Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 8.8
CVE-2019-5963
Cross-site request forgery (CSRF) vulnerability in Zoho SalesIQ 1.0.8 and earlier allows remote attackers to hijack the authentication of administrat…
Salesiq
after 1.0.8
HIGH 8.4
CVE-2019-6636
On BIG-IP (AFM, ASM) 14.1.0-14.1.0.5, 14.0.0-14.0.0.4, 13.0.0-13.1.1.4, 12.1.0-12.1.4, and 11.5.1-11.6.4, a stored cross-site scripting vulnerability…
Big Ip Advanced Firewall Manager
12.1.4.1 / 13.1.1.5+
HIGH 8.8
CVE-2019-12851
A CSRF vulnerability was detected in one of the admin endpoints of JetBrains YouTrack. The issue was fixed in YouTrack 2018.4.49852.
Youtrack
2018.4.49852+
HIGH 8.8
CVE-2019-5630
A Cross-Site Request Forgery (CSRF) vulnerability was found in Rapid7 Nexpose InsightVM Security Console versions 6.5.0 through 6.5.68. This issue al…
Nexpose
after 6.5.68
HIGH 8.8
CVE-2018-10986
OX Guard 2.8.0 has CSRF.
Ox Guard
Mitigation only
HIGH 8.8
CVE-2018-11427
CSRF tokens are not used in the web application of Moxa OnCell G3100-HSPA Series version 1.4 Build 16062919 and prior, which makes it possible to per…
Oncell G3150 Hspa Firmware
after 1.4
HIGH 8.8
CVE-2017-8406
An issue was discovered on D-Link DCS-1130 devices. The device provides a crossdomain.xml file with no restrictions on who can access the webserver. …
Dcs 1130 Firmware
No fix yet
HIGH 8.8
CVE-2017-8407
An issue was discovered on D-Link DCS-1130 devices. The device provides a user with the capability of changing the administrative password for the we…
Dcs 1130 Firmware
No fix yet
HIGH 8.8
CVE-2019-7262EPSS 16%
Linear eMerge E3-Series devices allow Cross-Site Request Forgery (CSRF).
Linear Emerge Essential Firmware
after 1.00-06
HIGH 8.8
CVE-2019-7270
Linear eMerge 50P/5000P devices allow Cross-Site Request Forgery (CSRF).
Linear Emerge 50p Firmware
after 4.6.07
HIGH 8.8
CVE-2019-13056
An issue was discovered in CyberPanel through 1.8.4. On the user edit page, an attacker can edit the administrator's e-mail and password because of t…
Cyberpanel
after 1.8.4
HIGH 8.8
CVE-2019-7273
Optergy Proton/Enterprise devices allow Cross-Site Request Forgery (CSRF).
Enterprise
after 2.3.0a
HIGH 8.8
CVE-2019-7281
Prima Systems FlexAir, Versions 2.3.38 and prior. An unauthenticated user can send unverified HTTP requests, which may allow the attacker to perform …
Flexair
after 2.3.38
HIGH 8.8
CVE-2019-12826
A Cross-Site-Request-Forgery (CSRF) vulnerability in widget_logic.php in the 2by2host Widget Logic plugin before 5.10.2 for WordPress allows remote a…
Widget Logic
5.10.2+
HIGH 8.8
CVE-2018-20848
Advisto PEEL SHOPPING 9.0.0 has CSRF via en/achat/caddie_ajout.php and en/achat/caddie_affichage.php, as demonstrated by an XSS payload in the couleu…
Peel Shopping
No fix yet
MEDIUM 6.5
CVE-2019-5814
Insufficient policy enforcement in Blink in Google Chrome prior to 74.0.3729.108 allowed a remote attacker to leak cross-origin data via a crafted HT…
Chrome
74.0.3729.108+
HIGH 8.8
CVE-2019-6166
A vulnerability reported in Lenovo Service Bridge before version 4.1.0.1 could allow cross-site request forgery.
Service Bridge
4.1.0.1+
HIGH 8.8
CVE-2018-1858
IBM API Connect 5.0.0.0 through 5.0.8.6 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthoriz…
Api Connect
after 5.0.8.6
HIGH 8.8
CVE-2019-9958
CSRF within the admin panel in Quadbase EspressReport ES (ERES) v7.0 update 7 allows remote attackers to escalate privileges, or create new admin acc…
Espressreport Enterprise Server
No fix yet
HIGH 8.8
CVE-2019-12836
The Bobronix JEditor editor before 3.0.6 for Jira allows an attacker to add a URL/Link (to an existing issue) that can cause forgery of a request to …
Jeditor
3.0.6+
HIGH 8.8
CVE-2019-1904
A vulnerability in the web-based UI (web UI) of Cisco IOS XE Software could allow an unauthenticated, remote attacker to conduct a cross-site request…
Ios Xe
Mitigation only
HIGH 8.8
CVE-2019-1874
A vulnerability in the web-based management interface of Cisco Prime Service Catalog Software could allow an unauthenticated, remote attacker to cond…
Prime Service Catalog
Patch available
HIGH 8.0
CVE-2019-1632
A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) could allow an authenticated, remote attacker t…
Integrated Management Controller
Mitigation only
HIGH 8.8
CVE-2018-17387
CSRF exists in Nimble Messaging Bulk SMS Marketing Application 1.0 for adding an admin account.
Nimble Professional
No fix yet
HIGH 8.8
CVE-2018-17389
CSRF exists in server.php in Live Call Support Application 1.5 for adding an admin account.
Live Call Support
No fix yet
HIGH 8.8
CVE-2017-8328
An issue was discovered on Securifi Almond, Almond+, and Almond 2015 devices with firmware AL-R096. The device provides a user with the capability of…
Almond 2015 Firmware
No fix yet
HIGH 8.0
CVE-2017-8334
An issue was discovered on Securifi Almond, Almond+, and Almond 2015 devices with firmware AL-R096. The device provides a user with the capability of…
Almond 2015 Firmware
No fix yet
HIGH 8.8
CVE-2018-18802
The Tubigan "Welcome to our Resort" 1.0 software allows CSRF via admin/mod_users/controller.php?action=edit.
Welcome To Our Resort
No fix yet
HIGH 8.8
CVE-2019-4142
IBM Cloud Private 2.1.0, 3.1.0, 3.1.1, and 3.1.2 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and u…
Cloud Private
after 2.1.0.3
HIGH 8.8
CVE-2017-9381
An issue was discovered on Vera VeraEdge 1.7.19 and Veralite 1.7.481 devices. The device provides a user with the capability of installing or deletin…
Veraedge Firmware
after 1.7.481