Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 8.8
CVE-2018-21037
Subrion CMS 4.1.5 (and possibly earlier versions) allow CSRF to change the administrator password via the panel/members/edit/1 URI.
Subrion
after 4.1.5
HIGH 8.8
CVE-2020-9346
Zoho ManageEngine Password Manager Pro 10.4 and prior has no protection against Cross-site Request Forgery (CSRF) attacks, as demonstrated by changin…
Manageengine Password Manager Pro
10.4+
HIGH 8.8
CVE-2020-6585
Nagios Log Server 2.1.3 has CSRF.
Nagios
No fix yet
HIGH 8.8
CVE-2020-10241
An issue was discovered in Joomla! before 3.9.16. Missing token checks in the image actions of com_templates lead to CSRF.
Joomla\!
3.9.16+
HIGH 8.8
CVE-2020-10568
The sitepress-multilingual-cms (WPML) plugin before 4.3.7-b.2 for WordPress has CSRF due to a loose comparison. This leads to remote code execution i…
Sitepress Multilingual Cms
4.3.7+
MEDIUM 6.5
CVE-2019-13199
Some Kyocera printers (such as the ECOSYS M5526cdw 2R7_2000.001.701) did not implement any mechanism to avoid CSRF. Successful exploitation of this v…
Ecosys M5526cdw Firmware
Mitigation only
MEDIUM 6.5
CVE-2019-13170
Some Xerox printers (such as the Phaser 3320 V53.006.16.000) did not implement any mechanism to avoid CSRF attacks. Successful exploitation of this v…
Phaser 3320 Firmware
Mitigation only
HIGH 8.8
CVE-2019-13395
The Voo branded NETGEAR CG3700b custom firmware V2.02.03 allows CSRF against all /goform/ URIs. An attacker can modify all settings including WEP/WPA…
Cg3700b Firmware
No fix yet
HIGH 8.8
CVE-2020-10540
Untis WebUntis before 2020.9.6 allows CSRF for certain combinations of rights and modules.
Webuntis
2020.9.6+
HIGH 8.8
CVE-2019-17653
A Cross-Site Request Forgery (CSRF) vulnerability in the user interface of Fortinet FortiSIEM 5.2.5 could allow a remote, unauthenticated attacker to…
Fortisiem
Mitigation only
MEDIUM 6.5
CVE-2020-10501
CSRF in admin/manage-departments.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to edit a department, given the id, via a crafted req…
Phpkb
No fix yet
MEDIUM 6.5
CVE-2020-10497
CSRF in admin/manage-categories.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to delete a category via a crafted request.
Phpkb
No fix yet
MEDIUM 6.5
CVE-2020-10498
CSRF in admin/edit-category.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to edit a category, given the id, via a crafted request.
Phpkb
No fix yet
HIGH 8.8
CVE-2020-10478
CSRF in admin/manage-settings.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to change the global settings, potentially gaining code …
Phpkb
No fix yet
CRITICAL 9.8
CVE-2020-10181 KEVEPSS 15%
goform/formEMR30 in Sumavision Enhanced Multimedia Router (EMR) 3.0.4.27 allows creation of arbitrary users with elevated privileges (administrator) …
Enhanced Multimedia Router Firmware
Mitigation only
HIGH 8.8
CVE-2020-9454
A CSRF vulnerability in the RegistrationMagic plugin through 4.6.0.3 for WordPress allows remote attackers to forge requests on behalf of a site admi…
Registrationmagic
after 4.6.0.3
HIGH 8.8
CVE-2019-17642
An issue was discovered in Centreon before 18.10.8, 19.10.1, and 19.04.2. It allows CSRF with resultant remote command execution via shell metacharac…
Centreon
18.10.8 / 19.04.2+
HIGH 8.8
CVE-2020-10057
GeniXCMS 1.1.7 is vulnerable to user privilege escalation due to broken access control. This issue exists because of an incomplete fix for CVE-2015-2…
Genixcms
No fix yet
HIGH 7.1
CVE-2020-3148
A vulnerability in the web-based interface of Cisco Prime Network Registrar (CPNR) could allow an unauthenticated, remote attacker to conduct a cross…
Prime Network Registrar
10.1+
HIGH 8.8
CVE-2020-7988
An issue was discovered in tools/pass-change/result.php in phpIPAM 1.4. CSRF can be used to change the password of any user/admin, to escalate privil…
Phpipam
No fix yet
HIGH 8.8
CVE-2019-20487
An issue was discovered on NETGEAR WNR1000V4 1.1.0.54 devices. Multiple actions within the WNR1000V4 web management console are vulnerable to an unau…
Wnr1000 Firmware
Mitigation only
HIGH 8.8
CVE-2015-1583
Multiple cross-site request forgery (CSRF) vulnerabilities in ATutor 2.2 allow remote attackers to hijack the authentication of administrators for re…
Atutor
Patch available
HIGH 8.8
CVE-2020-5402
In Cloud Foundry UAA, versions prior to 74.14.0, a CSRF vulnerability exists due to the OAuth2 state parameter not being checked in the callback func…
Cf Deployment
12.33.0 / 74.14.0+
HIGH 8.8
CVE-2015-5686
Parts of the Puppet Enterprise Console 3.x were found to be susceptible to clickjacking and CSRF (Cross-Site Request Forgery) attacks. This would all…
Puppet Enterprise
2015.2.0+
MEDIUM 6.5
CVE-2019-19987
An issue was discovered in Selesta Visual Access Manager (VAM) 4.15.0 through 4.29. It allows Cross-Site Request Forgery (CSRF) on any HTML form. An …
Visual Access Manager
after 4.29.0
HIGH 8.8
CVE-2020-9394
An issue was discovered in the pricing-table-by-supsystic plugin before 1.8.2 for WordPress. It allows CSRF.
Pricing Table By Supsystic
1.8.2+
MEDIUM 5.3
CVE-2020-9018
LiteCart through 2.2.1 allows admin/?app=users&doc=edit_user CSRF to add a user.
Litecart
after 2.2.1
HIGH 8.8
CVE-2019-20480
In MIELE XGW 3000 ZigBee Gateway before 2.4.0, a malicious website visited by an authenticated admin user or a malicious mail is allowed to make arbi…
Xgw 3000 Zigbee Gateway Firmware
2.4.0+
HIGH 8.8
CVE-2020-9341
CandidATS 2.1.0 is vulnerable to CSRF that allows for an administrator account to be added via the index.php?m=settings&a=addUser URI.
Candidats
No fix yet
HIGH 8.8
CVE-2012-2629
Multiple cross-site request forgery (CSRF) and cross-site scripting (XSS) vulnerabilities in Axous 1.1.1 and earlier allow remote attackers to hijack…
Axous
after 1.1.1