Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 8.8
CVE-2020-12257
rConfig 3.9.4 is vulnerable to cross-site request forgery (CSRF) because it lacks implementation of CSRF protection such as a CSRF token. An attacker…
Rconfig
No fix yet
HIGH 8.1
CVE-2019-20390
A Cross-Site Request Forgery (CSRF) vulnerability was discovered in Subrion CMS 4.2.1 that allows a remote attacker to remove files on the server wit…
Subrion
No fix yet
HIGH 8.8
CVE-2020-5576
Cross-site request forgery (CSRF) vulnerability in Movable Type series (Movable Type 7 r.4606 (7.2.1) and earlier (Movable Type 7), Movable Type Adva…
Movable Type
after 7.2.1
HIGH 8.8
CVE-2020-11069
In TYPO3 CMS 9.0.0 through 9.5.16 and 10.0.0 through 10.4.1, it has been discovered that the backend user interface and install tool are vulnerable t…
TYPO3
after 10.4.1
HIGH 8.8
CVE-2020-12427
The Western Digital WD Discovery application before 3.8.229 for MyCloud Home on Windows and macOS is vulnerable to CSRF, with impacts such as stealin…
Wd Discovery
3.8.229+
HIGH 8.8
CVE-2020-11060EPSS 11%
In GLPI before 9.4.6, an attacker can execute system commands by abusing the backup functionality. Theoretically, this vulnerability can be exploited…
Glpi
9.4.6+
HIGH 7.4
CVE-2020-5745
Cross-site request forgery in TCExam 14.2.2 allows a remote attacker to perform sensitive application actions by tricking legitimate users into click…
Tcexam
Patch available
HIGH 8.8
CVE-2019-19517
Intelbras RF1200 1.1.3 devices allow CSRF to bypass the login.html form, as demonstrated by launching a scrapy process.
Action Rf 1200 Firmware
No fix yet
MEDIUM 6.5
CVE-2020-5517
CSRF in the /login URI in BlueOnyx 5209R allows an attacker to access the dashboard and perform scraping or other analysis.
5209r Firmware
Patch available
HIGH 8.1
CVE-2020-7983
A CSRF issue in login.asp on Ruckus R500 3.4.2.0.384 devices allows remote attackers to access the panel or conduct SSRF attacks.
Ruckus Zoneflex R500 Firmware
No fix yet
HIGH 8.8
CVE-2020-8829
CSRF on Intelbras CIP 92200 devices allows an attacker to access the panel and perform scraping or other analysis.
Cip 92200 Firmware
No fix yet
HIGH 8.8
CVE-2020-8830
CSRF in login.asp on Ruckus devices allows an attacker to access the panel, and use SSRF to perform scraping or other analysis via the SUBCA-1 field …
Ruckus Zoneflex R500 Firmware
No fix yet
HIGH 8.8
CVE-2020-5335
RSA Archer, versions prior to 6.7 P2 (6.7.0.2), contain a cross-site request forgery vulnerability. A remote unauthenticated attacker could potential…
Archer
6.7.0.2+
MEDIUM 6.5
CVE-2020-12626
An issue was discovered in Roundcube Webmail before 1.4.4. A CSRF attack can cause an authenticated user to be logged out because POST was not consid…
Debian Linux
1.4.4+
HIGH 8.8
CVE-2019-0235EPSS 33%
Apache OFBiz 17.12.01 is vulnerable to some CSRF attacks.
Ofbiz
No fix yet
MEDIUM 6.1
CVE-2020-12462
The ninja-forms plugin before 3.4.24.2 for WordPress allows CSRF with resultant XSS.
Ninja Forms
3.4.24.2+
HIGH 8.0
CVE-2017-18861
Certain NETGEAR devices are affected by CSRF. This affects ReadyNAS Surveillance 1.4.3-15-x86 and earlier and ReadyNAS Surveillance 1.1.4-5-ARM and e…
Readynas Surveillance
after 1.4.3-15
HIGH 7.4
CVE-2018-21096
Certain NETGEAR devices are affected by CSRF. This affects WAC120 before 2.1.7, WAC505 before 5.0.5.4, WAC510 before 5.0.5.4, WNAP320 before 3.7.11.4…
Wac120 Firmware
2.1.7 / 3.7.11.4+
HIGH 8.8
CVE-2019-4750
IBM Cloud App Management 2019.3.0 and 2019.4.0 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and una…
Cloud App Management
Mitigation only
HIGH 8.8
CVE-2017-18703
Certain NETGEAR devices are affected by CSRF. This affects D1500 before 1.0.0.25, D500 before 1.0.0.25, D6100 before 1.0.0.55, D7000 before 1.0.1.50,…
D1500 Firmware
1.0.0.25 / 1.0.0.55+
HIGH 8.8
CVE-2017-18708
Certain NETGEAR devices are affected by CSRF. This affects R8300 before 1.0.2.94 and R8500 before 1.0.2.94.
R8300 Firmware
1.0.2.94+
HIGH 8.8
CVE-2018-21160
NETGEAR ReadyNAS devices before 6.9.3 are affected by CSRF.
Readynas Os
6.9.3+
HIGH 8.8
CVE-2018-21102
NETGEAR ReadyNAS devices before 6.9.3 are affected by CSRF.
Readynas Os Firmware
6.9.3+
HIGH 8.8
CVE-2017-18742
Certain NETGEAR devices are affected by CSRF. This affects JR6150 before 1.0.1.10, R6050 before 1.0.1.10, R6250 before 1.0.4.12, R6300v2 before 1.0.4…
Jr6150 Firmware
1.0.0.54 / 1.0.1.10+
HIGH 8.8
CVE-2017-18749
Certain NETGEAR devices are affected by CSRF. This affects JNR1010v2 before 1.1.0.44, JR6150 before 1.0.1.10, JWNR2010v5 before 1.1.0.44, R6050 befor…
Jnr1010 Firmware
1.0.0.112 / 1.0.1.10+
HIGH 8.8
CVE-2020-12076
The data-tables-generator-by-supsystic plugin before 1.9.92 for WordPress lacks CSRF nonce checks for AJAX actions. One consequence of this is stored…
Data Tables Generator
1.9.92+
HIGH 8.8
CVE-2020-10890
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PhantomPDF 9.7.0.29478. User interaction is r…
Phantompdf
after 9.7.1.29511
HIGH 8.8
CVE-2020-10892
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PhantomPDF 9.7.0.29478. User interaction is r…
Phantompdf
after 9.7.1.29511
HIGH 8.8
CVE-2017-18755
Certain NETGEAR devices are affected by CSRF. This affects R6300v2 before 1.0.4.8, R6400v2 before 1.0.2.32, R6700 before 1.0.1.22, R6900 before 1.0.1…
R6300 Firmware
1.0.0.54 / 1.0.0.56+
HIGH 8.8
CVE-2017-18768
Certain NETGEAR devices are affected by CSRF. This affects EX6100 before 1.0.2.16_1.1.130, EX6100v2 before 1.0.1.70, EX6150v2 before 1.0.1.54, EX6200…
Ex6100 Firmware
1.0.1.50 / 1.0.1.54+