Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 8.8
CVE-2013-3312
Multiple cross-site request forgery (CSRF) vulnerabilities in the Loftek Nexus 543 IP Camera allow remote attackers to hijack the authentication of u…
Nexus 543 Firmware
No fix yet
HIGH 8.8
CVE-2019-16548
A cross-site request forgery vulnerability in Jenkins Google Compute Engine Plugin 4.1.1 and earlier in ComputeEngineCloud#doProvision could be used …
Google Compute Engine
4.2.0+
HIGH 8.8
CVE-2011-4952
cobbler: Web interface lacks CSRF protection when using Django framework
Cobbler
Mitigation only
MEDIUM 6.5
CVE-2019-18651
A cross-site request forgery (CSRF) vulnerability in 3xLogic Infinias Access Control through 6.6.9586.0 allows remote attackers to execute malicious …
Infinias Access Control Firmware
after 6.6.9586.0
HIGH 8.8
CVE-2013-3366
Undocumented TELNET service in TRENDnet TEW-812DRU when a web page named backdoor contains an HTML parameter of password and a value of j78G¬DFdg_24M…
Tew 812dru Firmware
Mitigation only
HIGH 8.8
CVE-2019-18884
index.php/team_members/add_team_member in RISE Ultimate Project Manager 2.3 has CSRF for adding authorized users.
Rise Ultimate Project Manager
No fix yet
MEDIUM 6.5
CVE-2013-3516
NETGEAR WNR3500U and WNR3500L routers uses form tokens abased solely on router's current date and time, which allows attackers to guess the CSRF toke…
Wnr3500u Firmware
No fix yet
MEDIUM 6.5
CVE-2012-4385
letodms 3.3.6 has CSRF via change password
Debian Linux
No fix yet
HIGH 8.8
CVE-2010-3305
Cross-site request forgery (CSRF) vulnerability in pixelpost 1.7.3 could allow remote attackers to change the admin password.
Pixelpost
No fix yet
HIGH 8.8
CVE-2019-17237
includes/class-coming-soon-creator.php in the igniteup plugin through 3.4 for WordPress allows CSRF.
Igniteup
after 3.4
HIGH 8.8
CVE-2019-18411
Zoho ManageEngine ADSelfService Plus 5.x through 5803 has CSRF on the users' profile information page. Users who are attacked with this vulnerability…
Manageengine Adselfservice Plus
Mitigation only
HIGH 8.8
CVE-2019-18650
An issue was discovered in Joomla! before 3.9.13. A missing token check in com_template causes a CSRF vulnerability.
Joomla\!
after 3.9.12
HIGH 8.0
CVE-2019-8109
A remote code execution vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user can craft …
Magento
2.2.10 / 2.3.2+
MEDIUM 6.5
CVE-2013-6275
Multiple CSRF issues in Horde Groupware Webmail Edition 5.1.2 and earlier in basic.php.
Debian Linux
after 5.1.2
HIGH 8.8
CVE-2013-6364
Horde Groupware Webmail Edition has CSRF and XSS when saving search as a virtual address book
Debian Linux
No fix yet
MEDIUM 5.3
CVE-2013-6365
Horde Groupware Web mail 5.1.2 has CSRF with requests to change permissions
Debian Linux
Patch available
MEDIUM 6.5
CVE-2019-13497
One Identity Cloud Access Manager before 8.1.4 Hotfix 1 allows CSRF for logout requests.
Cloud Access Manager
8.1.4+
HIGH 8.8
CVE-2019-18206
A cross-site request forgery (CSRF) vulnerability in Zucchetti InfoBusiness before and including 4.4.1 allows arbitrary file upload.
Infobusiness
after 4.4.1
HIGH 8.8
CVE-2019-9926
An issue was discovered in LabKey Server 19.1.0. It is possible to force a logged-in administrator to execute code through a /reports-viewScriptRepor…
Labkey Server
No fix yet
HIGH 8.8
CVE-2010-4241
Tiki Wiki CMS Groupware 5.2 has CSRF
Tikiwiki Cms\/groupware
No fix yet
HIGH 8.8
CVE-2013-4848
TP-Link TL-WDR4300 version 3.13.31 has multiple CSRF vulnerabilities.
Tl Wdr4300 Firmware
No fix yet
MEDIUM 6.5
CVE-2019-8234
Adobe Experience Manager versions 6.4, 6.3 and 6.2 have a cross-site request forgery vulnerability. Successful exploitation could lead to sensitive i…
Experience Manager
Mitigation only
HIGH 8.8
CVE-2019-12095
Horde Trean, as used in Horde Groupware Webmail Edition through 5.2.22 and other products, allows CSRF, as demonstrated by the treanBookmarkTags para…
Groupware
after 5.2.22
HIGH 8.8
CVE-2019-18414
Sourcecodester Restaurant Management System 1.0 is affected by an admin/staff-exec.php Cross Site Request Forgery vulnerability due to a lack of CSRF…
Restaurant Management System
No fix yet
MEDIUM 6.5
CVE-2019-9596
Darktrace Enterprise Immune System before 3.1 allows CSRF via the /whitelisteddomains endpoint.
Enterprise Immune System
3.1+
MEDIUM 6.5
CVE-2019-9597
Darktrace Enterprise Immune System before 3.1 allows CSRF via the /config endpoint.
Enterprise Immune System
3.1+
HIGH 8.8
CVE-2019-18220
Sitemagic CMS 4.4.1 is affected by a Cross-Site-Request-Forgery (CSRF) issue as it doesn't implement any method to validate incoming requests, allowi…
Sitemagic
Mitigation only
HIGH 8.8
CVE-2019-18280
Sourcecodester Online Grading System 1.0 is affected by a Cross Site Request Forgery vulnerability due to a lack of CSRF protection. This could lead …
Online Grading System
No fix yet
HIGH 8.8
CVE-2019-10471
A cross-site request forgery vulnerability in Jenkins Libvirt Slaves Plugin allows attackers to connect to an attacker-specified SSH server using att…
Libvirt Slaves
after 1.8.5
HIGH 8.1
CVE-2019-10462
A cross-site request forgery vulnerability in Jenkins Dynatrace Application Monitoring Plugin 2.1.3 and earlier allowed attackers to connect to an at…
Dynatrace Application Monitoring
after 2.1.3