Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 8.8
CVE-2019-13961
A CSRF vulnerability was found in flatCore before 1.5, leading to the upload of arbitrary .php files via acp/core/files.upload-script.php.
Flatcore
1.5+
HIGH 8.8
CVE-2019-1010112
OECMS v4.3.R60321 and v4.3 later is affected by: Cross Site Request Forgery (CSRF). The impact is: The victim clicks on adding an administrator accou…
Oecms
No fix yet
HIGH 8.8
CVE-2019-13949
SyGuestBook A5 Version 1.2 has no CSRF protection mechanism, as demonstrated by CSRF for an index.php?c=Administrator&a=update admin password change.
Syguestbook A5
No fix yet
HIGH 8.8
CVE-2019-9231
An issue was discovered on AudioCodes Mediant 500L-MSBR, 500-MBSR, M800B-MSBR and 800C-MSBR devices with firmware versions before 7.20A.202.307. A Cr…
Mediant 500l Msbr Firmware
Mitigation only
HIGH 8.8
CVE-2019-1010054
Dolibarr 7.0.0 is affected by: Cross Site Request Forgery (CSRF). The impact is: allow malitious html to change user password, disable users and disa…
Dolibarr Erp\/crm
No fix yet
HIGH 8.8
CVE-2019-1010094
domainmod v4.10.0 is affected by: Cross Site Request Forgery (CSRF). The impact is: There is a CSRF vulnerability that can change admin password. The…
Domainmod
No fix yet
HIGH 8.8
CVE-2019-1010095
DomainMOD v4.10.0 is affected by: Cross Site Request Forgery (CSRF). The impact is: There is a CSRF vulnerability that can add the administrator acco…
Domainmod
No fix yet
HIGH 8.8
CVE-2019-1010096
DomainMOD v4.10.0 is affected by: Cross Site Request Forgery (CSRF). The impact is: There is a CSRF vulnerability that can change the read-only user …
Domainmod
No fix yet
HIGH 7.5
CVE-2019-10353
CSRF tokens in Jenkins 2.185 and earlier, LTS 2.176.1 and earlier did not expire, thereby allowing attackers able to obtain them to bypass CSRF prote…
Jenkins
after 2.185
HIGH 8.8
CVE-2019-13611
An issue was discovered in python-engineio through 3.8.2. There is a Cross-Site WebSocket Hijacking (CSWSH) vulnerability that allows attackers to ma…
Python Engineio
after 3.8.2
HIGH 8.8
CVE-2019-13594
In Mirumee Saleor 2.7.0 (fixed in 2.8.0), CSRF protection middleware was accidentally disabled, which allowed attackers to send a POST request withou…
Saleor
Mitigation only
HIGH 8.8
CVE-2019-13563
D-Link DIR-655 C devices before 3.02B05 BETA03 allow CSRF for the entire management console.
Dir 655 Firmware
No fix yet
HIGH 8.8
CVE-2019-12363
An CSRF issue was discovered in the JN-Jones MyBB-2FA plugin through 2014-11-05 for MyBB. An attacker can forge a request to an installed mybb2fa plu…
Mybb 2fa
after 2014-11-05
HIGH 8.8
CVE-2019-10340
A cross-site request forgery vulnerability in Jenkins Docker Plugin 1.1.6 and earlier in DockerAPI.DescriptorImpl#doTestConnection allowed users with…
Docker
after 1.1.6
HIGH 8.8
CVE-2019-12466
Wikimedia MediaWiki through 1.32.1 allows CSRF.
Debian Linux
after 1.32.1
HIGH 8.8
CVE-2019-13071
CSRF in the Agent/Center component of CyberPower PowerPanel Business Edition 3.4.0 allows an attacker to submit POST requests to any forms in the web…
Powerpanel
No fix yet
HIGH 8.8
CVE-2018-12628
An issue was discovered in Eventum 3.5.0. CSRF in htdocs/manage/users.php allows creating another user with admin privileges.
Eventum
after 3.5.0
MEDIUM 6.5
CVE-2019-12923
In MailEnable Enterprise Premium 10.23, the potential cross-site request forgery (CSRF) protection mechanism was not implemented correctly and it was…
Mailenable
6.90 / 7.62+
HIGH 8.8
CVE-2019-13401
Dynacolor FCM-MB40 v1.2.0.0 devices have CSRF in all scripts under cgi-bin/.
Fcm Mb40 Firmware
No fix yet
HIGH 8.8
CVE-2019-13183
Flarum before 0.1.0-beta.9 allows CSRF against all POST endpoints, as demonstrated by changing admin settings.
Flarum
Mitigation only
HIGH 8.8
CVE-2019-13370
index.php/admin/permissions in Ignited CMS through 2017-02-19 allows CSRF to add an administrator.
Ignitedcms
after 2017-02-19
HIGH 8.8
CVE-2019-5984
Cross-site request forgery (CSRF) vulnerability in Custom CSS Pro 1.0.3 and earlier allows remote attackers to hijack the authentication of administr…
Custom Css Pro
after 1.0.3
HIGH 8.8
CVE-2019-5968
Cross-site request forgery (CSRF) vulnerability in GROWI v3.4.6 and earlier allows remote attackers to hijack the authentication of administrators vi…
Growi
after 3.4.6
HIGH 8.8
CVE-2019-5971
Cross-site request forgery (CSRF) vulnerability in Attendance Manager 0.5.6 and earlier allows remote attackers to hijack the authentication of admin…
Attendance Manager
after 0.5.6
HIGH 8.8
CVE-2019-5973
Cross-site request forgery (CSRF) vulnerability in Online Lesson Booking 0.8.6 and earlier allows remote attackers to hijack the authentication of ad…
Online Lesson Booking
after 0.8.6
HIGH 8.8
CVE-2019-5974
Cross-site request forgery (CSRF) vulnerability in Contest Gallery versions prior to 10.4.5 allows remote attackers to hijack the authentication of a…
Contest Gallery
10.4.5+
HIGH 8.8
CVE-2019-5979
Cross-site request forgery (CSRF) vulnerability in Personalized WooCommerce Cart Page 2.4 and earlier allows remote attackers to hijack the authentic…
Personalized Woocommerce Cart Page
after 2.4
HIGH 8.8
CVE-2019-5980
Cross-site request forgery (CSRF) vulnerability in Related YouTube Videos versions prior to 1.9.9 allows remote attackers to hijack the authenticatio…
Related Youtube Videos
1.9.9+
HIGH 8.8
CVE-2019-5983
Cross-site request forgery (CSRF) vulnerability in HTML5 Maps 1.6.5.6 and earlier allows remote attackers to hijack the authentication of administrat…
Html5 Maps
after 1.6.5.6
HIGH 8.8
CVE-2019-5960
Cross-site request forgery (CSRF) vulnerability in WP Open Graph 1.6.1 and earlier allows remote attackers to hijack the authentication of administra…
Wp Open Graph
after 1.6.1