability in edit_user.php in OSWAPP Warehouse Inventory System (aka OSWA-INV) through 2020-08-10 allows remo…
Warehouse Inventory System
after 2020-08-10
HIGH 8.8
CVE-2020-2240
A cross-site request forgery (CSRF) vulnerability in Jenkins database Plugin 1.6 and earlier allows attackers to execute arbitrary SQL scripts.
Database
after 1.6
HIGH 8.8
CVE-2020-2241
A cross-site request forgery (CSRF) vulnerability in Jenkins database Plugin 1.6 and earlier allows attackers to connect to an attacker-specified dat…
Database
after 1.6
HIGH 8.1
CVE-2020-15156
In nodebb-plugin-blog-comments before version 0.7.0, a logged in user is vulnerable to an XSS attack which could allow a third party to post on their…
Blog Comments
0.7.0+
HIGH 8.8
CVE-2020-5922
In BIG-IP versions 15.0.0-15.1.0.4, 14.1.0-14.1.2.6, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.2, iControl REST does not implement Cross Si…
Big Ip Access Policy Manager
12.1.5.2 / 13.1.3.4+
HIGH 8.8
CVE-2020-14043
** PRODUCT NOT SUPPORTED WHEN ASSIGNED ** A Cross Side Request Forgery (CSRF) vulnerability was found in Codiad v1.7.8 and later. The request to down…
Codiad
No fix yet
HIGH 8.1
CVE-2020-19886
DBHcms v1.2.0 has no CSRF protection mechanism,as demonstrated by CSRF for an /index.php?dbhcms_pid=-80&deletemenu=9 can delete any menu.
Dbhcms
No fix yet
HIGH 8.8
CVE-2020-19889
DBHcms v1.2.0 has no CSRF protection mechanism,as demonstrated by CSRF for index.php?dbhcms_pid=-70 can add a user.
Dbhcms
No fix yet
HIGH 8.0
CVE-2020-15151
OpenMage LTS before versions 19.4.6 and 20.0.2 allows attackers to circumvent the `fromkey protection` in the Admin Interface and increases the attac…
Openmage Long Term Support
19.4.6 / 20.0.2+
MEDIUM 6.5
CVE-2020-12480
In Play Framework 2.6.0 through 2.8.1, the CSRF filter can be bypassed by making CORS simple requests with content types that contain parameters that…
Play Framework
after 2.8.1
MEDIUM 6.5
CVE-2016-11085
php/qmn_options_questions_tab.php in the quiz-master-next plugin before 4.7.9 for WordPress allows CSRF, with resultant stored XSS, via the question_…
Quiz And Survey Master
4.7.9+
HIGH 7.6
CVE-2020-7304
Cross site request forgery vulnerability in McAfee Data Loss Prevention (DLP) ePO extension prior to 11.5.3 allows authenticated remote attacker to e…
Data Loss Prevention
11.3.28 / 11.4.200+