Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 6.1
CVE-2018-15677
The newsfeed (aka /index.php?page=viewnews) in BTITeam XBTIT 2.5.4 has stored XSS via the title of a news item. This is also exploitable via CSRF.
Xbtit
Patch available
HIGH 8.8
CVE-2018-15682
An issue was discovered in BTITeam XBTIT. Due to a lack of cross-site request forgery protection, it is possible to automate the action of sending pr…
Xbtit
after 2.5.4
HIGH 8.8
CVE-2018-14769
VIVOTEK FD8177 devices before XXXXXX-VVTK-xx06a allow CSRF.
Camera
No fix yet
MEDIUM 6.5
CVE-2018-16458
An issue was discovered in baigo CMS v2.1.1. There is an index.php?m=article&c=request CSRF that can cause publication of any article.
Baigo Cms
No fix yet
HIGH 8.8
CVE-2018-16447
Frog CMS 0.9.5 has admin/?/user/edit/1 CSRF.
Frogcms
No fix yet
HIGH 8.8
CVE-2018-16448
Cscms 4 allows CSRF for creating a member via upload/admin.php/user/save, authenticating vip members via upload/admin.php/user/init/tid and upload/ad…
Cscms
No fix yet
MEDIUM 6.5
CVE-2018-16449
OneThink 1.1.141212 allows CSRF for adding a page via admin.php?s=/Channel/add.html, adding a blog via admin.php?s=/Article/update.html, and setting …
Onethink
No fix yet
HIGH 8.8
CVE-2018-16431
admin/admin/adminsave.html in YFCMF v3.0 allows CSRF to add an administrator account.
Yfcmf
No fix yet
HIGH 8.8
CVE-2018-16416
Cross-site request forgery (CSRF) vulnerability in my_profile/edit?inline= in FUEL CMS 1.4 allows remote attackers to change the administrator's pass…
Fuel Cms
No fix yet
HIGH 8.8
CVE-2018-16387
An issue was discovered in Elefant CMS before 2.0.5. There is a CSRF vulnerability that can add an account via user/add.
Elefantcms
2.0.5+
HIGH 8.8
CVE-2018-16380
An issue was discovered in Ogma CMS 0.4 Beta. There is a CSRF vulnerability in users.php?action=createnew that can add an admin account.
Ogma Cms
No fix yet
HIGH 8.8
CVE-2018-16366
An issue was discovered in idreamsoft iCMS V7.0.10. admincp.php?app=user&do=save allows CSRF.
Icms
No fix yet
HIGH 8.8
CVE-2018-16365
An issue was discovered in idreamsoft iCMS V7.0.10. admincp.php?app=group&do=save allows CSRF.
Icms
No fix yet
HIGH 8.8
CVE-2018-16345
An issue was discovered in EasyCMS 1.5. There is a CSRF vulnerability that can update the admin password via index.php?s=/admin/rbacuser/update/navTa…
Easycms
No fix yet
MEDIUM 6.5
CVE-2018-16337
An issue was discovered in Cscms V4.1.8. There is a CSRF vulnerability that can modify a website's basic configuration via upload/admin.php/setting/s…
Cscms
No fix yet
HIGH 8.8
CVE-2018-16338
An issue was discovered in AuraCMS 2.3. There is a CSRF vulnerability that can change the administrator's password via admin.php?mod=users and subseq…
Auracms
No fix yet
HIGH 8.8
CVE-2018-16339
An issue was discovered in EmpireCMS 7.0. There is a CSRF vulnerability that can add administrators via upload/e/admin/user/AddUser.php?enews=AddUser.
Empirecms
No fix yet
HIGH 8.8
CVE-2018-16331
admin.php?s=/Admin/doedit in DamiCMS v6.0.0 allows CSRF to change the administrator account's password.
Damicms
No fix yet
HIGH 8.8
CVE-2018-16332
An issue was discovered in iCMS 7.0.9. There is an admincp.php?app=article&do=update CSRF vulnerability.
Icms
No fix yet
HIGH 8.8
CVE-2018-16314
An issue was discovered in admincp.php in idreamsoft iCMS 7.0.11. When verifying CSRF_TOKEN, if CSRF_TOKEN does not exist, only the Referer header is…
Icms
No fix yet
MEDIUM 6.5
CVE-2018-16315
In waimai Super Cms 20150505, there is a CSRF vulnerability that can change the configuration via admin.php?m=Config&a=add.
Waimai Super Cms
No fix yet
HIGH 8.8
CVE-2018-11718
Xovis PC2, PC2R, and PC3 devices through 3.6.0 allow CSRF.
Pc2r Firmware
after 3.6.0
HIGH 8.8
CVE-2018-15121
An issue was discovered in Auth0 auth0-aspnet and auth0-aspnet-owin. Affected packages do not use or validate the state parameter of the OAuth 2.0 an…
Aspnet
Mitigation only
HIGH 8.8
CVE-2018-15884
RICOH MP C4504ex devices allow HTML Injection via the /web/entry/en/address/adrsSetUserWizard.cgi entryNameIn parameter.
Mp C4504ex Firmware
No fix yet
HIGH 8.8
CVE-2018-15901
e107 2.1.8 has CSRF in 'usersettings.php' with an impact of changing details such as passwords of users including administrators.
E107
No fix yet
HIGH 8.8
CVE-2014-6046
Multiple cross-site request forgery (CSRF) vulnerabilities in phpMyFAQ before 2.8.13 allow remote attackers to hijack the authentication of unspecifi…
Phpmyfaq
2.8.13+
HIGH 8.8
CVE-2018-15850
An issue was discovered in REDAXO CMS 4.7.2. There is a CSRF vulnerability that can add an administrator account via index.php?page=user.
Redaxo Cms
Mitigation only
HIGH 8.8
CVE-2018-15851
An issue was discovered in Flexo CMS v0.1.6. There is a CSRF vulnerability that can add an administrator via /admin/user/add.
Flexo Cms
Mitigation only
HIGH 8.8
CVE-2018-15844
An issue was discovered in DamiCMS 6.0.0. There is an CSRF vulnerability that can revise the administrator account's password via /admin.php?s=/Admin…
Damicms
No fix yet
HIGH 8.8
CVE-2018-15845
There is a CSRF vulnerability that can add an administrator account in Gleez CMS 1.2.0 via admin/users/add.
Gleez Cms
No fix yet