Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 8.8
CVE-2020-3114
A vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker to …
Data Center Network Manager
11.3+
HIGH 8.8
CVE-2019-12437
In SilverStripe through 4.3.3, the previous fix for SS-2018-007 does not completely mitigate the risk of CSRF in GraphQL mutations,
Silverstripe
after 4.3.3
HIGH 8.8
CVE-2020-9270
ICE Hrm 26.2.0 is vulnerable to CSRF that leads to password reset via service.php.
Icehrm
No fix yet
MEDIUM 6.5
CVE-2020-9271
ICE Hrm 26.2.0 is vulnerable to CSRF that leads to user creation via service.php.
Icehrm
No fix yet
MEDIUM 6.5
CVE-2020-9266
SOPlanning 1.45 is vulnerable to a CSRF attack that allows for arbitrary changing of the admin password via process/xajax_server.php.
Soplanning
No fix yet
MEDIUM 6.5
CVE-2020-9267
SOPlanning 1.45 is vulnerable to a CSRF attack that allows for arbitrary user creation via process/xajax_server.php.
Soplanning
No fix yet
HIGH 8.8
CVE-2020-6844
In TopManage OLK 2020, login CSRF can be chained with another vulnerability in order to takeover admin and user accounts.
Olk Webstore
No fix yet
HIGH 8.8
CVE-2013-4227
Cross-site request forgery (CSRF) vulnerability in the persona_xsrf_token function in persona.module in the Mozilla Persona module 7.x-1.x before 7.x…
Persona
7.x-1.11+
HIGH 8.8
CVE-2020-5530
Cross-site request forgery (CSRF) vulnerability in Easy Property Listings versions prior to 3.4 allows remote attackers to hijack the authentication …
Easy Property Listings
3.4+
MEDIUM 6.5
CVE-2020-1692
Moodle before version 3.7.2 is vulnerable to information exposure of service tokens for users enrolled in the same course.
Moodle
3.7.2+
MEDIUM 5.5
CVE-2013-4792
PrestaShop before 1.4.11 allows logout CSRF.
Prestashop
1.4.11+
HIGH 8.8
CVE-2020-1977
Insufficient Cross-Site Request Forgery (XSRF) protection on Expedition Migration Tool allows remote unauthenticated attackers to hijack the authenti…
Expedition Migration Tool
after 1.1.51
HIGH 8.8
CVE-2020-2116
A cross-site request forgery vulnerability in Jenkins Pipeline GitHub Notify Step Plugin 1.0.4 and earlier allows attackers to connect to an attacker…
Pipeline Github Notify Step
after 1.0.4
MEDIUM 6.3
CVE-2012-6721
Multiple cross-site request forgery (CSRF) vulnerabilities in the (1) Forum, (2) Event, and (3) Classifieds plugins in SocialEngine before 4.2.4.
Socialengine
4.2.4+
MEDIUM 5.4
CVE-2019-19667
A CSRF vulnerability exists in the Block Clients component of Web File Manager in Rumpus FTP 8.2.9.1 that could allow an attacker to whitelist or blo…
Rumpus Ftp
Mitigation only
MEDIUM 6.5
CVE-2019-19669
A CSRF vulnerability exists in the Upload Center Forms Component of Web File Manager in Rumpus FTP 8.2.9.1. This could allow an attacker to delete, c…
Rumpus Ftp
Mitigation only
MEDIUM 6.5
CVE-2019-19662
A CSRF vulnerability exists in the Web File Manager's Create/Delete Accounts functionality of Rumpus FTP Server 8.2.9.1. By exploiting it, an attacke…
Rumpus Ftp
Mitigation only
HIGH 7.1
CVE-2019-19664
A CSRF vulnerability exists in the Web Settings of Web File Manager in Rumpus FTP 8.2.9.1. Exploitation of this vulnerability can result in manipulat…
Rumpus Ftp
Mitigation only
MEDIUM 5.4
CVE-2013-2108
WordPress WP Cleanfix Plugin 2.4.4 has CSRF
Cleanfix
No fix yet
HIGH 8.8
CVE-2013-2109
WordPress plugin wp-cleanfix has Remote Code Execution
Wp Cleanfix
No fix yet
MEDIUM 6.5
CVE-2019-19660
A CSRF vulnerability exists in the Web File Manager's Network Setting functionality of Rumpus FTP Server 8.2.9.1. By exploiting it, an attacker can m…
Rumpus
Mitigation only
MEDIUM 6.5
CVE-2019-19663
A CSRF vulnerability exists in the Folder Sets Settings of Web File Manager in Rumpus FTP 8.2.9.1. This allows an attacker to Create/Delete Folders a…
Rumpus
Mitigation only
MEDIUM 6.5
CVE-2019-19665
A CSRF vulnerability exists in the FTP Settings of Web File Manager in Rumpus FTP 8.2.9.1. Exploitation of this vulnerability can result in manipulat…
Rumpus
Mitigation only
HIGH 8.8
CVE-2019-19659
A CSRF vulnerability exists in the Web File Manager's Edit Accounts functionality of Rumpus FTP Server 8.2.9.1. By exploiting it, an attacker can tak…
Rumpus
Mitigation only
HIGH 8.8
CVE-2019-20059
payment_manage.ajax.php and various *_manage.ajax.php in MFScripts YetiShare 3.5.2 through 4.5.4 directly insert values from the sSortDir_0 parameter…
Yetishare
after 4.5.4
HIGH 8.8
CVE-2014-2225
Multiple cross-site request forgery (CSRF) vulnerabilities in Ubiquiti Networks UniFi Controller before 3.2.1 allow remote attackers to hijack the au…
Airvision Controller
3.2.1+
HIGH 8.8
CVE-2011-1085
CSRF vulnerability in Smoothwall Express 3.
Smoothwall Express
No fix yet
HIGH 8.8
CVE-2014-5288
A CSRF Vulnerability exists in Kemp Load Master before 7.0-18a via unspecified vectors in administrative pages.
Load Master
7.1.20b+
HIGH 8.8
CVE-2013-3568EPSS 25%
Cross-site request forgery (CSRF) vulnerability in Cisco Linksys WRT110 allows remote attackers to hijack the authentication of users for requests th…
Linksys Wrt110 Firmware
No fix yet
HIGH 8.8
CVE-2012-6297
Command Injection vulnerability exists via a CSRF in DD-WRT 24-sp2 from specially crafted configuration values containing shell meta-characters, whic…
Dd Wrt
No fix yet