Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 8.8
CVE-2019-19832
Xerox AltaLink C8035 printers allow CSRF. A request to add users is made in the Device User Database form field to the xerox.set URI. (The frmUserNam…
Altalink C8035 Firmware
No fix yet
MEDIUM 6.5
CVE-2019-19833EPSS 15%
In Tautulli 2.1.9, CSRF in the /shutdown URI allows an attacker to shut down the remote media server. (Also, anonymous access can be achieved in appl…
Tautulli
No fix yet
HIGH 8.8
CVE-2019-11657
Cross-Site Request Forgery vulnerability in all Micro Focus ArcSight Logger affecting all product versions below version 7.0. The vulnerability could…
Arcsight Logger
7.0+
HIGH 8.8
CVE-2019-16575
A cross-site request forgery vulnerability in Jenkins Alauda Kubernetes Suport Plugin 2.3.0 and earlier allows attackers to connect to an attacker-sp…
Alauda Kubernetes Support
after 2.3.0
HIGH 8.8
CVE-2019-16573
A cross-site request forgery vulnerability in Jenkins Alauda DevOps Pipeline Plugin 2.3.2 and earlier allows attackers to connect to an attacker-spec…
Alauda Devops Pipeline
after 2.3.2
HIGH 8.8
CVE-2019-16570
A cross-site request forgery vulnerability in Jenkins RapidDeploy Plugin 4.1 and earlier allows attackers to connect to an attacker-specified web ser…
Rapiddeploy
after 4.1
HIGH 8.8
CVE-2019-16565
A cross-site request forgery vulnerability in Jenkins Team Concert Plugin 1.3.0 and earlier allows attackers to connect to an attacker-specified URL …
Team Concert
after 1.3.0
HIGH 8.8
CVE-2019-16560
A cross-site request forgery vulnerability in Jenkins WebSphere Deployer Plugin 1.6.1 and earlier allows attackers to perform connection tests and de…
Websphere Deployer
after 1.6.1
HIGH 8.8
CVE-2019-16553
A cross-site request forgery vulnerability in Jenkins Build Failure Analyzer Plugin 1.24.1 and earlier allows attackers to have Jenkins evaluate a co…
Build Failure Analyzer
after 1.24.1
HIGH 8.8
CVE-2019-16550
A cross-site request forgery vulnerability in a connection test form method in Jenkins Maven Release Plugin 0.16.1 and earlier allows attackers to ha…
Maven
after 0.16.1
HIGH 8.8
CVE-2019-16551
A cross-site request forgery vulnerability in Jenkins Gerrit Trigger Plugin 2.30.1 and earlier allows attackers to connect to an attacker-specified H…
Gerrit Trigger
after 2.30.1
MEDIUM 6.5
CVE-2017-18107
Various resources in the Crowd Demo application of Atlassian Crowd before version 3.1.1 allow remote attackers to modify add, modify and delete users…
Crowd
3.1.1+
HIGH 8.8
CVE-2014-0197
CFME: CSRF protection vulnerability via permissive check of the referrer header
Cloudforms
after 5.9.3.1
HIGH 8.1
CVE-2019-13930
A vulnerability has been identified in XHQ (All versions < V6.0.0.2). The web interface could allow a Cross-Site Request Forgery (CSRF) attack if an …
Xhq
6.0.0.2+
HIGH 8.8
CVE-2019-15934
Intesync Solismed 3.3sp has CSRF.
Solismed
No fix yet
HIGH 8.8
CVE-2019-0398
Due to insufficient CSRF protection, SAP BusinessObjects Business Intelligence Platform (Monitoring Application), before versions 4.1, 4.2 and 4.3, m…
Businessobjects Business Intelligence Platform
Mitigation only
MEDIUM 6.5
CVE-2014-0026
katello-headpin is vulnerable to CSRF in REST API
Subscription Asset Manager
No fix yet
HIGH 8.8
CVE-2019-19685
RoxyFileman, as shipped with nopCommerce v4.2.0, is vulnerable to CSRF because GET requests can be used for renames and deletions.
Nopcommerce
No fix yet
HIGH 8.8
CVE-2019-18346
A CSRF issue was discovered in DAViCal through 1.1.8. If an authenticated user visits an attacker-controlled webpage, the attacker can send arbitrary…
Davical
after 1.1.8
MEDIUM 6.5
CVE-2019-19516EPSS 10%
Intelbras WRN 150 1.0.18 devices allow CSRF via GO=system_password.asp to the goform/SysToolChangePwd URI to change a password.
Wrn 150 Firmware
No fix yet
HIGH 8.8
CVE-2019-19469
In Zmanda Management Console 3.3.9, ZMC_Admin_Advanced?form=adminTasks&action=Apply&command= allows CSRF, as demonstrated by command injection with s…
Amanda
Mitigation only
MEDIUM 5.3
CVE-2019-19375
In Octopus Deploy before 2019.10.7, in a configuration where SSL offloading is enabled, the CSRF cookie was sometimes sent without the secure attribu…
Octopus Deploy
2019.6.14 / 2019.9.8+
HIGH 8.8
CVE-2019-17590
The csrf_callback function in the CSRF Magic library through 2016-03-27 is vulnerable to CSRF protection bypass as it allows one to tamper with the c…
Csrf Magic
after 2016-03-27
MEDIUM 6.1
CVE-2019-18677EPSS 7%
An issue was discovered in Squid 3.x and 4.x through 4.8 when the append_domain setting is used (because the appended characters do not properly inte…
Ubuntu Linux
after 4.8
MEDIUM 6.5
CVE-2019-16002
A vulnerability in the vManage web-based UI (web UI) of the Cisco SD-WAN Solution could allow an unauthenticated, remote attacker to conduct a cross-…
Sd Wan Firmware
19.2.0+
MEDIUM 6.5
CVE-2011-3609
A CSRF issue was found in JBoss Application Server 7 before 7.1.0. JBoss did not properly restrict access to the management console information (for …
Jboss Application Server
Mitigation only
HIGH 8.8
CVE-2013-6811
Multiple cross-site request forgery (CSRF) vulnerabilities in the D-Link DSL-6740U gateway (Rev. H1) allow remote attackers to hijack the authenticat…
Dsl6740u Firmware
Mitigation only
HIGH 8.8
CVE-2019-19013
A CSRF vulnerability in Pagekit 1.0.17 allows an attacker to upload an arbitrary file by removing the CSRF token from a request.
Pagekit
No fix yet
HIGH 8.8
CVE-2012-2079
A cross-site request forgery (CSRF) vulnerability in the Activity module 6.x-1.x for Drupal.
Activity
Mitigation only
HIGH 8.8
CVE-2015-3140
Multiple cross-site request forgery (CSRF) vulnerabilities in Synametrics Technologies SynaMan before 3.5 Build 1451, Syncrify before 3.7 Build 856, …
Synaman
Mitigation only