Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 8.8
CVE-2019-10464
A cross-site request forgery vulnerability in Jenkins Deploy WebLogic Plugin allows attackers to connect to an attacker-specified URL using attacker-…
Deploy Weblogic
after 4.1
HIGH 8.8
CVE-2019-10468
A cross-site request forgery vulnerability in Jenkins ElasticBox Jenkins Kubernetes CI/CD Plugin allows attackers to connect to an attacker-specified…
Kubernetes Ci
after 1.3
HIGH 8.8
CVE-2015-9497
The ad-inserter plugin before 1.5.3 for WordPress has CSRF with resultant XSS via wp-admin/options-general.php?page=ad-inserter.php.
Ad Inserter
1.5.3+
HIGH 8.8
CVE-2015-9498
The wps-hide-login plugin before 1.1 for WordPress has CSRF that affects saving an option value.
Wps Hide Login
1.1+
HIGH 8.8
CVE-2019-17367
OpenWRT firmware version 18.06.4 is vulnerable to CSRF via wireless/radio0.network1, wireless/radio1.network1, firewall, firewall/zones, firewall/for…
Openwrt
Patch available
HIGH 8.8
CVE-2019-17118
A CSRF issue in WiKID 2FA Enterprise Server through 4.2.0-b2053 allows a remote attacker to trick an authenticated user into performing unintended ac…
2fa Enterprise Server
Patch available
HIGH 8.8
CVE-2019-17675
WordPress before 5.2.4 does not properly consider type confusion during validation of the referer in the admin pages, possibly leading to CSRF.
WordPress
5.2.4+
HIGH 8.8
CVE-2019-17676
app/system/admin/admin/index.class.php in MetInfo 7.0.0beta allows a CSRF attack to add a user account via a doSaveSetup action to admin/index.php, a…
Metinfo
No fix yet
HIGH 8.8
CVE-2019-12636
A vulnerability in the web-based management interface of Cisco Small Business Smart and Managed Switches could allow an unauthenticated, remote attac…
Sf250 24 Firmware
2.5.0.90+
HIGH 8.8
CVE-2019-10437
A cross-site request forgery vulnerability in Jenkins CRX Content Package Deployer Plugin 1.8.1 and earlier allowed attackers to connect to an attack…
Crx Content Package Deployer
after 1.8.1
MEDIUM 6.5
CVE-2016-11015
NETGEAR JNR1010 devices before 1.0.0.32 allow cgi-bin/webproc CSRF via the :InternetGatewayDevice.X_TWSZ-COM_URL_Filter.BlackList.1.URL parameter.
Jnr1010 Firmware
1.0.0.32+
CRITICAL 9.8
CVE-2019-17600
Intelbras IWR 1000N 1.6.4 devices allow disclosure of the administrator login name and password because v1/system/user is mishandled.
Iwr 1000n Firmware
No fix yet
HIGH 8.8
CVE-2019-17593
JIZHICMS 1.5.1 allows admin.php/Admin/adminadd.html CSRF to add an administrator.
Jizhicms
No fix yet
MEDIUM 6.5
CVE-2019-17521
An issue was discovered in Landing-CMS 0.0.6. There is a CSRF vulnerability that can change the admin's password via the password/ URI,
Landing Cms
No fix yet
HIGH 8.8
CVE-2018-20582
The GREE+ (aka com.gree.greeplus) application 1.4.0.8 for Android suffers from Cross Site Request Forgery.
Gree\+
No fix yet
CRITICAL 9.8
CVE-2019-17495EPSS 6%
A Cascading Style Sheets (CSS) injection vulnerability in Swagger UI before 3.23.11 allows attackers to use the Relative Path Overwrite (RPO) techniq…
Swagger Ui
3.23.11+
HIGH 8.8
CVE-2019-17386
The animate-it plugin before 2.3.6 for WordPress has CSRF in edsanimate.php.
Animate It\!
2.3.6+
HIGH 8.8
CVE-2019-17431
An issue was discovered in fastadmin 1.0.0.20190705_beta. There is a public/index.php/admin/auth/admin/add CSRF vulnerability.
Fastadmin
No fix yet
MEDIUM 6.5
CVE-2019-17432
An issue was discovered in fastadmin 1.0.0.20190705_beta. There is a public/admin/general.config/edit CSRF vulnerability, as demonstrated by resultan…
Fastadmin
No fix yet
HIGH 8.8
CVE-2019-13529
An attacker could send a malicious link to an authenticated operator, which may allow remote attackers to perform actions with the permissions of the…
Sunny Webbox Firmware
after 1.6
MEDIUM 6.5
CVE-2019-17369
OTCMS v3.85 has CSRF in the admin/member_deal.php Admin Panel page, leading to creation of a new management group account, as demonstrated by superad…
Otcms
No fix yet
HIGH 8.1
CVE-2015-9455
The buddypress-activity-plus plugin before 1.6.2 for WordPress has CSRF with resultant directory traversal via the wp-admin/admin-ajax.php bpfb_photo…
Buddypress Activity Plus
1.6.2+
HIGH 8.8
CVE-2019-17217
An issue was discovered on V-Zug Combi-Steam MSLQ devices before Ethernet R07 and before WLAN R05. There is no CSRF protection established on the web…
Combi Stream Mslq Firmware
Mitigation only
HIGH 8.8
CVE-2019-15040
JetBrains YouTrack versions before 2019.1 had a CSRF vulnerability on the settings page.
Youtrack
2019.1+
MEDIUM 6.5
CVE-2019-1915
A vulnerability in the web-based interface of Cisco Unified Communications Manager, Cisco Unified Communications Manager Session Management Edition (…
Unified Communications Manager
Mitigation only
HIGH 8.8
CVE-2019-16993
In phpBB before 3.1.7-PL1, includes/acp/acp_bbcodes.php has improper verification of a CSRF token on the BBCode page in the Administration Control Pa…
Debian Linux
after 3.1.7
MEDIUM 6.5
CVE-2019-13376
phpBB version 3.2.7 allows the stealing of an Administration Control Panel session id by leveraging CSRF in the Remote Avatar feature. The CSRF Token…
Phpbb
No fix yet
HIGH 8.8
CVE-2019-16667EPSS 55%
diag_command.php in pfSense 2.4.4-p3 allows CSRF via the txtCommand or txtRecallBuffer field, as demonstrated by executing OS commands. This occurs b…
Pfsense
No fix yet
HIGH 8.8
CVE-2015-9445
The unite-gallery-lite plugin before 1.5 for WordPress has CSRF and SQL injection via wp-admin/admin-ajax.php in a unitegallery_ajax_action operation.
Unite Gallery Lite
1.5+
MEDIUM 6.5
CVE-2015-9447
The unite-gallery-lite plugin before 1.5 for WordPress has CSRF and SQL injection via wp-admin/admin.php galleryid or id parameters.
Unite Gallery Lite
1.5+