Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 8.8
CVE-2019-15865
The breadcrumbs-by-menu plugin before 1.0.3 for WordPress has CSRF.
Breadcrumbs By Menu
1.0.3+
HIGH 8.8
CVE-2019-15868
The affiliates-manager plugin before 2.6.6 for WordPress has CSRF.
Affiliates Manager
2.6.6+
HIGH 8.8
CVE-2019-15834
The webp-converter-for-media plugin before 1.0.3 for WordPress has CSRF.
Webp Converter For Media
1.0.3+
HIGH 8.8
CVE-2019-15835
The wp-better-permalinks plugin before 3.0.5 for WordPress has CSRF.
Wp Better Permalinks
3.0.5+
HIGH 8.8
CVE-2019-15840
The facebook-for-woocommerce plugin before 1.9.14 for WordPress has CSRF.
Facebook For Woocommerce
1.9.14+
HIGH 8.8
CVE-2019-15841
The facebook-for-woocommerce plugin before 1.9.15 for WordPress has CSRF via ajax_woo_infobanner_post_click, ajax_woo_infobanner_post_xout, or ajax_f…
Facebook For Woocommerce
1.9.15+
HIGH 8.8
CVE-2019-15828
The one-click-ssl plugin before 1.4.7 for WordPress has CSRF.
One Click Ssl
1.4.7+
HIGH 8.8
CVE-2019-15831
The visitors-traffic-real-time-statistics plugin before 1.12 for WordPress has CSRF in the settings page.
Visitor Traffic Real Time Statistics
1.12+
HIGH 8.8
CVE-2019-15832
The visitors-traffic-real-time-statistics plugin before 1.13 for WordPress has CSRF.
Visitor Traffic Real Time Statistics
1.13+
HIGH 8.8
CVE-2015-9380
The photo-gallery plugin before 1.2.42 for WordPress has CSRF.
Photo Gallery
1.2.42+
HIGH 8.8
CVE-2019-15779
The insta-gallery plugin before 2.4.8 for WordPress has no nonce validation for qligg_dismiss_notice or qligg_form_item_delete.
Wp Social Feed Gallery
2.4.8+
HIGH 8.8
CVE-2019-15781
The facebook-by-weblizar plugin before 2.8.5 for WordPress has CSRF.
Social Likebox \& Feed
2.8.5+
HIGH 8.8
CVE-2019-15769
The handl-utm-grabber plugin before 2.6.5 for WordPress has CSRF via add_option and update_option.
Handl Utm Grabber
2.6.5+
HIGH 8.8
CVE-2019-15770
The woo-address-book plugin before 1.6.0 for WordPress has save calls without nonce verification checks.
Woocommerce Address Book
1.6.0+
MEDIUM 6.5
CVE-2019-10057
Various Lexmark products have CSRF.
Cs31x Firmware
No fix yet
HIGH 8.8
CVE-2019-15496
MyT Project Management 1.5.1 lacks CSRF protection and, for example, allows a user/create CSRF attack. This could lead to an attacker tricking the ad…
Myt Project Management
No fix yet
HIGH 8.8
CVE-2019-10384
Jenkins 2.191 and earlier, LTS 2.176.2 and earlier allowed users to obtain CSRF tokens without an associated web session ID, resulting in CSRF tokens…
Jenkins
after 2.191
HIGH 8.8
CVE-2019-11457
Multiple CSRF issues exist in MicroPyramid Django CRM 0.2.1 via /change-password-by-admin/, /api/settings/add/, /cases/create/, /change-password-by-a…
Django Crm
No fix yet
HIGH 8.8
CVE-2019-15660
The wp-members plugin before 3.2.8 for WordPress has CSRF.
Wp Members
3.2.8+
MEDIUM 6.5
CVE-2019-15648
The insert-or-embed-articulate-content-into-wordpress plugin before 4.29991 for WordPress has insufficient restrictions on deleting or renaming by a …
Insert Or Embed Articulate Content
4.29991+
HIGH 8.8
CVE-2018-21002
The js-support-ticket plugin before 2.0.6 for WordPress has CSRF.
Js Help Desk
2.0.6+
HIGH 8.8
CVE-2018-21006
The bbp-move-topics plugin before 1.1.6 for WordPress has CSRF.
Bbpress Move Topics
1.1.6+
HIGH 8.8
CVE-2019-15645
The zoho-salesiq plugin before 1.0.9 for WordPress has CSRF.
Salesiq
1.0.9+
HIGH 8.8
CVE-2015-9343
The wp-rollback plugin before 1.2.3 for WordPress has CSRF.
Wp Rollback
1.2.3+
MEDIUM 6.5
CVE-2019-15515
Discourse 2.3.2 sends the CSRF token in the query string.
Discourse
Patch available
MEDIUM 6.5
CVE-2019-11587
Various exposed resources of the ViewLogging class in Jira before version 7.13.6, from version 8.0.0 before version 8.2.3, and from version 8.3.0 bef…
Jira
7.13.6 / 8.2.3+
HIGH 8.8
CVE-2019-15491
openITCOCKPIT before 3.7.1 has CSRF, aka RVID 2-445b21.
Openitcockpit
3.7.1+
HIGH 8.8
CVE-2019-15329
The import-users-from-csv-with-meta plugin before 1.14.0.3 for WordPress has CSRF.
Import Users From Csv With Meta
1.14.0.3+
HIGH 8.8
CVE-2016-10918
The gallery-by-supsystic plugin before 1.8.6 for WordPress has CSRF.
Photo Gallery
1.8.6+
HIGH 8.8
CVE-2019-12624EPSS 18%
A vulnerability in the web-based management interface of Cisco IOS XE New Generation Wireless Controller (NGWC) could allow an unauthenticated, remot…
Ios Xe
after 3.11.xe