Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 8.8
CVE-2019-11569
Veeam ONE Reporter 9.5.0.3201 allows CSRF.
One Reporter
No fix yet
HIGH 8.8
CVE-2018-4066
An exploitable cross-site request forgery vulnerability exists in the ACEManager functionality of Sierra Wireless AirLink ES450 FW 4.9.3. A specially…
Airlink Es450 Firmware
No fix yet
HIGH 8.8
CVE-2019-5430
In UniFi Video 3.10.0 and prior, due to the lack of CSRF protection, it is possible to abuse the Web API to make changes on the server configuration …
Unifi Video
after 3.10.0
MEDIUM 5.4
CVE-2019-5431
This vulnerability was caused by an incomplete fix to CVE-2017-0911. Twitter Kit for iOS versions 3.0 to 3.4.0 is vulnerable to a callback verificati…
Twitter Kit
after 3.4.0
HIGH 8.8
CVE-2019-1857
A vulnerability in the web-based management interface of Cisco HyperFlex HX-Series could allow an unauthenticated, remote attacker to conduct a cross…
Hx220c M5 Firmware
Mitigation only
HIGH 8.8
CVE-2019-1713
A vulnerability in the web-based management interface of Cisco Adaptive Security Appliance (ASA) Software could allow an unauthenticated, remote atta…
Adaptive Security Appliance Software
9.4.4.34 / 9.6.4.25+
HIGH 8.8
CVE-2019-11617
doorGets 7.0 has a CSRF vulnerability in /doorgets/app/requests/user/configurationRequest.php. A remote attacker can exploit this vulnerability for "…
Doorgets Cms
No fix yet
MEDIUM 6.1
CVE-2019-11193
The FileManager in InfinitumIT DirectAdmin through v1.561 has XSS via CMD_FILE_MANAGER, CMD_SHOW_USER, and CMD_SHOW_RESELLER; an attacker can bypass …
Directadmin
after 1.561
HIGH 8.8
CVE-2018-14930
An issue was discovered in the Armor module in Polaris FT Intellect Core Banking 9.7.1. CSRF can occur via a /CollatWebApp/gcmsRefInsert?name=SUPP UR…
Intellect Core Banking
No fix yet
HIGH 8.8
CVE-2018-15206
BPC SmartVista 2 has CSRF via SVFE2/pages/admpages/roles/createrole.jsf.
Smartvista
No fix yet
MEDIUM 6.5
CVE-2019-10307
A cross-site request forgery vulnerability in Jenkins Static Analysis Utilities Plugin 1.95 and earlier in the DefaultGraphConfigurationView#doSave f…
Static Analysis Utilities
after 1.95
HIGH 8.8
CVE-2019-10310
A cross-site request forgery vulnerability in Jenkins Ansible Tower Plugin 0.9.1 and earlier in the TowerInstallation.TowerInstallationDescriptor#doT…
Ansible Tower
after 0.9.1
HIGH 8.8
CVE-2019-10315
Jenkins GitHub Authentication Plugin 0.31 and earlier did not use the state parameter of OAuth to prevent CSRF.
Github Authentication
after 0.31
HIGH 8.8
CVE-2018-5123
A third party website can access information available to a user with access to a restricted bug entry using the image generation in report.cgi in al…
Bugzilla
4.4+
HIGH 8.8
CVE-2019-11590
The 10Web Form Maker plugin before 1.13.5 for WordPress allows CSRF via the wp-admin/admin-ajax.php action parameter, with resultant local file inclu…
Form Maker
1.13.5+
HIGH 8.8
CVE-2019-11591
The WebDorado Contact Form plugin before 1.13.5 for WordPress allows CSRF via the wp-admin/admin-ajax.php action parameter, with resultant local file…
Contact Form
1.13.5+
HIGH 8.8
CVE-2019-11557
The WebDorado Contact Form Builder plugin before 1.0.69 for WordPress allows CSRF via the wp-admin/admin-ajax.php action parameter, with resultant lo…
Wp Form Builder
1.0.69+
HIGH 8.8
CVE-2015-9284
The request phase of the OmniAuth Ruby gem (1.9.1 and earlier) is vulnerable to Cross-Site Request Forgery when used as part of the Ruby on Rails fra…
Omniauth
2.0.0+
HIGH 8.8
CVE-2019-8991
The administrator web interface of TIBCO Software Inc.'s TIBCO ActiveMatrix BPM, TIBCO ActiveMatrix BPM Distribution for TIBCO Silver Fabric, TIBCO A…
Activematrix Bpm
after 4.2.0
MEDIUM 6.1
CVE-2019-11203
The workspace client, openspace client, app development client, and REST API of TIBCO Software Inc.'s TIBCO ActiveMatrix BPM, TIBCO ActiveMatrix BPM …
Activematrix Business Process Management
after 4.2.0
HIGH 8.8
CVE-2019-11456
Gila CMS 1.10.1 allows fm/save CSRF for executing arbitrary PHP code.
Gila Cms
No fix yet
HIGH 8.8
CVE-2019-11416
A CSRF issue was discovered on Intelbras IWR 3000N 1.5.0 devices, leading to complete control of the router, as demonstrated by v1/system/user.
Iwr 3000n Firmware
No fix yet
HIGH 8.8
CVE-2019-11374EPSS 10%
74CMS v5.0.1 has a CSRF vulnerability to add a new admin user via the index.php?m=Admin&c=admin&a=add URI.
74cms
No fix yet
MEDIUM 6.5
CVE-2019-11375
Msvod v10 has a CSRF vulnerability to change user information via the admin/member/edit.html URI.
Msvod
No fix yet
HIGH 8.8
CVE-2019-3718
Dell SupportAssist Client versions prior to 3.2.0.90 contain an improper origin validation vulnerability. An unauthenticated remote attacker could po…
Supportassist
3.2.0.90+
MEDIUM 6.5
CVE-2018-17168
PrinterOn Enterprise 4.1.4 contains multiple Cross Site Request Forgery (CSRF) vulnerabilities in the Administration page. For example, an administra…
Printeron
No fix yet
HIGH 8.0
CVE-2019-10300
A cross-site request forgery vulnerability in Jenkins GitLab Plugin 1.5.11 and earlier in the GitLabConnectionConfig#doTestConnection form validation…
GitLab
after 1.5.11
MEDIUM 6.5
CVE-2019-10304
A cross-site request forgery vulnerability in Jenkins XebiaLabs XL Deploy Plugin in the Credential#doValidateUserNamePassword form validation method …
Xebialabs Xl Deploy
after 7.5.3
MEDIUM 6.5
CVE-2019-1722
A vulnerability in the FindMe feature of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an unauthenticat…
Expressway Series
Mitigation only
HIGH 8.8
CVE-2019-1797
A vulnerability in the web-based management interface of Cisco Wireless LAN Controller (WLC) Software could allow an unauthenticated, remote attacker…
Wireless Lan Controller Software
8.3.150.0 / 8.5.150.0+