Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 6.5
CVE-2018-19376
An issue was discovered in GreenCMS v2.3.0603. There is a CSRF vulnerability that allows attackers to delete a log file via the index.php?m=admin&c=d…
Greencms
No fix yet
HIGH 8.8
CVE-2018-18772
CentOS-WebPanel.com (aka CWP) CentOS Web Panel through 0.9.8.740 allows CSRF via admin/index.php?module=send_ssh, as demonstrated by executing an arb…
Webpanel
after 0.9.8.740
HIGH 8.8
CVE-2018-18773
CentOS-WebPanel.com (aka CWP) CentOS Web Panel through 0.9.8.740 allows CSRF via admin/index.php?module=rootpwd, as demonstrated by changing the root…
Webpanel
after 0.9.8.740
MEDIUM 5.3
CVE-2018-19335
Google Monorail before 2018-06-07 has a Cross-Site Search (XS-Search) vulnerability because CSV downloads are affected by CSRF, and calculations of d…
Monorail
2018-06-07+
MEDIUM 5.3
CVE-2018-19334
Google Monorail before 2018-05-04 has a Cross-Site Search (XS-Search) vulnerability because CSV downloads are affected by CSRF, and calculations of d…
Monorail
2018-05-04+
MEDIUM 5.3
CVE-2018-10099
Google Monorail before 2018-04-04 has a Cross-Site Search (XS-Search) vulnerability because CSV downloads are affected by CSRF, and calculations of d…
Monorail
2018-04-04+
HIGH 8.8
CVE-2018-19327
An issue was discovered in JTBC(PHP) 3.0.1.7. aboutus/manage.php?type=action&action=add allows CSRF.
Jtbc Php
No fix yet
HIGH 8.8
CVE-2018-19332
An issue was discovered in S-CMS v1.5. There is a CSRF vulnerability that can add a new user via the admin/ajax.php?type=member&action=add URI.
S Cms
No fix yet
HIGH 8.8
CVE-2018-19318
SRCMS 3.0.0 allows CSRF via admin.php?m=Admin&c=manager&a=update to change the username and password of the super administrator account.
Srcms
No fix yet
MEDIUM 6.5
CVE-2018-19319
SRCMS 3.0.0 allows CSRF via admin.php?m=Admin&c=gifts&a=update to change goods prices with the super administrator's privileges.
Srcms
No fix yet
MEDIUM 6.5
CVE-2018-18760
RhinOS 3.0 build 1190 allows CSRF.
Rhinos
No fix yet
HIGH 8.8
CVE-2018-18794
School Event Management System 1.0 allows CSRF via user/controller.php?action=edit.
School Event Management System
No fix yet
HIGH 8.8
CVE-2018-18797
School Attendance Monitoring System 1.0 has CSRF via /user/user/edit.php.
School Attendance Monitoring System
No fix yet
HIGH 8.8
CVE-2018-18799
School Attendance Monitoring System 1.0 has CSRF via event/controller.php?action=photos.
School Attendance Monitoring System
No fix yet
MEDIUM 6.5
CVE-2018-19291
An issue was discovered in DiliCMS 2.4.0. There is a CSRF vulnerability that can delete a user or group via an admin/index.php/user/del/1 or admin/in…
Dilicms
No fix yet
HIGH 8.8
CVE-2018-12416
The GridServer Broker and GridServer Director components of TIBCO Software Inc.'s TIBCO DataSynapse GridServer Manager contain vulnerabilities which …
Datasynapse Gridserver Manager
after 5.2.0
HIGH 8.8
CVE-2018-19225
An issue was discovered in LAOBANCMS 2.0. admin/mima.php has CSRF.
Laobancms
No fix yet
HIGH 8.8
CVE-2018-19192
An issue was discovered in XiaoCms 20141229. admin/index.php?c=content&a=add&catid=3 has CSRF, as demonstrated by entering news via the data[content]…
Xiaocms
No fix yet
HIGH 8.8
CVE-2018-19135
ClipperCMS 1.3.3 does not have CSRF protection on its kcfinder file upload (enabled by default). This can be used by an attacker to perform actions f…
Clippercms
No fix yet
HIGH 8.8
CVE-2017-17550
ZyXEL ZyWALL USG 2.12 AQQ.2 and 3.30 AQQ.7 devices are affected by a CSRF vulnerability via a cgi-bin/zysh-cgi cmd action to add a user account. This…
Zywall Usg 100 Firmware
No fix yet
HIGH 8.8
CVE-2018-19138
WSTMart 2.0.7 has CSRF via the index.php/admin/staffs/add.html URI.
Wstmart
No fix yet
HIGH 8.0
CVE-2018-15445
A vulnerability in the web-based management interface of Cisco Energy Management Suite Software could allow an authenticated, remote attacker to cond…
Energy Management Suite Software
No fix yet
HIGH 8.8
CVE-2018-19104
In BageCMS 3.1.3, upload/index.php has a CSRF vulnerability that can be used to upload arbitrary files and get server privileges.
Bagecms
No fix yet
HIGH 8.8
CVE-2018-12411
The administrative daemon (tibdgadmind) of TIBCO Software Inc.'s TIBCO ActiveSpaces - Community Edition, TIBCO ActiveSpaces - Developer Edition, and …
Activespaces
Mitigation only
HIGH 8.8
CVE-2018-12412
The realm server (tibrealmserver) component of TIBCO Software Inc. TIBCO FTL - Community Edition, TIBCO FTL - Developer Edition, and TIBCO FTL - Ente…
Ftl
5.4.0+
HIGH 8.8
CVE-2018-12413
The Schema repository server (tibschemad) component of TIBCO Software Inc.'s TIBCO Messaging - Apache Kafka Distribution - Schema Repository - Commun…
Messaging Apache Kafka Distribution Schema Repository
Mitigation only
HIGH 8.8
CVE-2018-12414
The Rendezvous Routing Daemon (rvrd), Rendezvous Secure Routing Daemon (rvrsd), Rendezvous Secure Daemon (rvsd), Rendezvous Cache (rvcache), and Rend…
Rendezvous
after 8.4.5
HIGH 8.8
CVE-2018-12415
The Central Administration server (emsca) component of TIBCO Software Inc.'s TIBCO Enterprise Message Service, TIBCO Enterprise Message Service - Com…
Enterprise Message Service
after 8.4.0
CRITICAL 9.8
CVE-2018-18934
An issue was discovered in PopojiCMS v2.0.1. admin_component.php is exploitable via the po-admin/route.php?mod=component&act=addnew URI by using the …
Popojicms
No fix yet
HIGH 8.8
CVE-2018-18935
An issue was discovered in PopojiCMS v2.0.1. It has CSRF via the po-admin/route.php?mod=component&act=addnew URI, as demonstrated by adding a level=1…
Popojicms
No fix yet