Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 8.8
CVE-2018-11349
The administration panel of Jirafeau before 3.4.1 is vulnerable to three CSRF attacks on search functionalities: search_by_name, search_by_hash, and …
Jirafeau
3.4.1+
HIGH 8.8
CVE-2018-13340
Gleez CMS 1.2.0 has CSRF, as demonstrated by a /page/add request.
Gleez Cms
No fix yet
HIGH 8.8
CVE-2018-12739
In BEESCMS 4.0, CSRF allows administrators to be added arbitrarily, a related issue to CVE-2018-10266.
Beescms
No fix yet
HIGH 8.8
CVE-2018-13031
DamiCMS v6.0.0 aand 6.1.0 allows CSRF via admin.php?s=/Admin/doadd to add an administrator account.
Damicms
No fix yet
HIGH 8.8
CVE-2016-10522
rails_admin ruby gem <v1.1.1 is vulnerable to cross-site request forgery (CSRF) attacks. Non-GET methods were not validating CSRF tokens and, as a re…
Rails Admin
1.1.1+
HIGH 8.8
CVE-2018-11636
Cross-site request forgery (CSRF) vulnerability in the administrative console in Dialogic PowerMedia XMS through 3.5 allows remote attackers to execu…
Powermedia Xms
after 3.5
HIGH 8.8
CVE-2018-13067
/upload/catalog/controller/account/password.php in OpenCart through 3.0.2.0 has CSRF via the index.php?route=account/password URI to change a user's …
Opencart
after 3.0.2.0
HIGH 8.8
CVE-2018-12529
An issue was discovered on Intex N150 devices. The router firmware suffers from multiple CSRF injection point vulnerabilities including changing user…
N150 Firmware
No fix yet
HIGH 8.8
CVE-2018-12574
CSRF exists for all actions in the web interface on TP-Link TL-WR841N v13 00000001 0.9.1 4.16 v0001.0 Build 180119 Rel.65243n devices.
Tl Wr841n Firmware
Mitigation only
HIGH 8.8
CVE-2018-13040
OpenSID 18.06-pasca has a CSRF vulnerability. This vulnerability can add an account (at the admin level) via the index.php/man_user/insert URI.
Opensid
No fix yet
HIGH 8.8
CVE-2018-13032
ECESSA ShieldLink SL175EHQ 10.7.4 devices have CSRF to add superuser accounts via the cgi-bin/pl_web.cgi/util_configlogin_act URI.
Shieldlink Sl175ehq Firmware
No fix yet
HIGH 8.8
CVE-2018-13010
WSTMall v1.9.1_170316 has CSRF via the index.php?m=Admin&c=Users&a=edit URI to add a user account.
Wstmall
No fix yet
MEDIUM 6.5
CVE-2018-12971
EasyCMS 1.3 has CSRF via the index.php?s=/admin/user/delAll URI to delete users.
Easycms
No fix yet
HIGH 8.8
CVE-2018-11447
A vulnerability has been identified in SCALANCE M875 (All versions). The web interface on port 443/tcp could allow a Cross-Site Request Forgery (CSRF…
Scalance M875 Firmware
Mitigation only
MEDIUM 6.5
CVE-2018-1000505
Tooltipy (tooltips for WP) version 5 contains a Cross ite Request Forgery (CSRF) vulnerability in Settings page that can result in could allow anybod…
Tooltipy
No fix yet
HIGH 8.8
CVE-2018-1000506
Metronet Tag Manager version 1.2.7 contains a Cross ite Request Forgery (CSRF) vulnerability in Settings page /wp-admin/options-general.php?page=metr…
Metronet Tag Manager
No fix yet
MEDIUM 6.5
CVE-2018-1000507
WP User Groups version 2.0.0 contains a Cross ite Request Forgery (CSRF) vulnerability in Settings page that can result in allows anybody to modify u…
Wp User Groups
No fix yet
HIGH 8.8
CVE-2018-12603
Cross-site request forgery (CSRF) vulnerability in admin.php in LFCMS 3.7.0 allows remote attackers to hijack the authentication of unspecified users…
Lfcms
No fix yet
HIGH 8.8
CVE-2018-12602
A CSRF vulnerability exists in LFCMS 3.7.0: users can be added arbitrarily.
Lfcms
No fix yet
HIGH 8.8
CVE-2018-12659
SLiMS 8 Akasia 8.3.1 allows remote attackers to bypass the CSRF protection mechanism and obtain admin access by omitting the csrf_token parameter.
Slims Akasia
No fix yet
HIGH 8.8
CVE-2018-0363
A vulnerability in the web-based management interface of Cisco Unified Communications Manager IM & Presence Service (formerly CUPS) could allow an un…
Unified Communications Manager Im And Presence Service
Mitigation only
HIGH 8.8
CVE-2018-0364
A vulnerability in the web-based management interface of Cisco Unified Communications Domain Manager could allow an unauthenticated, remote attacker …
Unified Communications Domain Manager
Mitigation only
HIGH 8.8
CVE-2018-0365
A vulnerability in the web-based management interface of Cisco Firepower Management Center could allow an unauthenticated, remote attacker to conduct…
Secure Firewall Management Center
Mitigation only
HIGH 8.8
CVE-2018-6563
Multiple cross-site request forgery (CSRF) vulnerabilities in totemomail Encryption Gateway before 6.0.0_Build_371 allow remote attackers to hijack t…
Encryption Gateway
after 6.0.0
HIGH 8.8
CVE-2018-12582
An issue was discovered in AKCMS 6.1. CSRF can add an admin account via a /index.php?file=account&action=manageaccounts&job=newaccount URI.
Akcms
No fix yet
MEDIUM 6.5
CVE-2018-12583
An issue was discovered in AKCMS 6.1. CSRF can delete an article via an admincp deleteitem action to index.php.
Akcms
No fix yet
HIGH 8.8
CVE-2018-6496
Remote Cross-site Request forgery (CSRF) potential has been identified in UCMBD Browser version 4.10, 4.11, 4.12, 4.13, 4.14, 4.15, 4.15.1 which coul…
Universal Cmbd Browser
after 4.15.1
HIGH 8.8
CVE-2018-6497
Remote Cross-site Request forgery (CSRF) potential has been identified in UCMBD Server version DDM Content Pack V 10.20, 10.21, 10.22, 10.22 CUP7, 10…
Cms Server
after 11.0
HIGH 8.8
CVE-2018-12114
Maccms 10 allows CSRF via admin.php/admin/admin/info.html to add user accounts.
Maccms
No fix yet
HIGH 8.8
CVE-2018-12354
Knowage (formerly SpagoBI) 6.1.1 allows CSRF via every form, as demonstrated by a /knowage/restful-services/2.0/analyticalDrivers/ POST request.
Knowage
Mitigation only