Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 6.5
CVE-2019-20401
Various installation setup resources in Jira before version 8.5.2 allow remote attackers to configure a Jira instance, which has not yet finished bei…
Jira Server
8.5.2 / 8.6.0+
HIGH 8.8
CVE-2020-8658EPSS 10%
The BestWebSoft Htaccess plugin through 1.8.1 for WordPress allows wp-admin/admin.php?page=htaccess.php&action=htaccess_editor CSRF. The flag htccss_…
Htaccess
after 1.8.1
HIGH 8.8
CVE-2011-0525
Batavi before 1.0 has CSRF.
Batavi
1.0+
HIGH 8.8
CVE-2019-4613
IBM Planning Analytics 2.0 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions tr…
Planning Analytics
Mitigation only
MEDIUM 6.5
CVE-2020-8615EPSS 9%
A CSRF vulnerability in the Tutor LMS plugin before 1.5.3 for WordPress can result in an attacker approving themselves as an instructor and performin…
Tutor Lms
1.5.3+
CRITICAL 9.6
CVE-2019-10784
phppgadmin through 7.12.1 allows sensitive actions to be performed without validating that the request originated from the application. One such area…
Phppgadmin
after 7.12.1
HIGH 8.8
CVE-2013-7053
D-Link DIR-100 4.03B07: cli.cgi CSRF
Dir 100 Firmware
No fix yet
MEDIUM 6.5
CVE-2020-8504
School Management Software PHP/mySQL through 2019-03-14 allows office_admin/?action=addadmin CSRF to add an administrative user.
School Management Software Php\/mysql
after 2019-03-14
MEDIUM 6.5
CVE-2020-8505
School Management Software PHP/mySQL through 2019-03-14 allows office_admin/?action=deleteadmin CSRF to delete a user.
School Management Software Php\/mysql
after 2019-03-14
MEDIUM 6.5
CVE-2019-7654
Wowza Streaming Engine 4.8.0 and earlier suffers from multiple CSRF vulnerabilities. For example, an administrator, by following a link, can be trick…
Streaming Engine
after 4.8.0
HIGH 8.8
CVE-2020-7965
flaskparser.py in Webargs 5.x through 5.5.2 doesn't check that the Content-Type header is application/json when receiving JSON input. If the request …
Webargs
after 5.5.2
HIGH 8.8
CVE-2020-8424
Cups Easy (Purchase & Inventory) 1.0 is vulnerable to CSRF that leads to admin account takeover via passwordmychange.php.
Cups Easy
No fix yet
MEDIUM 6.5
CVE-2020-8425
Cups Easy (Purchase & Inventory) 1.0 is vulnerable to CSRF that leads to admin account deletion via userdelete.php.
Cups Easy \(purchase \& Inventory\)
No fix yet
HIGH 8.8
CVE-2020-8420
An issue was discovered in Joomla! before 3.9.15. A missing CSRF token check in the LESS compiler of com_templates causes a CSRF vulnerability.
Joomla\!
3.9.15+
HIGH 8.8
CVE-2013-3093
ASUS RT-N56U devices allow CSRF.
Rt N56u Firmware
Mitigation only
HIGH 8.8
CVE-2020-8417EPSS 12%
The Code Snippets plugin before 2.14.0 for WordPress allows CSRF because of the lack of a Referer check on the import menu.
Code Snippets
2.14.0+
HIGH 8.8
CVE-2020-8419
An issue was discovered in Joomla! before 3.9.15. Missing token checks in the batch actions of various components cause CSRF vulnerabilities.
Joomla\!
3.9.15+
HIGH 8.8
CVE-2015-5483
Multiple cross-site request forgery (CSRF) vulnerabilities in the Private Only plugin 3.5.1 for WordPress allow remote attackers to hijack the authen…
Private Only
No fix yet
MEDIUM 6.5
CVE-2013-4865
Cross-site request forgery (CSRF) vulnerability in upgrade_step2.sh in MiCasaVerde VeraLite with firmware 1.5.408 allows remote attackers to hijack t…
Veralite Firmware
No fix yet
HIGH 8.8
CVE-2020-7991
Adive Framework 2.0.8 has admin/config CSRF to change the Administrator password.
Framework
No fix yet
MEDIUM 6.5
CVE-2014-2050
Cross-site request forgery (CSRF) vulnerability in ownCloud Server before 5.0.15 and 6.0.x before 6.0.2 allows remote attackers to hijack the authent…
Owncloud
5.0.15 / 6.0.2+
HIGH 8.8
CVE-2019-16513
An issue was discovered in ConnectWise Control (formerly known as ScreenConnect) 19.3.25270.7185. CSRF can be used to send API requests.
Control
No fix yet
HIGH 8.8
CVE-2011-3612
Cross-Site Request Forgery (CSRF) vulnerability exists in panel.php in UseBB before 1.0.12.
Usebb
1.0.12+
HIGH 8.8
CVE-2011-3582
A Cross-site Request Forgery (CSRF) vulnerability exists in Advanced Electron Forums (AEF) through 1.0.9 due to inadequate confirmation for sensitive…
Advanced Electron Forums
after 1.0.9
HIGH 8.8
CVE-2020-6849
The marketo-forms-and-tracking plugin through 1.0.2 for WordPress allows wp-admin/admin.php?page=marketo_fat CSRF with resultant XSS.
Marketo Forms And Tracking
after 1.0.2
HIGH 8.8
CVE-2019-3864
A vulnerability was discovered in all quay-2 versions before quay-3.0.0, in the Quay web GUI where POST requests include a specific parameter which i…
Quay
3.0.0+
MEDIUM 5.3
CVE-2020-5397
Spring Framework, versions 5.2.x prior to 5.2.3 are vulnerable to CSRF attacks through CORS preflight requests that target Spring MVC (spring-webmvc …
Spring Framework
5.2.3+
HIGH 8.8
CVE-2019-19854
An issue was discovered in Serpico (aka SimplE RePort wrIting and CollaboratiOn tool) 1.3.0. It does not use CSRF Tokens to mitigate against CSRF; it…
Serpico
Patch available
HIGH 8.8
CVE-2019-18271
OSIsoft PI Vision, All versions of PI Vision prior to 2019. The affected product is vulnerable to a cross-site request forgery that may be introduced…
Pi Vision
2019+
HIGH 8.8
CVE-2020-2098
A cross-site request forgery vulnerability in Jenkins Sounds Plugin 0.5 and earlier allows attacker to execute arbitrary OS commands as the OS user a…
Sounds
after 0.5