Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 8.8
CVE-2019-6325
HP Color LaserJet Pro M280-M281 Multifunction Printer series (before v. 20190419), HP LaserJet Pro MFP M28-M31 Printer series (before v. 20190426) ma…
T6b80a Firmware
2019-04-19 / 2019-04-26+
MEDIUM 6.5
CVE-2019-0996
A spoofing vulnerability exists in Azure DevOps Server when it improperly handles requests to authorize applications, resulting in a cross-site reque…
Azure Devops Server
Patch available
HIGH 8.8
CVE-2019-3410
All versions up to UKBB_WF820+_1.0.0B06 of ZTE WF820+ LTE Outdoor CPE product are impacted by Cross-Site Request Forgery vulnerability,which stems fr…
Wf820\+ Lte Outdoor Cpe Firmware
1.0.0b06+
HIGH 8.8
CVE-2019-10338
A cross-site request forgery vulnerability in Jenkins JX Resources Plugin 1.0.36 and earlier in GlobalPluginConfiguration#doValidateClient allowed at…
Jx Resources
after 1.0.36
MEDIUM 6.5
CVE-2019-11517
WampServer before 3.1.9 has CSRF in add_vhost.php because the synchronizer pattern implemented as remediation of CVE-2018-8817 was incomplete. An att…
Wampserver
3.1.9+
HIGH 8.8
CVE-2018-10696
An issue was discovered on Moxa AWK-3121 1.14 devices. The device provides a web interface to allow an administrator to manage the device. However, t…
Awk 3121 Firmware
No fix yet
HIGH 8.8
CVE-2019-1881
A vulnerability in the web-based management interface of Cisco Industrial Network Director (IND) could allow an unauthenticated, remote attacker to c…
Industrial Network Director
Mitigation only
MEDIUM 6.5
CVE-2019-12616EPSS 19%
An issue was discovered in phpMyAdmin before 4.9.0. A vulnerability was found that allows an attacker to trigger a CSRF attack against a phpMyAdmin u…
phpMyAdmin
4.9.0+
HIGH 8.8
CVE-2019-9882
Multi modules of MailSherlock MSR35 and MSR45 lead to a CSRF vulnerability. It allows attacker to add malicious email sources into whitelist via user…
Msr35 Isherlock Base
1.5.127 / 1.5.196+
HIGH 8.8
CVE-2019-9883
Multi modules of MailSherlock MSR35 and MSR45 lead to a CSRF vulnerability. It allows attacker to elevate privilege of specific account via useradmin…
Msr35 Isherlock Base
1.5.127 / 1.5.196+
MEDIUM 6.5
CVE-2019-10324
A cross-site request forgery vulnerability in Jenkins Artifactory Plugin 3.2.2 and earlier in ReleaseAction#doSubmit, GradleReleaseApiAction#doStagin…
Artifactory
after 3.2.2
HIGH 8.8
CVE-2019-12502
There is a lack of CSRF countermeasures on MOBOTIX S14 MX-V4.2.1.61 cameras, as demonstrated by adding an admin account via the /admin/access URI.
S14 Firmware
No fix yet
HIGH 8.8
CVE-2018-16218
A CSRF (Cross Site Request Forgery) in the web interface of the Yeahlink Ultra-elegant IP Phone SIP-T41P firmware version 66.83.0.35 allows a remote …
Ultra Elegant Ip Phone Sip T41p Firmware
No fix yet
MEDIUM 6.1
CVE-2019-12361
EmpireCMS 7.5.0 has XSS via the from parameter to e/member/doaction.php, as demonstrated by a CSRF payload that changes the dynamic page template. Th…
Empirecms
No fix yet
HIGH 8.8
CVE-2016-10756
Kliqqi 3.0.0.5 allows CSRF with resultant Arbitrary File Upload because module.php?module=upload can be used to configure the uploading of .php files…
Kliqqi Cms
No fix yet
HIGH 8.8
CVE-2016-10757
In Redaxo 5.2.0, the cron management of the admin panel suffers from CSRF that leads to arbitrary Remote Code Execution via addons/cronjob/lib/types/…
Readaxo
No fix yet
MEDIUM 6.5
CVE-2018-19613
Westermo DR-250 Pre-5162 and DR-260 Pre-5162 routers allow CSRF.
Dr 260 Firmware
No fix yet
HIGH 8.8
CVE-2019-10847
Computrols CBAS 18.0.0 allows Cross-Site Request Forgery.
Computrols Building Automation Software
after 19.0.0
HIGH 8.8
CVE-2018-7828
A Cross-Site Request Forgery (CSRF) vulnerability exists in the 1st Gen. Pelco Sarix Enhanced Camera and Spectra Enhanced PTZ Camera when an authenti…
D6220 Firmware
2.2.3.0+
MEDIUM 6.5
CVE-2019-12253
my little forum before 2.4.20 allows CSRF to delete posts, as demonstrated by mode=posting&delete_posting.
My Little Forum
2.4.20+
HIGH 7.2
CVE-2019-12239
The WP Booking System plugin 1.5.1 for WordPress has no CSRF protection, which allows attackers to reach certain SQL injection issues that require ad…
Wp Booking System
1.5.2+
HIGH 8.8
CVE-2018-16136
An issue was discovered in the administrator interface in IPBRICK OS 6.3. The application doesn't check for Anti-CSRF tokens, allowing the submission…
Ipbrick Os
No fix yet
MEDIUM 6.5
CVE-2018-14711
Missing cross-site request forgery protection in appGet.cgi on ASUS RT-AC3200 version 3.0.0.4.382.50010 allows attackers to cause state-changing acti…
Rt Ac3200 Firmware
No fix yet
HIGH 8.8
CVE-2019-11886
The WaspThemes Visual CSS Style Editor (aka yellow-pencil-visual-theme-customizer) plugin before 7.2.1 for WordPress allows yp_option_update CSRF, as…
Visual Css Style Editor
7.2.1+
HIGH 8.8
CVE-2018-1790
IBM Financial Transaction Manager for Digital Payments for Multi-Platform 3.0.2 is vulnerable to cross-site request forgery which could allow an atta…
Financial Transaction Manager
after 3.0.2.1
HIGH 8.8
CVE-2017-12789
Metinfo 5.3.18 is affected by: Cross Site Request Forgery (CSRF). The impact is: Information Disclosure (remote). The component is: admin/interface/o…
Metinfo
No fix yet
MEDIUM 6.5
CVE-2017-12790
Metinfo 5.3.18 is affected by: Cross Site Request Forgery (CSRF). The impact is: Information Disclosure (remote). The component is: admin/index.php. …
Metinfo
No fix yet
HIGH 8.1
CVE-2019-7746
JioFi 4 jmr1140 Amtel_JMR1140_R12.07 devices allow remote attackers to obtain an admin token by making a /cgi-bin/qcmap_auth type=getuser request and…
Jmr1140 Firmware
No fix yet
HIGH 8.8
CVE-2018-2001
IBM Cram Social Program Management 6.1.1, 6.2.0, 7.0.4, and 7.0.5 is vulnerable to cross-site request forgery which could allow an attacker to execut…
Curam Social Program Management
after 7.0.4.0
HIGH 8.8
CVE-2018-13993
The WebUI of PHOENIX CONTACT FL SWITCH 3xxx, 4xxx, 48xx versions 1.0 to 1.34 is prone to CSRF.
Fl Switch 3005 Firmware
after 1.34