Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 8.1
CVE-2019-14526
An issue was discovered on NETGEAR Nighthawk M1 (MR1100) devices before 12.06.03. The web-interface Cross-Site Request Forgery token is stored in a d…
Mr1100 Firmware
12.06.03+
HIGH 8.8
CVE-2019-10199
It was found that Keycloak's account console, up to 6.0.1, did not perform adequate header checks in some requests. An attacker could use this flaw t…
Keycloak
after 6.0.1
HIGH 8.8
CVE-2017-18510
The custom-sidebars plugin before 3.1.0 for WordPress has CSRF related to set location, import actions, and export actions.
Custom Sidebars
3.1.0+
HIGH 8.8
CVE-2017-18511
The custom-sidebars plugin before 3.0.8.1 for WordPress has CSRF.
Custom Sidebars
3.0.8.1+
HIGH 8.8
CVE-2017-18512
The newsletter-by-supsystic plugin before 1.1.8 for WordPress has CSRF.
Newsletter By Supsystic
1.1.8+
HIGH 8.8
CVE-2017-18513
The responsive-menu plugin before 3.1.4 for WordPress has no CSRF protection mechanism for the admin interface.
Responsive Menu
3.1.4+
HIGH 8.8
CVE-2018-20967
The wp-ultimate-csv-importer plugin before 5.6.1 for WordPress has CSRF.
Import All Pages\, Post Types\, Products\, Orders\, And Users As Xml \& Csv
5.6.1+
HIGH 8.8
CVE-2018-20968
The wp-ultimate-exporter plugin before 1.4.2 for WordPress has CSRF.
Ultimate Exporter
1.4.2+
HIGH 8.8
CVE-2013-7476
The simple-fields plugin before 1.2 for WordPress has CSRF in the admin interface.
Simple Fields
1.2+
HIGH 8.8
CVE-2015-9307
The wp-google-map-plugin plugin before 2.3.10 for WordPress has CSRF in the add/edit location feature.
Wp Maps
2.3.10+
HIGH 8.8
CVE-2015-9308
The wp-google-map-plugin plugin before 2.3.10 for WordPress has CSRF in the add/edit map feature.
Wp Maps
2.3.10+
HIGH 8.8
CVE-2015-9309
The wp-google-map-plugin plugin before 2.3.10 for WordPress has CSRF in the add/edit category feature.
Wp Maps
2.3.10+
HIGH 8.8
CVE-2016-10882
The google-document-embedder plugin before 2.6.2 for WordPress has CSRF.
Google Doc Embedder
2.6.2+
MEDIUM 6.5
CVE-2016-10883
The simple-add-pages-or-posts plugin before 1.7 for WordPress has CSRF for deleting users.
Simple Add Pages Or Posts
1.7+
HIGH 8.8
CVE-2016-10884
The simple-membership plugin before 3.3.3 for WordPress has multiple CSRF issues.
Simple Membership
3.3.3+
HIGH 8.8
CVE-2016-10885
The wp-editor plugin before 1.2.6 for WordPress has CSRF.
Wp Editor
1.2.6+
HIGH 8.8
CVE-2019-11207
The web server component of TIBCO Software Inc.'s TIBCO LogLogic Enterprise Virtual Appliance, and TIBCO LogLogic Log Management Intelligence contain…
Loglogic Enterprise Virtual Appliance
after 6.2.1
HIGH 8.8
CVE-2018-20964
The contact-form-to-email plugin before 1.2.66 for WordPress has CSRF.
Contact Form Email
1.2.66+
HIGH 8.8
CVE-2017-18504
The twitter-cards-meta plugin before 2.5.0 for WordPress has CSRF.
Twitter Cards Meta
2.5.0+
HIGH 8.8
CVE-2016-10874
The wp-database-backup plugin before 4.3.3 for WordPress has CSRF.
Wp Database Backup
4.3.3+
HIGH 8.8
CVE-2016-10876
The wp-database-backup plugin before 4.3.1 for WordPress has CSRF.
Wp Database Backup
4.3.1+
HIGH 8.8
CVE-2019-14933
Bagisto 0.1.5 allows CSRF under /admin URIs.
Bagisto
No fix yet
MEDIUM 6.1
CVE-2016-10865
The Lightbox Plus Colorbox plugin through 2.7.2 for WordPress has cross-site request forgery (CSRF) via wp-admin/admin.php?page=lightboxplus, as demo…
Lightbox Plus Colorbox
after 2.7.2
HIGH 8.8
CVE-2016-10862
Neet AirStream NAS1.1 devices have a password of ifconfig for the root account. This cannot be changed via the configuration page.
Airstream Nas Firmware
No fix yet
HIGH 8.8
CVE-2016-10863
Edimax Wi-Fi Extender devices allow goform/formwlencryptvxd CSRF with resultant PSK key disclosure.
Ew 7438rpn Mini Firmware
No fix yet
MEDIUM 5.4
CVE-2017-18485
Cognitoys Dino devices allow profiles_add.html CSRF.
Cognitoys Dino Firmware
No fix yet
HIGH 8.8
CVE-2015-9292
6kbbs 7.1 and 8.0 allows CSRF via portalchannel_ajax.php (id or code parameter) or admin.php (fileids parameter).
6kbbs
No fix yet
MEDIUM 5.7
CVE-2019-14683
The codection "Import users from CSV with meta" plugin before 1.14.2.2 for WordPress allows wp-admin/admin-ajax.php?action=acui_delete_attachment CSR…
Import Users From Csv With Meta
1.14.2.2+
MEDIUM 6.5
CVE-2019-14679
core/views/arprice_import_export.php in the ARPrice Lite plugin 2.2 for WordPress allows wp-admin/admin.php?page=arplite_import_export CSRF.
Arprice Lite
No fix yet
MEDIUM 5.7
CVE-2019-14680
The admin-renamer-extended (aka Admin renamer extended) plugin 3.2.1 for WordPress allows wp-admin/plugins.php?page=admin-renamer-extended/admin.php …
Admin Renamer Extended
No fix yet