Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 8.8
CVE-2017-15732
In phpMyFAQ before 2.9.9, there is Cross-Site Request Forgery (CSRF) in admin/news.php.
Phpmyfaq
after 2.9.8
HIGH 8.8
CVE-2017-15733
In phpMyFAQ before 2.9.9, there is Cross-Site Request Forgery (CSRF) in admin/ajax.attachment.php and admin/att.main.php.
Phpmyfaq
after 2.9.8
HIGH 8.8
CVE-2017-15734
In phpMyFAQ before 2.9.9, there is Cross-Site Request Forgery (CSRF) in admin/stat.main.php.
Phpmyfaq
after 2.9.8
HIGH 8.8
CVE-2017-15735
In phpMyFAQ before 2.9.9, there is Cross-Site Request Forgery (CSRF) for modifying a glossary.
Phpmyfaq
after 2.9.8
HIGH 8.8
CVE-2017-15645
CSRF exists in Webmin 1.850. By sending a GET request to at/create_job.cgi containing dir=/&cmd= in the URI, an attacker to execute arbitrary command…
Webmin
after 1.850
HIGH 8.8
CVE-2017-12271
A vulnerability in Cisco SPA300 and SPA500 Series IP Phones could allow an unauthenticated, remote attacker to execute unwanted actions on an affecte…
Spa300 Firmware
after 7.5.5
HIGH 8.8
CVE-2015-7715
Cross-site request forgery (CSRF) vulnerability in the Realtyna RPL (com_rpl) component before 8.9.5 for Joomla! allows remote attackers to hijack th…
Realtyna Property Listing
8.9.5+
MEDIUM 5.7
CVE-2017-14956
AlienVault USM v5.4.2 and earlier offers authenticated users the functionality of exporting generated reports via the "/ossim/report/wizard_email.php…
Unified Security Management
after 5.4.2
HIGH 8.8
CVE-2014-3709
The org.keycloak.services.resources.SocialResource.callback method in JBoss KeyCloak before 1.0.3.Final allows remote attackers to conduct cross-site…
Keycloak
after 1.0.2.final
HIGH 8.8
CVE-2017-14011
A Cross-Site Request Forgery issue was discovered in ProMinent MultiFLEX M10a Controller web interface. The application does not sufficiently verify …
Multiflex M10a Controller Firmware
Mitigation only
HIGH 8.8
CVE-2017-15296
The Java component in SAP CRM has CSRF. This is SAP Security Note 2478964.
Customer Relationship Management
No fix yet
HIGH 8.8
CVE-2016-1261
J-Web does not validate certain input that may lead to cross-site request forgery (CSRF) issues or cause a denial of J-Web service (DoS).
Junos
Mitigation only
CRITICAL 9.8
CVE-2016-1265
A remote unauthenticated network based attacker with access to Junos Space may execute arbitrary code on Junos Space or gain access to devices manage…
Junos Space
after 15.1r2
HIGH 8.0
CVE-2016-5789
A Cross-site Request Forgery issue was discovered in JanTek JTC-200, all versions. An attacker could perform actions with the same permissions as a v…
Jtc 200 Firmware
Mitigation only
HIGH 8.0
CVE-2015-2142
Multiple cross-site request forgery (CSRF) vulnerabilities in Issuetracker phpBugTracker before 1.7.0 allow remote authenticated users to (1) hijack …
Phpbugtracker
after 1.6.0
HIGH 8.8
CVE-2015-2143
Multiple cross-site request forgery (CSRF) vulnerabilities in Issuetracker phpBugTracker before 1.7.0 allow remote attackers to hijack the authentica…
Phpbugtracker
after 1.6.0
MEDIUM 6.5
CVE-2017-15084
The web UI in Rapid7 Metasploit before 4.14.1-20170828 allows logout CSRF, aka R7-2017-22.
Metasploit
after 4.14.1
HIGH 8.8
CVE-2017-15063
There are CSRF vulnerabilities in Subrion CMS 4.1.x through 4.1.5, and before 4.2.0, because of a logic error. Although there is functionality to det…
Subrion
after 4.1.5
MEDIUM 6.5
CVE-2017-1000085
Subversion Plugin connects to a user-specified Subversion repository as part of form validation (e.g. to retrieve a list of tags). This functionality…
Subversion
after 2.8
HIGH 8.8
CVE-2017-1000090
Role-based Authorization Strategy Plugin was not requiring requests to its API be sent via POST, thereby opening itself to Cross-Site Request Forgery…
Role Based Authorization Strategy
after 2.5.0
MEDIUM 6.3
CVE-2017-1000091
GitHub Branch Source Plugin connects to a user-specified GitHub API URL (e.g. GitHub Enterprise) as part of form validation and completion (e.g. to v…
Github Branch Source
Mitigation only
HIGH 7.5
CVE-2017-1000092
Git Plugin connects to a user-specified Git repository as part of form validation. An attacker with no direct access to Jenkins but able to guess at …
Git
Mitigation only
HIGH 8.8
CVE-2017-1000093
Poll SCM Plugin was not requiring requests to its API be sent via POST, thereby opening itself to Cross-Site Request Forgery attacks. This allowed at…
Poll Scm
after 1.3.1
HIGH 8.8
CVE-2016-6806
Apache Wicket 6.x before 6.25.0, 7.x before 7.5.0, and 8.0.0-M1 provide a CSRF prevention measure that fails to discover some cross origin requests. …
Wicket
Mitigation only
HIGH 8.0
CVE-2017-14924
Cross-Site Request Forgery (CSRF) vulnerability via IMG element in Tiki before 16.3, 17.x before 17.1, 12 LTS before 12.12 LTS, and 15 LTS before 15.…
Tikiwiki Cms\/groupware
Patch available
HIGH 8.0
CVE-2017-14925
Cross-Site Request Forgery (CSRF) vulnerability via IMG element in Tiki before 16.3, 17.x before 17.1, 12 LTS before 12.12 LTS, and 15 LTS before 15.…
Tikiwiki Cms\/groupware
Patch available
HIGH 8.8
CVE-2015-9233
The cp-contact-form-with-paypal (aka CP Contact Form with PayPal) plugin before 1.1.6 for WordPress has CSRF with resultant XSS, related to cp_contac…
Cp Contact Form With Paypal
1.1.6+
HIGH 8.0
CVE-2017-13129
Cross-site request forgery (CSRF) vulnerability in ZKTeco ZKTime Web 2.0.1.12280 allows remote authenticated users to hijack the authentication of ad…
Zktime Web
Mitigation only
HIGH 8.8
CVE-2017-7969
A cross-site request forgery vulnerability exists on the Secure Gateway component of Schneider Electric's PowerSCADA Anywhere v1.0 redistributed with…
Powerscada Anywhere
Patch available
HIGH 8.8
CVE-2015-5182
Cross-site request forgery (CSRF) vulnerability in the jolokia API in A-MQ.
Amq
Mitigation only