Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 5.3
CVE-2019-1003017
A data modification vulnerability exists in Jenkins Job Import Plugin 3.0 and earlier in JobImportAction.java that allows attackers to copy jobs from…
Job Import
after 3.0
MEDIUM 6.1
CVE-2019-7402
An issue was discovered in PHPMyWind 5.5. The GetQQ function in include/func.class.php allows XSS via the cfg_qqcode parameter. This can be explo…
Phpmywind
No fix yet
HIGH 8.8
CVE-2019-1000022
Taoensso Sente version Prior to version 1.14.0 contains a Cross Site Request Forgery (CSRF) vulnerability in WebSocket handshake endpoint that can re…
Sente
1.14.0+
HIGH 8.8
CVE-2019-1000003
MapSVG MapSVG Lite version 3.2.3 contains a Cross Site Request Forgery (CSRF) vulnerability in REST endpoint /wp-admin/admin-ajax.php?action=mapsvg_s…
Mapsvg Lite
No fix yet
HIGH 8.8
CVE-2019-7346
A CSRF check issue exists in ZoneMinder through 1.32.3 as whenever a CSRF check fails, a callback function is called displaying a "Try again" button,…
Zoneminder
after 1.32.3
HIGH 8.8
CVE-2019-3604
Cross-Site Request Forgery (CSRF) vulnerability in McAfee ePO (legacy) Cloud allows unauthenticated users to perform unintended ePO actions using an …
Epolicy Orchestrator
Mitigation only
HIGH 8.1
CVE-2019-6779
Cscms 4.1.8 allows admin.php/links/save CSRF to add, modify, or delete friend links.
Cscms
No fix yet
HIGH 7.4
CVE-2019-1658
A vulnerability in the web-based management interface of Cisco Unified Intelligence Center could allow an unauthenticated, remote attacker to conduct…
Unified Intelligence Center
Mitigation only
HIGH 8.8
CVE-2017-17835
In Apache Airflow 1.8.2 and earlier, a CSRF vulnerability allowed for a remote command injection on a default install of Airflow.
Airflow
after 1.8.2
HIGH 8.8
CVE-2019-6507
An issue was discovered in creditease-sec insight through 2018-09-11. login_user_delete in srcpm/app/admin/views.py allows CSRF.
Insight
after 2018-09-11
HIGH 8.8
CVE-2019-6508
An issue was discovered in creditease-sec insight through 2018-09-11. role_perm_delete in srcpm/app/admin/views.py allows CSRF.
Insight
after 2018-09-11
HIGH 8.8
CVE-2019-6509
An issue was discovered in creditease-sec insight through 2018-09-11. depart_delete in srcpm/app/admin/views.py allows CSRF.
Insight
after 2018-09-11
HIGH 8.8
CVE-2019-6510
An issue was discovered in creditease-sec insight through 2018-09-11. user_delete in srcpm/app/admin/views.py allows CSRF.
Insight
after 2018-09-11
HIGH 8.8
CVE-2018-20728
A cross site request forgery (CSRF) vulnerability in NeDi before 1.7Cp3 allows remote attackers to escalate privileges via User-Management.php.
Nedi
after 1.7c
HIGH 8.8
CVE-2016-10738
Zenbership v107 has CSRF via admin/cp-functions/event-add.php.
Zenbership
No fix yet
HIGH 8.8
CVE-2019-6294
An issue was discovered in EasyCMS 1.5. There is CSRF via the index.php?s=/admin/articlem/insert/navTabId/listarticle/callbackType/closeCurrent URI.
Easycms
No fix yet
HIGH 8.8
CVE-2019-6249
An issue was discovered in HuCart v5.7.4. There is a CSRF vulnerability that can add an admin account via /adminsys/index.php?load=admins&act=edit_in…
Hucart
No fix yet
HIGH 8.8
CVE-2019-6244
An issue was discovered in UsualToolCMS 8.0. cmsadmin/a_sqlbackx.php?t=sql allows CSRF attacks that can execute SQL statements, and consequently exec…
Usualtoolcms
No fix yet
MEDIUM 6.5
CVE-2018-1000411
A cross-site request forgery vulnerability exists in Jenkins JUnit Plugin 1.25 and earlier in TestObject.java that allows setting the description of …
Junit
after 1.25
HIGH 8.1
CVE-2018-1000414
A cross-site request forgery vulnerability exists in Jenkins Config File Provider Plugin 3.1 and earlier in ConfigFilesManagement.java, FolderConfigF…
Config File Provider
after 3.1
HIGH 8.1
CVE-2018-1000417
A cross-site request forgery vulnerability exists in Jenkins Email Extension Template Plugin 1.0 and earlier in ExtEmailTemplateManagement.java that …
Email Extension Template
after 1.0
HIGH 8.8
CVE-2018-20613
TEMMOKU T1.09 Beta allows admin/user/add CSRF.
Temmoku
No fix yet
HIGH 8.8
CVE-2018-20598
UCMS 1.4.7 has ?do=user_addpost CSRF.
Ucms
No fix yet
HIGH 8.8
CVE-2018-20603
Lei Feng TV CMS (aka LFCMS) 3.8.6 allows admin.php?s=/Member/add.html CSRF.
Lei Feng Tv Cms
No fix yet
HIGH 8.8
CVE-2018-20612
UWA 2.3.11 allows index.php?g=admin&c=admin&a=add_admin_do CSRF.
Universal Website Asthis
No fix yet
HIGH 8.8
CVE-2018-20595
A CSRF issue was discovered in web/authorization/oauth2/controller/OAuth2ClientController.java in hsweb 3.0.4 because the state parameter in the requ…
Hsweb
Patch available
HIGH 8.8
CVE-2018-18696
main.aspx in Microstrategy Analytics 10.4.0026.0049 and earlier has CSRF. NOTE: The vendor claims that documentation for preventing a CSRF attack has…
Microstrategy
after 10.4.0026.0049
MEDIUM 5.4
CVE-2018-20576
Orange Livebox 00.96.320S devices allow cgi-bin/autodialing.exe and cgi-bin/phone_test.exe CSRF, leading to arbitrary outbound telephone calls to an …
Arv7519rw22 Livebox 2.1 Firmware
No fix yet
CRITICAL 9.1
CVE-2018-20577
Orange Livebox 00.96.320S devices allow cgi-bin/restore.exe, cgi-bin/firewall_SPI.exe, cgi-bin/setup_remote_mgmt.exe, cgi-bin/setup_pass.exe, and cgi…
Arv7519rw22 Livebox 2.1 Firmware
No fix yet
HIGH 8.8
CVE-2018-19182
Engelsystem before commit hash 2e28336 allows CSRF.
Engelsystem
3.0.0+