Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 8.8
CVE-2018-20419
DouCo DouPHP 1.5 has upload/admin/manager.php?rec=insert CSRF to add an administrator account.
Douphp
No fix yet
MEDIUM 6.5
CVE-2018-8892
A cross-site request forgery (CSRF) vulnerability in the Management Console of BlackBerry UEM versions earlier than 12.9.1 could allow an attacker to…
Unified Endpoint Manager
12.9.1+
HIGH 8.8
CVE-2018-1000858
GnuPG version 2.1.12 - 2.2.11 contains a Cross ite Request Forgery (CSRF) vulnerability in dirmngr that can result in Attacker controlled CSRF, Infor…
Ubuntu Linux
after 2.2.11
HIGH 8.8
CVE-2018-1000843
Luigi version prior to version 2.8.0; after commit 53b52e12745075a8acc016d33945d9d6a7a6aaeb; after GitHub PR spotify/luigi/pull/1870 contains a Cross…
Luigi
2.8.0+
HIGH 8.8
CVE-2018-1000846
FreshDNS version 1.0.3 and earlier contains a Cross ite Request Forgery (CSRF) vulnerability in All (authenticated) API calls in index.php / class.ma…
Freshdns
after 1.0.3
HIGH 8.8
CVE-2018-1661
IBM DataPower Gateways 7.5, 7.5.1, 7.5.2, and 7.6 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and …
Datapower Gateway
after 7.6.0.9
HIGH 8.0
CVE-2018-20228
Subsonic V6.1.5 allows internetRadioSettings.view streamUrl CSRF, with resultant SSRF.
Subsonic
No fix yet
HIGH 8.8
CVE-2018-20231
Cross Site Request Forgery (CSRF) in the two-factor-authentication plugin before 1.3.13 for WordPress allows remote attackers to disable 2FA via the …
Two Factor Authentication
1.3.13+
MEDIUM 6.5
CVE-2018-19829
Artica Integria IMS 5.0.83 has CSRF in godmode/usuarios/lista_usuarios, resulting in the ability to delete an arbitrary user when the ID number is kn…
Integria Ims
No fix yet
MEDIUM 6.5
CVE-2018-18921
PHP Server Monitor before 3.3.2 has CSRF, as demonstrated by a Delete action.
Php Server Monitor
3.3.2+
HIGH 8.8
CVE-2018-20188
FUEL CMS 1.4.3 has CSRF via users/create/ to add an administrator account.
Fuel Cms
No fix yet
MEDIUM 6.5
CVE-2018-18246
Icinga Web 2 before 2.6.2 has CSRF via /icingaweb2/config/moduledisable?name=monitoring to disable the monitoring module, or via /icingaweb2/config/m…
Icinga Web 2
2.6.2+
HIGH 8.8
CVE-2018-1926
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 Admin Console is vulnerable to cross-site request forgery, caused by improper validation of u…
Websphere Application Server
after 9.0.0.9
HIGH 8.8
CVE-2018-19969
phpMyAdmin 4.7.x and 4.8.x versions prior to 4.8.4 are affected by a series of CSRF flaws. By deceiving a user into clicking on a crafted URL, it is …
phpMyAdmin
4.8.4+
HIGH 8.8
CVE-2018-20015
YzmCMS v5.2 has admin/role/add.html CSRF.
Yzmcms
No fix yet
HIGH 8.8
CVE-2018-19923
An issue was discovered in Sales & Company Management System (SCMS) through 2018-06-06. There is member/member_email.php?action=edit CSRF.
Sales \& Company Management System
after 2018-06-06
HIGH 7.5
CVE-2018-19911
FreeSWITCH through 1.8.2, when mod_xml_rpc is enabled, allows remote attackers to execute arbitrary commands via the api/system or txtapi/system (or …
Freeswitch
after 1.8.2
HIGH 8.8
CVE-2018-1002103
In Minikube versions 0.3.0-0.29.0, minikube exposes the Kubernetes Dashboard listening on the VM IP at port 30000. In VM environments where the IP is…
Minikube
after 0.29.0
HIGH 8.8
CVE-2018-16634
Pluck v4.7.7 allows CSRF via admin.php?action=settings.
Pluck
No fix yet
HIGH 8.8
CVE-2018-7831
An Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability exists in the embedded web servers in all Modicon M340…
Modicom M340 Firmware
No fix yet
HIGH 8.8
CVE-2018-1927
IBM StoredIQ 7.6 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted …
Storediq
7.6.0.17+
MEDIUM 6.5
CVE-2018-19621
server/index.php?s=/api/teamMember/save in ShowDoc 2.4.2 has a CSRF that can add members to a team.
Showdoc
No fix yet
HIGH 8.8
CVE-2018-14892
Missing protections against Cross-Site Request Forgery in the web application in ZyXEL NSA325 V2 version 4.81 allow attackers to perform state-changi…
Nsa325 V2 Firmware
No fix yet
HIGH 8.8
CVE-2018-16854
A flaw was found in moodle versions 3.5 to 3.5.2, 3.4 to 3.4.5, 3.3 to 3.3.8, 3.1 to 3.1.14 and earlier. The login form is not protected by a token t…
Moodle
3.1.15 / 3.3.9+
HIGH 8.8
CVE-2018-19555
tp4a TELEPORT 3.1.0 has CSRF via user/do-reset-password to change any password, such as the administrator password.
Teleport
No fix yet
HIGH 8.8
CVE-2018-19560
BageCMS 3.1.3 has CSRF via upload/index.php?r=admini/admin/ownerUpdate to modify a user account.
Bagecms
No fix yet
HIGH 8.8
CVE-2018-19561
sikcms 1.1 has CSRF via admin.php?m=Admin&c=Users&a=userAdd to add an administrator account.
Sikcms
No fix yet
MEDIUM 6.5
CVE-2018-19544
JEECMS 9.3 has CSRF via the api/admin/content/save URI to add news.
Jeecms
No fix yet
HIGH 8.8
CVE-2018-19545
JEECMS 9.3 has CSRF via the api/admin/role/save URI to add a user.
Jeecms
No fix yet
HIGH 8.8
CVE-2018-19546
JTBC(PHP) 3.0.1.7 has CSRF via the console/xml/manage.php?type=action&action=edit URI, as demonstrated by an XSS payload in the content parameter.
Jtbc Php
No fix yet