Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 8.8
CVE-2018-15846
An issue was discovered in fledrCMS through 2014-02-03. There is a CSRF vulnerability that can change the administrator's password via index.php?p=do…
Fledrcms
after 2014-02-03
HIGH 8.8
CVE-2018-15848
An issue was discovered in portfolioCMS 1.0.5. There is CSRF to create new pages via admin/portfolio.php?newpage=true.
Portfoliocms
Mitigation only
MEDIUM 6.5
CVE-2018-11502
An issue was discovered in the Moderator Log Notes plugin 1.1 for MyBB. It allows moderators to save notes and display them in a list in the modCP. A…
Moderator Log Notes
No fix yet
HIGH 8.8
CVE-2018-10884
Ansible Tower before versions 3.1.8 and 3.2.6 is vulnerable to cross-site request forgery (CSRF) in awx/api/authentication.py. An attacker could expl…
Ansible Tower
after 3.2.6
HIGH 8.8
CVE-2018-15564
An issue was discovered in daveismyname simple-cms through 2014-03-11. There is a CSRF vulnerability that can delete any page via admin/?delpage=8.
Simple Cms
after 2014-03-11
HIGH 8.8
CVE-2018-15565
An issue was discovered in daveismyname simple-cms through 2014-03-11. admin/addpage.php does not require authentication for adding a page. This can …
Simple Cms
after 2014-03-11
HIGH 8.8
CVE-2018-15568
tp5cms through 2017-05-25 has CSRF via admin.php/category/delete.html.
Tp5cms
after 2017-05-25
MEDIUM 6.5
CVE-2018-15569
my little forum 2.4.12 allows CSRF for deletion of users.
My Little Forum
Mitigation only
HIGH 8.8
CVE-2018-14057
Pimcore before 5.3.0 allows remote attackers to conduct cross-site request forgery (CSRF) attacks by leveraging validation of the X-pimcore-csrf-toke…
Pimcore
5.3.0+
CRITICAL 9.9
CVE-2018-1712
IBM API Connect's Developer Portal 5.0.0.0 through 5.0.8.3 is vulnerable to Server Side Request Forgery. An attacker, using specially crafted input p…
Api Connect
after 5.0.8.3
HIGH 8.8
CVE-2018-1455
IBM Tivoli Application Dependency Discovery Manager 7.2.2 and 7.3 is vulnerable to cross-site request forgery which could allow an attacker to execut…
Tivoli Application Dependency Discovery Manager
Mitigation only
MEDIUM 6.5
CVE-2018-13393
The convertCommentToAnswer resource in Atlassian Confluence Questions before version 2.6.6, the bundled version of Confluence Questions was updated t…
Questions For Confluence
2.6.6+
MEDIUM 6.5
CVE-2018-13394
The acceptAnswer resource in Atlassian Confluence Questions before version 2.6.6, the bundled version of Confluence Questions was updated to a fixed …
Questions For Confluence
2.6.6+
HIGH 8.8
CVE-2018-2442
In SAP BusinessObjects Business Intelligence, versions 4.0, 4.1 and 4.2, while viewing a Web Intelligence report from BI Launchpad, the user session …
Businessobjects Business Intelligence
Mitigation only
HIGH 8.8
CVE-2018-7097
A security vulnerability was identified in 3PAR Service Processor (SP) prior to SP-4.4.0.GA-110(MU7). The vulnerability may be exploited remotely to …
3par Service Provider
Mitigation only
HIGH 8.8
CVE-2018-14783
NetComm Wireless G LTE Light Industrial M2M Router (NWL-25) with firmware 2.0.29.11 and prior. A cross-site request forgery condition can occur, allo…
Nwl 25 Firmware
after 2.0.29.11
HIGH 8.8
CVE-2018-15186
PHP Scripts Mall Chartered Accountant : Auditor Website 2.0.1 has CSRF via client/auditor/updprofile.php.
Auditor Website Project
No fix yet
HIGH 8.0
CVE-2018-15187
PHP Scripts Mall advanced-real-estate-script 4.0.9 has CSRF via edit-profile.php.
Advanced Real Estate Script
No fix yet
MEDIUM 6.3
CVE-2018-15202
An issue was discovered in Juunan06 eCommerce through 2018-08-05. There is a CSRF vulnerability in ee/eBoutique/app/template/includes/crudTreatment.p…
Ecommerce
No fix yet
MEDIUM 6.5
CVE-2018-15203
An issue was discovered in Ignited CMS through 2017-02-19. ign/index.php/admin/pages/add_page allows a CSRF attack to add pages.
Ignitedcms
after 2017-02-19
HIGH 8.8
CVE-2018-15197
An issue was discovered in OneThink v1.1. There is a CSRF vulnerability in admin.php?s=/AuthManager/addToGroup.html that can endow administrator priv…
Onethink
No fix yet
HIGH 8.8
CVE-2018-15198
An issue was discovered in OneThink v1.1. There is a CSRF vulnerability in admin.php?s=/User/add.html that can add a user.
Onethink
No fix yet
HIGH 8.8
CVE-2018-15193
A CSRF vulnerability in the admin panel in Gogs through 0.11.53 allows remote attackers to execute admin operations via a crafted issue / link.
Gogs
No fix yet
HIGH 8.8
CVE-2018-15177
In Gxlcms 2.0, a news/index.php?s=Admin-Admin-Insert CSRF attack can add an administrator account.
Gxlcms
Mitigation only
HIGH 8.8
CVE-2013-7464
In csrf-magic before 1.0.4, if $GLOBALS['csrf']['secret'] is not configured, the Anti-CSRF Token used is predictable and would permit an attacker to …
Csrf Magic
1.0.4+
HIGH 8.8
CVE-2018-7060
Aruba ClearPass 6.6.x prior to 6.6.9 and 6.7.x prior to 6.7.1 is vulnerable to CSRF attacks against authenticated users. An attacker could manipulate…
Clearpass
6.6.9 / 6.7.1+
HIGH 8.8
CVE-2018-14978
An issue was discovered in QCMS 3.0.1. CSRF exists via the backend/user/admin/add.html URI.
Qcms
No fix yet
HIGH 8.8
CVE-2018-14960
Xiao5uCompany 1.7 has CSRF via admin/Admin.asp.
Xiao5ucompany
No fix yet
HIGH 8.8
CVE-2018-14963
zzcms 8.3 has CSRF via the admin/adminadd.php?action=add URI.
Zzcms
No fix yet
HIGH 8.8
CVE-2018-14965
An issue was discovered in EMLsoft 5.4.5. The eml/upload/eml/?action=address&do=add page allows CSRF.
Emlsoft
No fix yet