Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
CRITICAL 9.8
CVE-2019-10655EPSS 15%
Grandstream GAC2500 1.0.3.35, GXP2200 1.0.3.27, GVC3202 1.0.3.51, GXV3275 before 1.0.3.219 Beta, and GXV3240 before 1.0.3.219 Beta devices allow unau…
Gac2500 Firmware
1.0.3.51 / 1.0.3.219+
HIGH 8.8
CVE-2019-10644
An issue was discovered in HYBBS 2.2. /?admin/user.html has a CSRF vulnerability that can add an administrator account.
Hybbs
No fix yet
HIGH 8.8
CVE-2019-9604
PHP Scripts Mall Online Lottery PHP Readymade Script 1.7.0 has Cross-Site Request Forgery (CSRF) for Edit Profile actions.
Online Lottery Php Readymade Script
No fix yet
MEDIUM 6.8
CVE-2019-6607
On BIG-IP ASM 11.5.1-11.5.8, 11.6.1-11.6.3, 12.1.0-12.1.3, 13.0.0-13.1.1.3, and 14.0.0-14.0.0.2, there is a stored cross-site scripting vulnerability…
Big Ip Application Security Manager
after 14.0.0.2
HIGH 7.1
CVE-2019-1003044
A cross-site request forgery vulnerability in Jenkins Slack Notification Plugin 2.19 and earlier allows attackers to connect to an attacker-specified…
Slack Notification
after 2.19
MEDIUM 6.5
CVE-2019-1003046
A cross-site request forgery vulnerability in Jenkins Fortify on Demand Uploader Plugin 3.0.10 and earlier allows attackers to initiate a connection …
Fortify On Demand Uploader
after 3.0.10
HIGH 8.8
CVE-2019-10237
S-CMS PHP v1.0 has a CSRF vulnerability to add a new admin user via the 4.edu.php/admin/ajax.php?type=admin&action=add&lang=0 URI, a related issue to…
S Cms
No fix yet
CRITICAL 10.0
CVE-2019-3809
A flaw was found in Moodle versions 3.1 to 3.1.15 and earlier unsupported versions. The mybackpack functionality allowed setting the URL of badges, w…
Moodle
after 3.1.15
HIGH 8.8
CVE-2019-1764
A vulnerability in the web-based management interface of Session Initiation Protocol (SIP) Software for Cisco IP Phone 8800 Series could allow an una…
Ip Phone 8821 Firmware
11.0 / 12.5+
HIGH 8.8
CVE-2019-7433
PHP Scripts Mall Rental Bike Script 2.0.3 has Cross-Site Request Forgery (CSRF) via the Edit Profile feature.
Rental Bike Script
No fix yet
MEDIUM 6.5
CVE-2019-7440
JioFi 4G M2S 1.0.2 devices have CSRF via the SSID name and Security Key field under Edit Wi-Fi Settings (aka a SetWiFi_Setting request to cgi-bin/qcm…
Jiofi 4g M2s Firmware
No fix yet
HIGH 8.8
CVE-2019-7391EPSS 14%
ZyXEL VMG3312-B10B DSL-491HNU-B1B v2 devices allow login/login-page.cgi CSRF.
Dsl 491hnu B10b Firmware
No fix yet
HIGH 8.8
CVE-2019-6967EPSS 13%
AirTies Air5341 1.0.0.12 devices allow cgi-bin/login CSRF.
Air 5341 Firmware
No fix yet
HIGH 8.8
CVE-2019-6282
ChinaMobile PLC Wireless Router GPN2.4P21-C-CN devices with firmware W2001EN-00 have CSRF via the cgi-bin/webproc?getpage=html/index.html subpage=wls…
Gpn2.4p21 C Cn Firmware
No fix yet
HIGH 8.8
CVE-2018-20641
PHP Scripts Mall Entrepreneur Job Portal Script 3.0.1 has Cross-Site Request Forgery (CSRF) via the Edit Profile feature.
Entrepreneur Job Portal Script
No fix yet
HIGH 8.8
CVE-2018-20644
PHP Scripts Mall Basic B2B Script 2.0.9 has Cross-Site Request Forgery (CSRF) via the Edit profile feature.
Basic B2b Script
No fix yet
HIGH 8.8
CVE-2018-20648
PHP Scripts Mall Car Rental Script 2.0.8 has Cross-Site Request Forgery (CSRF) via accountedit.php.
Car Rental Script
No fix yet
HIGH 8.8
CVE-2018-20633
PHP Scripts Mall Advance B2B Script 2.1.4 has Cross-Site Request Forgery (CSRF) via the Edit Profile feature.
Advance B2b Script
No fix yet
MEDIUM 6.5
CVE-2018-19511
wg7.php in Webgalamb 7.0 lacks security measures to prevent CSRF attacks, as demonstrated by wg7.php?options=1 to change the administrator password.
Webgalamb
No fix yet
MEDIUM 6.1
CVE-2018-19525
An issue was discovered on Systrome ISG-600C, ISG-600H, and ISG-800W 1.1-R2.1_TRUNK-20180914.bin devices. There is CSRF via /ui/?g=obj_keywords_add a…
Cumilon Isg 600c Firmware
No fix yet
MEDIUM 6.5
CVE-2018-17996
LayerBB before 1.1.3 allows CSRF for adding a user via admin/new_user.php, deleting a user via admin/members.php/delete_user/, and deleting content v…
Layerbb
Patch available
HIGH 8.8
CVE-2018-14575
Trash Bin plugin 1.1.3 for MyBB has cross-site scripting (XSS) via a thread subject and a cross-site request forgery (CSRF) via a post subject.
Trash Bin
No fix yet
HIGH 8.8
CVE-2019-9787EPSS 41%
WordPress before 5.1.1 does not properly filter comment content, leading to Remote Code Execution by unauthenticated users in a default configuration…
WordPress
5.1.1+
HIGH 8.8
CVE-2019-9769
PilusCart 1.4.1 is vulnerable to index.php?module=users&action=newUser CSRF, leading to the addition of a new user as administrator.
Piluscart
No fix yet
HIGH 8.8
CVE-2019-5924
Cross-site request forgery (CSRF) vulnerability in Smart Forms 2.6.15 and earlier allows remote attackers to hijack the authentication of administrat…
Smart Forms
after 2.6.15
HIGH 8.8
CVE-2019-5920
Cross-site request forgery (CSRF) vulnerability in FormCraft 1.2.1 and earlier allows remote attackers to hijack the authentication of administrators…
Formcraft
after 1.2.1
HIGH 8.8
CVE-2019-9688
sftnow through 2018-12-29 allows index.php?g=Admin&m=User&a=add_post CSRF to add an admin account.
Sftnow
after 2018-12-29
HIGH 8.8
CVE-2019-9652
There is a CSRF in SDCMS V1.7 via an m=admin&c=theme&a=edit request. It allows PHP code injection by providing a filename in the file parameter, and …
Sdcms
No fix yet
MEDIUM 6.5
CVE-2019-9598
An issue was discovered in Cscms 4.1.0. There is an admin.php/pay CSRF vulnerability that can change the payment account to redirect funds.
Cscms
No fix yet
HIGH 8.8
CVE-2018-17429
/console/account/manage.php?type=action&action=add in JTBC v3.0(C) has CSRF for adding an administrator account.
Jtbc
No fix yet