Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 5.4
CVE-2018-0216
A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to cond…
Identity Services Engine
Mitigation only
HIGH 8.8
CVE-2018-7565
CSRF exists on Polycom QDX 6000 devices.
Qdx 6000 Firmware
No fix yet
HIGH 8.8
CVE-2018-7746
An issue was discovered in Western Bridge Cobub Razor 0.7.2. Authentication is not required for /index.php?/manage/channel/modifychannel. For example…
Razor
No fix yet
HIGH 8.8
CVE-2018-7720
A cross-site request forgery (CSRF) vulnerability exists in Western Bridge Cobub Razor 0.7.2 via /index.php?/user/createNewUser/, resulting in accoun…
Razor
No fix yet
HIGH 8.8
CVE-2017-11649
Cross-site request forgery (CSRF) vulnerability in DrayTek Vigor AP910C devices with firmware 1.2.0_RC3 build r6594 allows remote attackers to hijack…
Vigorap 910c Firmware
No fix yet
HIGH 8.8
CVE-2018-7733
An issue was discovered in YxtCMF 3.1. RbacController.class.php has CSRF, as demonstrated by modifying an administrator account via index.php/admin/u…
Yxtcmf
after 3.1
MEDIUM 5.4
CVE-2018-7724
The management panel in Piwigo 2.9.3 has stored XSS via the name parameter in a /admin.php?page=photo-${photo_number} request. CSRF exploitation, rel…
Piwigo
No fix yet
HIGH 8.8
CVE-2018-7307
The Auth0 Auth0.js library before 9.3 has CSRF because it mishandles the case where the authorization response lacks the state parameter.
Auth0.js
9.3+
HIGH 8.8
CVE-2018-7634
An issue was discovered in Enalean Tuleap 9.17. Lack of CSRF attack mitigation while changing an e-mail address makes it possible to abuse the functi…
Tuleap
Patch available
HIGH 8.8
CVE-2018-7590
CSRF exists in Hoosk 1.7.0 via /admin/users/new/add, resulting in account creation.
Hoosk
Mitigation only
HIGH 8.8
CVE-2016-0295
Cross-site request forgery (CSRF) vulnerability in the IBM BigFix Platform 9.0, 9.1, 9.2, and 9.5 before 9.5.2 allows remote attackers to hijack the …
Bigfix Platform
9.5.2+
HIGH 8.8
CVE-2018-0520
Cross-site request forgery (CSRF) vulnerability in FS010W firmware FS010W_00_V1.3.0 and earlier allows an attacker to hijack the authentication of ad…
Fs010w Firmware
Mitigation only
MEDIUM 5.4
CVE-2018-0146
A vulnerability in the Cisco Data Center Analytics Framework application could allow an unauthenticated, remote attacker to conduct a cross-site requ…
Data Center Analytics Framework
Mitigation only
HIGH 8.8
CVE-2018-0148
A vulnerability in the web-based management interface of Cisco UCS Director Software and Cisco Integrated Management Controller (IMC) Supervisor Soft…
Ucs Director
Mitigation only
HIGH 8.8
CVE-2018-7308
A CSRF issue was found in var/www/html/files.php in DanWin hosting through 2018-02-11 that allows arbitrary remote users to add/delete/modify any fil…
Hosting
after 2018-02-11
HIGH 8.0
CVE-2016-0348
Cross-site request forgery (CSRF) vulnerability in IBM TRIRIGA Application Platform 3.3, 3.3.1, 3.3.2, and 3.4 allows remote attackers to hijack the …
Tririga Application Platform
Mitigation only
HIGH 7.5
CVE-2017-12415
OXID eShop Community Edition before 6.0.0 RC2 (development), 4.10.x before 4.10.5 (maintenance), and 4.9.x before 4.9.10 (legacy), Enterprise Edition…
Eshop
4.9.10 / 4.10.5+
MEDIUM 6.1
CVE-2018-6940
A /shell?cmd= XSS issue exists in the HTTPD component of NAT32 v2.2 Build 22284 devices that can be exploited for Remote Code Execution in conjunctio…
Nat32
No fix yet
HIGH 8.8
CVE-2018-6941
A /shell?cmd= CSRF issue exists in the HTTPD component of NAT32 v2.2 Build 22284 devices that can be exploited for Remote Code Execution in conjuncti…
Nat32
No fix yet
HIGH 8.8
CVE-2017-16756
An issue was discovered in Userscape HelpSpot before 4.7.2. A cross-site request forgery vulnerability exists on POST requests to the "index.php?pg=p…
Helpspot
after 4.7.1
HIGH 8.8
CVE-2018-7219
application/admin/controller/Admin.php in NoneCms 1.3.0 has CSRF, as demonstrated by changing an admin password or adding an account via a public/ind…
Nonecms
No fix yet
HIGH 8.0
CVE-2018-7216
Cross-site request forgery (CSRF) vulnerability in esop/toolkit/profile/regData.do in Bravo Tejari Procurement Portal allows remote authenticated use…
Bravo Solution
No fix yet
HIGH 8.8
CVE-2018-7176
FrontAccounting 2.4.3 suffers from a CSRF flaw, which leads to adding a user account via admin/users.php (aka the "add user" feature of the User Perm…
Frontaccounting
No fix yet
HIGH 8.8
CVE-2017-5781
A CSRF vulnerability in HPE Matrix Operating Environment version v7.6 was found.
Matrix Operating Environment
No fix yet
HIGH 8.8
CVE-2017-5796
A Remote Cross Site Request Forgery (CSRF) vulnerability in HPE 2620 Series Network Switches version RA.15.05.0006 was found.
J9627a Firmware
Mitigation only
HIGH 8.0
CVE-2016-8513
A Cross-Site Request Forgery (CSRF) vulnerability in HPE Version Control Repository Manager (VCRM) was found. The problem impacts all versions prior …
Version Control Repository Manager
7.6+
HIGH 8.1
CVE-2017-9963
A cross-site request forgery vulnerability exists on the Secure Gateway component of Schneider Electric's PowerSCADA Anywhere v1.0 redistributed with…
Powerscada Anywhere
Mitigation only
HIGH 8.0
CVE-2018-6888
An issue was discovered in Typesetter 5.1. The User Permissions page (aka Admin/Users) suffers from critical flaw of Cross Site Request forgery: usin…
Typesetter
No fix yet
HIGH 8.8
CVE-2018-1000053
LimeSurvey version 3.0.0-beta.3+17110 contains a Cross ite Request Forgery (CSRF) vulnerability in Theme Uninstallation that can result in CSRF causi…
Limesurvey
Patch available
HIGH 8.8
CVE-2017-17552
/LoadFrame in Zoho ManageEngine AD Manager Plus build 6590 - 6613 allows attackers to conduct URL Redirection attacks via the src parameter, resultin…
Manageengine Admanager Plus
6.6+