Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 8.8
CVE-2017-1631
IBM Jazz for Service Management (IBM Tivoli Components 1.1.3) is vulnerable to cross-site request forgery which could allow an attacker to execute ma…
Jazz For Service Management
Patch available
HIGH 8.8
CVE-2017-1746
IBM Jazz for Service Management (IBM Tivoli Components 1.1.3) is vulnerable to cross-site request forgery which could allow an attacker to execute ma…
Jazz For Service Management
Patch available
HIGH 8.8
CVE-2017-17774
admin/configuration.php in Piwigo 2.9.2 has CSRF.
Piwigo
Patch available
HIGH 8.8
CVE-2017-14092
The absence of Anti-CSRF tokens in Trend Micro ScanMail for Exchange 12.0 web interface forms could allow an attacker to submit authenticated request…
Scanmail
Patch available
HIGH 8.8
CVE-2017-5264
Versions of Nexpose prior to 6.4.66 fail to adequately validate the source of HTTP requests intended for the Automated Actions administrative web app…
Nexpose
6.4.66+
HIGH 7.3
CVE-2017-14362
Cross-Site Request Forgery vulnerability in Micro Focus Project and Portfolio Management Center, version 9.32. This vulnerability could be exploited …
Project And Portfolio Management
Mitigation only
HIGH 8.8
CVE-2017-17056
The ZKTime Web Software 2.0.1.12280 allows the Administrator to elevate the privileges of the application user using a 'password_change()' function o…
Zktime Web
No fix yet
HIGH 8.8
CVE-2017-12631
Apache CXF Fediz ships with a number of container-specific plugins to enable WS-Federation for applications. A CSRF (Cross Style Request Forgery) sty…
Cxf Fediz
1.3.3+
HIGH 8.8
CVE-2016-10701
In Hitachi Vantara Pentaho BA Platform through 8.0, a CSRF issue exists in the Business Analytics application.
Pentaho Business Analytics
after 8.0
HIGH 8.8
CVE-2017-8138
HedEx Earlier than V200R006C00 versions has a cross-site request forgery (CSRF) vulnerability. An attacker could trick a user into accessing a websit…
Hedex Lite
Mitigation only
HIGH 7.5
CVE-2017-4928
The flash-based vSphere Web Client (6.0 prior to 6.0 U3c and 5.5 prior to 5.5 U3f) i.e. not the new HTML5-based vSphere Client, contains SSRF and CRL…
Vcenter Server
Patch available
MEDIUM 6.5
CVE-2017-1000224
CSRF in YouTube (WordPress plugin) could allow unauthenticated attacker to change any setting within the plugin
Youtube
after 11.8.1
HIGH 8.8
CVE-2017-15516
NetApp SnapCenter Server versions 1.1 through 2.x are susceptible to a Cross-Site Request Forgery (CSRF) vulnerability which could be used to cause a…
Snapcenter Server
Patch available
HIGH 8.8
CVE-2017-7851
D-Link DCS-936L devices with firmware before 1.05.07 have an inadequate CSRF protection mechanism that requires the device's IP address to be a subst…
Dcs 936l
1.05.07+
HIGH 8.8
CVE-2017-11876
Microsoft Project Server and Microsoft SharePoint Enterprise Server 2016 allow an attacker to use cross-site forgery to read content that they are no…
Project Server
Patch available
CRITICAL 9.8
CVE-2017-16780EPSS 6%
The installer in MyBB before 1.8.13 allows remote attackers to execute arbitrary code by writing to the configuration file.
Mybb
after 1.8.12
HIGH 8.0
CVE-2017-16563
Cross-Site Request Forgery (CSRF) in the Basic Settings screen on Vonage (Grandstream) HT802 devices allows attackers to modify settings, related to …
Ht802 Firmware
No fix yet
HIGH 8.8
CVE-2017-16565
Cross-Site Request Forgery (CSRF) in /cgi-bin/login on Vonage (Grandstream) HT802 devices allows attackers to authenticate a user via the login scree…
Ht802 Firmware
No fix yet
HIGH 8.8
CVE-2017-16570
KeystoneJS before 4.0.0-beta.7 allows application-wide CSRF bypass by removing the CSRF parameter and value, aka SecureLayer7 issue number SL7_KEYJS_…
Keystone
4.0.0+
MEDIUM 6.8
CVE-2017-1000147
Mahara 1.9 before 1.9.8 and 1.10 before 1.10.6 and 15.04 before 15.04.3 are vulnerable to perform a cross-site request forgery (CSRF) attack on the u…
Mahara
Patch available
HIGH 8.8
CVE-2017-1300
IBM OpenPages GRC Platform 7.1, 7.2, and 7.3 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unaut…
Openpages Grc Platform
Patch available
HIGH 8.8
CVE-2017-1000244
Jenkins Favorite Plugin version 2.2.0 and older is vulnerable to CSRF resulting in data modification
Favorite
after 2.2.0
HIGH 8.8
CVE-2017-16244
Cross-Site Request Forgery exists in OctoberCMS 1.0.426 (aka Build 426) due to improper validation of CSRF tokens for postback handling, allowing an …
October
Patch available
HIGH 8.8
CVE-2015-5170
Cloud Foundry Runtime cf-release before 216, UAA before 2.5.2, and Pivotal Cloud Foundry (PCF) Elastic Runtime before 1.7.0 allow remote attackers to…
Cf Release
1.7.0 / 2.5.2+
HIGH 8.8
CVE-2012-4568
Multiple cross-site request forgery (CSRF) vulnerabilities in LetoDMS (formerly MyDMS) before 3.3.8 allow remote attackers to hijack the authenticati…
Letodms
after 3.3.7
HIGH 8.8
CVE-2015-2878
Multiple cross-site request forgery (CSRF) vulnerabilities in Hexis HawkEye G 3.0.1.4912 allow remote attackers to hijack the authentication of admin…
Hawkeye G
No fix yet
HIGH 8.8
CVE-2017-15808
In phpMyFaq before 2.9.9, there is CSRF in admin/ajax.config.php.
Phpmyfaq
after 2.9.8
HIGH 8.8
CVE-2017-15729
In phpMyFAQ before 2.9.9, there is Cross-Site Request Forgery (CSRF) for adding a glossary.
Phpmyfaq
after 2.9.8
HIGH 8.8
CVE-2017-15730
In phpMyFAQ before 2.9.9, there is Cross-Site Request Forgery (CSRF) in admin/stat.ratings.php.
Phpmyfaq
after 2.9.8
HIGH 8.8
CVE-2017-15731
In phpMyFAQ before 2.9.9, there is Cross-Site Request Forgery (CSRF) in admin/stat.adminlog.php.
Phpmyfaq
after 2.9.8