Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 8.8
CVE-2015-9394
The users-ultra plugin before 1.5.63 for WordPress has CSRF via action=package_add_new to wp-admin/admin-ajax.php.
Users Ultra Membership
1.5.63+
MEDIUM 6.5
CVE-2016-10997
The beauty-premium theme 1.0.8 for WordPress has CSRF with resultant arbitrary file upload in includes/sendmail.php.
Beauty Premium
No fix yet
MEDIUM 6.5
CVE-2015-9387
The mtouch-quiz plugin before 3.1.3 for WordPress has wp-admin/options-general.php CSRF.
Mtouch Quiz
3.1.3+
MEDIUM 6.5
CVE-2015-9388
The mtouch-quiz plugin before 3.1.3 for WordPress has wp-admin/edit.php CSRF with resultant XSS.
Mtouch Quiz
3.1.3+
HIGH 8.8
CVE-2019-15089
An issue was discovered in PRiSE adAS 1.7.0. Forms have no CSRF protection, letting an attacker execute actions as the administrator.
Adas
Mitigation only
HIGH 8.8
CVE-2019-16531
LayerBB before 1.1.4 has multiple CSRF issues, as demonstrated by changing the System Settings via admin/general.php.
Layerbb
1.1.4+
HIGH 8.8
CVE-2016-10989
The leenkme plugin before 2.6.0 for WordPress has wp-admin/admin.php?page=leenkme_facebook CSRF.
Leenk.me
2.6.0+
HIGH 8.8
CVE-2016-10974
The fluid-responsive-slideshow plugin before 2.2.7 for WordPress has frs_save CSRF with resultant stored XSS.
Fluid Responsive Slideshow
2.2.7+
HIGH 8.8
CVE-2016-10978
The fossura-tag-miner plugin before 1.1.5 for WordPress has CSRF.
Tag Miner
after 1.1.2
HIGH 8.8
CVE-2016-10982
The kento-post-view-counter plugin through 2.8 for WordPress has wp-admin/admin.php?page=kentopvc_settings CSRF.
Kento Post View Counter
after 2.8
MEDIUM 6.5
CVE-2016-10962
The icegram plugin before 1.9.19 for WordPress has CSRF via the wp-admin/edit.php option_name parameter.
Icegram Engage
1.9.19+
HIGH 8.8
CVE-2019-16311
NIUSHOP V1.11 has CSRF via search_info to index.php.
Niushop
No fix yet
MEDIUM 6.5
CVE-2019-12922EPSS 10%
A CSRF issue in phpMyAdmin 4.9.0.1 allows deletion of any server in the Setup page.
Fedora
after 4.9.0.1
CRITICAL 9.6
CVE-2019-13363
admin.php?page=notification_by_mail in Piwigo 2.9.5 has XSS via the nbm_send_html_mail, nbm_send_mail_as, nbm_send_de…
Piwigo
No fix yet
CRITICAL 9.6
CVE-2019-13364
admin.php?page=account_billing in Piwigo 2.9.5 has XSS via the vat_number, billing_name, company, or billing_address parameter. This is e…
Piwigo
No fix yet
HIGH 8.8
CVE-2016-10946
The wp-d3 plugin before 2.4.1 for WordPress has CSRF.
Wp D3
2.4.1+
HIGH 8.8
CVE-2016-10944
The multisite-post-duplicator plugin before 1.1.3 for WordPress has wp-admin/tools.php?page=mpd CSRF.
Multisite Post Duplicator
1.1.3+
HIGH 8.8
CVE-2016-10945
The PageLines theme 1.1.4 for WordPress has wp-admin/admin-post.php?page=pagelines CSRF.
Pagelines
after 1.1.4
MEDIUM 6.5
CVE-2016-10938
The copy-me plugin 1.0.0 for WordPress has CSRF for copying non-public posts to a public location.
Copy Me
No fix yet
HIGH 8.8
CVE-2019-5986
Cross-site request forgery (CSRF) vulnerability in Hikari Denwa router/Home GateWay (Hikari Denwa router/Home GateWay provided by NIPPON TELEGRAPH AN…
Pr S300ne Firmware
after 19.41
HIGH 8.8
CVE-2019-5992
Cross-site request forgery (CSRF) vulnerability in WordPress Ultra Simple Paypal Shopping Cart v4.4 and earlier allows remote attackers to hijack the…
Wordpress Ultra Simple Paypal Shopping Cart
after 4.4
HIGH 8.8
CVE-2019-5993
Cross-site request forgery (CSRF) vulnerability in Category Specific RSS feed Subscription version v2.0 and earlier allows remote attackers to hijack…
Category Specific Rss Feed Subscription
after 2.0
HIGH 8.8
CVE-2019-1259
A spoofing vulnerability exists in Microsoft SharePoint when it improperly handles requests to authorize applications, resulting in cross-site reques…
Sharepoint Foundation
Patch available
HIGH 8.8
CVE-2019-1261
A spoofing vulnerability exists in Microsoft SharePoint when it improperly handles requests to authorize applications, resulting in cross-site reques…
Sharepoint Enterprise Server
Patch available
MEDIUM 6.5
CVE-2019-14998
The Webwork action Cross-Site Request Forgery (CSRF) protection implementation in Jira before version 8.4.0 allows remote attackers to bypass its pro…
Jira Server
8.4.0+
HIGH 8.8
CVE-2017-18607
The avada theme before 5.1.5 for WordPress has CSRF.
Avada
5.1.5+
MEDIUM 6.5
CVE-2019-10253
A Cross-Site Request Forgery (CSRF) vulnerability exists in TeamMate+ 21.0.0.0 that allows a remote attacker to modify application data (upload malic…
Teammate\+
No fix yet
HIGH 8.8
CVE-2019-16099
Silver Peak EdgeConnect SD-WAN before 8.1.7.x allows CSRF via JSON data to a .swf file.
Unity Edgeconnect Sd Wan Firmware
No fix yet
MEDIUM 6.5
CVE-2019-15128
iF.SVNAdmin through 1.6.2 allows svnadmin/usercreate.php CSRF to create a user.
If.svnadmin
after 1.6.2
HIGH 8.8
CVE-2019-16059
Sentrifugo 3.2 lacks CSRF protection. This could lead to an attacker tricking the administrator into executing arbitrary code at index.php/dashboard/…
Sentrifugo
No fix yet