Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 8.8
CVE-2020-14203
WebFOCUS Business Intelligence 8.0 (SP6) allows a Cross-Site Request Forgery (CSRF) attack against administrative users within the /ibi_apps/WFServle…
Webfocus Business Intelligence
No fix yet
HIGH 8.8
CVE-2019-20891
WooCommerce before 3.6.5, when it handles CSV imports of products, has a cross-site request forgery (CSRF) issue with resultant stored cross-site scr…
Woocommerce
3.6.5+
MEDIUM 6.1
CVE-2016-11084
An issue was discovered in Mattermost Server before 2.1.0. It allows XSS via CSRF.
Mattermost Server
2.1.0+
HIGH 8.8
CVE-2017-18903
An issue was discovered in Mattermost Server before 4.0.0, 3.10.2, and 3.9.2. CSRF can occur if CORS is enabled.
Mattermost Server
3.9.2 / 3.10.2+
MEDIUM 6.5
CVE-2020-8167
A CSRF vulnerability exists in rails <= 6.0.3 rails-ujs module that could allow attackers to send CSRF tokens to wrong domains.
Rails
5.2.4.3 / 6.0.3.1+
HIGH 8.8
CVE-2019-20865
An issue was discovered in Mattermost Server before 5.12.0, 5.11.1, 5.10.2, 5.9.2, and 4.10.10. The login page allows CSRF.
Mattermost Server
4.10.10 / 5.9.2+
HIGH 8.8
CVE-2019-20841
An issue was discovered in Mattermost Server before 5.18.0, 5.17.2, 5.16.4, 5.15.4, and 5.9.7. CSRF can sometimes occur via a crafted web site for ac…
Mattermost Server
5.9.7 / 5.15.4+
HIGH 8.8
CVE-2020-14432
Certain NETGEAR devices are affected by CSRF. This affects RBK752 before 3.2.15.25, RBK753 before 3.2.15.25, RBK753S before 3.2.15.25, RBR750 before …
Rbk752 Firmware
3.2.15.25+
HIGH 8.8
CVE-2020-7503
A CWE-352: Cross-Site Request Forgery (CSRF) vulnerability exists in Easergy T300 (Firmware version 1.5.2 and older) which could allow an attacker to…
Easergy T300 Firmware
after 1.5.2
HIGH 8.8
CVE-2019-19109
The wpForo plugin 1.6.5 for WordPress allows wp-admin/admin.php?page=wpforo-usergroups CSRF.
Wpforo
No fix yet
HIGH 8.8
CVE-2020-9042
In Couchbase Server 6.0, credentials cached by a browser can be used to perform a CSRF attack if an administrator has used their browser to check the…
Couchbase Server
Mitigation only
MEDIUM 6.5
CVE-2020-13868
An issue was discovered in the Comments plugin before 1.5.5 for Craft CMS. CSRF affects comment integrity.
Comments
1.5.5+
MEDIUM 6.5
CVE-2020-11682
Castel NextGen DVR v1.0.0 is vulnerable to CSRF in all state-changing request. A __RequestVerificationToken is set by the web interface, and included…
Nextgen Dvr Firmware
No fix yet
HIGH 8.8
CVE-2020-13786
D-Link DIR-865L Ax 1.20B01 Beta devices allow CSRF.
Dir 865l Firmware
No fix yet
HIGH 8.0
CVE-2020-2196
Jenkins Selenium Plugin 3.141.59 and earlier has no CSRF protection for its HTTP endpoints, allowing attackers to perform all administrative actions …
Selenium
after 3.141.59
MEDIUM 6.5
CVE-2020-2192
A cross-site request forgery vulnerability in Jenkins Self-Organizing Swarm Plug-in Modules Plugin 3.20 and earlier allows attackers to add or remove…
Self Organizing Swarm Modules
after 3.20
HIGH 8.8
CVE-2020-13760
In Joomla! before 3.9.19, missing token checks in com_postinstall lead to CSRF.
Joomla\!
3.9.19+
HIGH 8.8
CVE-2014-8942
Lexiglot through 2014-11-20 allows CSRF.
Lexiglot
after 2014-11-20
HIGH 8.8
CVE-2020-4018
The setup resources in Atlassian Fisheye and Crucible before version 4.8.1 allows remote attackers to complete the setup process via a cross-site req…
Crucible
4.8.1+
HIGH 8.8
CVE-2020-13643
An issue was discovered in the SiteOrigin Page Builder plugin before 2.10.16 for WordPress. The live editor feature did not do any nonce verification…
Page Builder
2.10.16+
HIGH 8.8
CVE-2020-13641
An issue was discovered in the Real-Time Find and Replace plugin before 4.0.2 for WordPress. The far_options_page function did not do any nonce verif…
Real Time Find And Replace
4.0.2+
HIGH 8.8
CVE-2020-13642
An issue was discovered in the SiteOrigin Page Builder plugin before 2.10.16 for WordPress. The action_builder_content function did not do any nonce …
Page Builder
2.10.16+
HIGH 8.8
CVE-2020-8168
We have recently released new version of AirMax AirOS firmware v6.3.0 for TI, XW and XM boards that fixes vulnerabilities found on AirMax AirOS v6.2.…
Airos
after 6.2.0
HIGH 8.8
CVE-2020-13458
An issue was discovered in the Image Resizer plugin before 2.0.9 for Craft CMS. There are CSRF issues with the log-clear controller action.
Image Resizer
2.0.9+
HIGH 8.8
CVE-2020-13412
An issue was discovered in Aviatrix Controller before 5.4.1204. An API call on the web interface lacked a session token check to control access, lead…
Controller
5.4.1204+
MEDIUM 6.5
CVE-2020-13416
An issue was discovered in Aviatrix Controller before 5.4.1066. A Controller Web Interface session token parameter is not required on an API call, wh…
Controller
5.4.1066+
MEDIUM 6.5
CVE-2020-1103
An information disclosure vulnerability exists where certain modes of the search function in Microsoft SharePoint Server are vulnerable to cross-site…
Sharepoint Enterprise Server
Patch available
HIGH 8.8
CVE-2019-20804
Gila CMS before 1.11.6 allows CSRF with resultant XSS via the admin/themes URI, leading to compromise of the admin account.
Gila Cms
1.11.6+
MEDIUM 6.5
CVE-2020-13231
In Cacti before 1.2.11, auth_profile.php?action=edit allows CSRF for an admin email change.
Fedora
1.2.11+
MEDIUM 6.5
CVE-2020-4286
IBM InfoSphere Information Server 11.3, 11.5, and 11.7 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious…
Infosphere Information Server
Patch available