Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 6.5
CVE-2020-2235
A cross-site request forgery (CSRF) vulnerability in Jenkins Pipeline Maven Integration Plugin 3.8.2 and earlier allows attackers to connect to an at…
Pipeline Maven Integration
after 3.8.2
HIGH 8.8
CVE-2020-7029
A Cross-Site Request Forgery (CSRF) vulnerability was discovered in the System Management Interface Web component of Avaya Aura Communication Manager…
Aura Communication Manager
7.1 / 8.1.0.0+
HIGH 8.8
CVE-2020-12781
Combodo iTop contains a cross-site request forgery (CSRF) vulnerability, attackers can execute specific commands via malicious site request forgery.
Itop
2.7.1+
HIGH 8.1
CVE-2020-16253
The PgHero gem through 2.6.0 for Ruby allows CSRF.
Pghero
after 2.6.0
HIGH 7.6
CVE-2020-15135
save-server (npm package) before version 1.05 is affected by a CSRF vulnerability, as there is no CSRF mitigation (Tokens etc.). The fix introduced i…
Save Server
1.0.5+
HIGH 8.8
CVE-2020-5615
Cross-site request forgery (CSRF) vulnerability in [Calendar01] free edition ver1.0.0 and [Calendar02] free edition ver1.0.0 allows remote attackers …
Calendar01
Mitigation only
HIGH 8.8
CVE-2020-5770
Cross-site request forgery in Teltonika firmware TRB2_R_00.02.04.01 allows a remote attacker to perform sensitive application actions by tricking leg…
Trb245 Firmware
No fix yet
MEDIUM 5.9
CVE-2020-14319
It was found that the AMQ Online console is vulnerable to a Cross-Site Request Forgery (CSRF) which is exploitable in cases where preflight checks ar…
Amq Online
0.32.2 / 1.5.2+
HIGH 8.8
CVE-2020-10984
Gambio GX before 4.0.1.0 allows admin/admin.php CSRF.
Gambio Gx
4.0.1.0+
HIGH 8.8
CVE-2020-5611
Cross-site request forgery (CSRF) vulnerability in Social Sharing Plugin versions prior to 1.2.10 allows remote attackers to hijack the authenticatio…
Social Sharing
1.2.10+
HIGH 8.1
CVE-2020-15882
A CSRF issue in manager/delete_machine/{id} in MunkiReport before 5.6.3 allows attackers to delete arbitrary machines from the MunkiReport database.
Munkireport
5.6.3+
MEDIUM 6.5
CVE-2020-5767
Cross-site request forgery in Icegram Email Subscribers & Newsletters Plugin for WordPress v4.4.8 allows a remote attacker to send forged emails by t…
Email Subscribers \& Newsletters
No fix yet
HIGH 8.8
CVE-2020-11438
LibreHealth EMR v2.0.0 is affected by systemic CSRF.
Librehealth Ehr
No fix yet
MEDIUM 6.3
CVE-2020-15695
An issue was discovered in Joomla! through 3.9.19. A missing token check in the remove request section of com_privacy causes a CSRF vulnerability.
Joomla\!
after 3.9.19
MEDIUM 6.3
CVE-2020-15700
An issue was discovered in Joomla! through 3.9.19. A missing token check in the ajax_install endpoint of com_installer causes a CSRF vulnerability.
Joomla\!
after 3.9.19
HIGH 8.8
CVE-2019-12784
An issue was discovered in Verint Impact 360 15.1. At wfo/control/signin, the login form can accept submissions from external websites. In conjunctio…
Impact 360
No fix yet
HIGH 8.8
CVE-2020-6289
SAP Disclosure Management, version 10.1, had insufficient protection against Cross-Site Request Forgery, which could be used to trick user in to brow…
Disclosure Management
Mitigation only
HIGH 8.8
CVE-2020-15711
In MISP before 2.4.129, setting a favourite homepage was not CSRF protected.
Misp
2.4.129+
MEDIUM 6.5
CVE-2020-10986
A CSRF issue in the /goform/SysToolReboot endpoint of Tenda AC15 AC1900 version 15.03.05.19 allows remote attackers to reboot the device and cause de…
Ac15 Firmware
No fix yet
MEDIUM 6.5
CVE-2020-15600
An issue was discovered in CMSUno before 1.6.1. uno.php allows CSRF to change the admin password.
Cmsuno
1.6.1+
MEDIUM 5.4
CVE-2020-15516
The mm_forum extension through 1.9.5 for TYPO3 allows XSS that can be exploited via CSRF.
Mm Forum
after 1.9.5
HIGH 8.8
CVE-2020-5904
In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, a cross-site request forgery (CSRF) vulnerability in the Traff…
Big Ip Access Policy Manager
after 15.1.0.3
HIGH 8.8
CVE-2020-5900
In versions 3.0.0-3.4.0, 2.0.0-2.9.0, and 1.0.1, there is insufficient cross-site request forgery (CSRF) protections for the NGINX Controller user in…
Nginx Controller
after 3.4.0
MEDIUM 6.5
CVE-2020-15043
iBall WRB303N devices allow CSRF attacks, as demonstrated by enabling remote management, enabling DHCP, or modifying the subnet range for IP addresse…
Wrb303n Firmware
No fix yet
HIGH 8.8
CVE-2020-15046
The web interface on Supermicro X10DRH-iT motherboards with BIOS 2.0a and IPMI firmware 03.40 allows remote attackers to exploit a cgi/config_user.cg…
X10drh It Bios
No fix yet
HIGH 8.8
CVE-2020-15014
pramodmahato BlogCMS through 2019-12-31 has admin/changepass.php CSRF.
Blogcms
after 2019-12-31
HIGH 8.8
CVE-2020-13155
clearsystem.php in NukeViet 4.4 allows CSRF with resultant HTML injection via the deltype parameter to the admin/index.php?nv=webtools&op=clearsystem…
Nukeviet
No fix yet
MEDIUM 6.5
CVE-2020-13156
modules\users\admin\add_user.php in NukeViet 4.4 allows CSRF to add a user account via the admin/index.php?nv=users&op=user_add URI.
Nukeviet
No fix yet
MEDIUM 6.5
CVE-2020-13157
modules\users\admin\edit.php in NukeViet 4.4 allows CSRF to change a user's password via an admin/index.php?nv=users&op=edit&userid= URI. The old pas…
Nukeviet
No fix yet
MEDIUM 6.5
CVE-2020-13426
The Multi-Scheduler plugin 1.0.0 for WordPress has a Cross-Site Request Forgery (CSRF) vulnerability in the forms it presents, allowing the possibili…
Multi Scheduler
No fix yet