Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 8.8
CVE-2018-6907
A Cross Site Request Forgery (CSRF) vulnerability in the Green Electronics RainMachine Mini-8 (2nd Generation) and Touch HD 12 web application allows…
Rainmachine Web Application
No fix yet
HIGH 8.8
CVE-2018-18842
CSRF exists in zb_users/plugin/AppCentre/theme.js.php in Z-BlogPHP 1.5.2.1935 (Zero), which allows remote attackers to execute arbitrary PHP code.
Z Blogphp
No fix yet
HIGH 8.8
CVE-2018-18734
A CSRF issue was discovered in admin/Index/addmanageuser.html in Catfish CMS 4.8.30.
Catfish Cms
No fix yet
HIGH 8.8
CVE-2018-18735
A CSRF issue was discovered in admin/Index/tiquan in catfish blog 2.0.33.
Catfish Blog
No fix yet
HIGH 8.8
CVE-2018-18742
A CSRF issue was discovered in SEMCMS 3.4 via the admin/SEMCMS_User.php?Class=add&CF=user URI.
Semcms
No fix yet
HIGH 8.8
CVE-2018-18712
An issue was discovered in WUZHI CMS 4.1.0. There is a CSRF vulnerability that can change the super administrator's username via index.php?m=member&f…
Wuzhicms
No fix yet
HIGH 8.8
CVE-2018-18711
An issue was discovered in WUZHI CMS 4.1.0. There is a CSRF vulnerability that can change the super administrator's password via index.php?m=core&f=p…
Wuzhicms
No fix yet
HIGH 8.8
CVE-2018-9281
An issue was discovered on Eaton UPS 9PX 8000 SP devices. The administration panel is vulnerable to a CSRF attack on the change-password functionalit…
9px Ups Firmware
Mitigation only
HIGH 8.8
CVE-2018-18420
Cross-Site Request Forgery (CSRF) vulnerability was discovered in the 8.3 version of Zenario Content Management System via the admin/organizer.ajax.p…
Zenario
No fix yet
HIGH 8.0
CVE-2015-4630
Multiple cross-site request forgery (CSRF) vulnerabilities in Koha 3.14.x before 3.14.16, 3.16.x before 3.16.12, 3.18.x before 3.18.08, and 3.20.x be…
Koha
3.14.16 / 3.16.12+
HIGH 8.8
CVE-2018-12370
In Reader View SameSite cookie protections are not checked on exiting. This allows for a payload to be triggered when Reader View is exited if loaded…
Ubuntu Linux
61.0+
HIGH 8.8
CVE-2018-12364
NPAPI plugins, such as Adobe Flash, can send non-simple cross-origin requests, bypassing CORS by making a same-origin POST that does a 307 redirect t…
Enterprise Linux Desktop
Mitigation only
MEDIUM 6.5
CVE-2018-15438
A vulnerability in the web-based management interface of Cisco Prime Collaboration Assurance could allow an unauthenticated, remote attacker to condu…
Prime Collaboration Assurance
Mitigation only
HIGH 8.8
CVE-2018-15402
A vulnerability in Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an unauthenticated, remote attacker to conduct cross-site request…
Enterprise Network Virtualization Software
Mitigation only
HIGH 8.8
CVE-2018-18436
JTBC(PHP) 3.0 allows CSRF for creating an account via the console/account/manage.php?type=action&action=add URI.
Jtbc Php
No fix yet
HIGH 8.8
CVE-2018-18422
UsualToolCMS 8.0 allows CSRF for adding a user account via the cmsadmin/a_adminx.php?x=a URI.
Usualtoolcms
No fix yet
HIGH 8.8
CVE-2018-18432
An issue was discovered in DESTOON B2B 7.0. CSRF exists via the admin.php URI in an action=add request.
Destoon B2b
No fix yet
HIGH 8.8
CVE-2018-15539
Agentejo Cockpit lacks an anti-CSRF protection mechanism. Thus, an attacker is able to change API tokens, passwords, etc.
Cockpit
Mitigation only
HIGH 8.8
CVE-2018-18316
emlog v6.0.0 has CSRF via the admin/user.php?action=new URI.
Emlog
No fix yet
HIGH 8.8
CVE-2018-18317
DESHANG DSCMS 1.1 has CSRF via the public/index.php/admin/admin/add.html URI.
Dscms
No fix yet
HIGH 8.8
CVE-2018-18215
In youke365 v1.1.5, admin/user.html has a CSRF vulnerability that can add an user account.
Youke 365
No fix yet
HIGH 8.8
CVE-2018-12456
Intelbras NPLUG 1.0.0.14 wireless repeater devices have no CSRF token protection in the web interface, allowing attackers to perform actions such as …
Nplug Firmware
No fix yet
HIGH 7.3
CVE-2018-13800
A vulnerability has been identified in SIMATIC S7-1200 CPU family version 4 (All versions < V4.2.3). The web interface could allow a Cross-Site Reque…
Simatic S7 1200 V4 Firmware
4.2.3+
HIGH 8.8
CVE-2018-18201
qibosoft V7.0 allows CSRF via admin/index.php?lfj=member&action=addmember to add a user account.
Qibosoft
No fix yet
HIGH 8.8
CVE-2018-17858
An issue was discovered in Joomla! before 3.8.13. com_installer actions do not have sufficient CSRF hardening in the backend.
Joomla\!
3.8.13+
HIGH 8.8
CVE-2018-18191
Cross-site request forgery (CSRF) vulnerability in /admin.php?c=member&m=edit&uid=1 in dayrui FineCms 5.4 allows remote attackers to change the admin…
Finecms
No fix yet
MEDIUM 6.5
CVE-2018-2474
SAP Fiori 1.0 for SAP ERP HCM (Approve Leave Request, version 2) application allows an attacker to trick an authenticated user to send unintended req…
Fiori
Mitigation only
MEDIUM 6.5
CVE-2018-15401
A vulnerability in the web-based management interface of Cisco Hosted Collaboration Mediation Fulfillment could allow an unauthenticated, remote atta…
Hosted Collaboration Mediation Fulfillment
Mitigation only
HIGH 8.8
CVE-2018-0451
A vulnerability in the web-based management interface of Cisco Tetration Analytics could allow an authenticated, remote attacker to conduct a cross-s…
Tetration Analytics
Mitigation only
HIGH 8.8
CVE-2018-0439
A vulnerability in the web-based management interface of Cisco Meeting Server could allow an unauthenticated, remote attacker to conduct a cross-site…
Meeting Server
Mitigation only