Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 8.8
CVE-2017-7557
dnsdist version 1.1.0 is vulnerable to a flaw in authentication mechanism for REST API potentially allowing CSRF attack.
Dnsdist
Patch available
HIGH 8.8
CVE-2017-5187
A Cross-Site Request Forgery (CWE-352) vulnerability in Directory Server (aka Enterprise Server Administration web UI) in Micro Focus Enterprise Deve…
Directory Server
after 2.3
HIGH 8.8
CVE-2017-7423
A Cross-Site Request Forgery (CWE-352) vulnerability in esfadmingui in Micro Focus Enterprise Developer and Enterprise Server 2.3, 2.3 Update 1 befor…
Enterprise Developer
Mitigation only
HIGH 8.8
CVE-2017-12881
Cross-site request forgery (CSRF) vulnerability in the Spring Batch Admin before 1.3.0 allows remote attackers to hijack the authentication of unspec…
Spring Batch Admin
after 1.2.1
HIGH 8.8
CVE-2015-5081
Cross-site request forgery (CSRF) vulnerability in django CMS before 3.0.14, 3.1.x before 3.1.1 allows remote attackers to manipulate privileged user…
Django Cms
after 3.0.13
HIGH 8.8
CVE-2017-12589
ToMAX R60G R60GV2-V2.0-v.2.6.3-170330 devices do not have any protection against a CSRF attack.
R60g Firmware
No fix yet
HIGH 8.8
CVE-2017-12593
ASUS DSL-N10S V2.1.16_APAC devices allow CSRF.
Dsl N10s Firmware
No fix yet
HIGH 8.8
CVE-2017-7556
Hawtio versions up to and including 1.5.3 are vulnerable to CSRF vulnerability allowing remote attackers to trick the user to visit their website con…
Hawtio
Mitigation only
HIGH 8.8
CVE-2017-12853
The RealTime RWR-3G-100 Router Firmware Version : Ver1.0.56 is affected by CSRF an attack that forces an end user to execute unwanted actions on a we…
Rwr 3g 100 Firmware
No fix yet
HIGH 8.8
CVE-2017-6328
The Symantec Messaging Gateway before 10.6.3-267 can encounter an issue of cross site request forgery (also known as one-click attack and is abbrevia…
Message Gateway
after 10.6.3-2
HIGH 8.8
CVE-2017-12651
Cross Site Request Forgery (CSRF) exists in the Blacklist and Whitelist IP Wizard in init.php in the Loginizer plugin before 1.3.6 for WordPress beca…
Loginizer
after 1.3.5
HIGH 8.8
CVE-2017-6756
A vulnerability in the Web UI Application of the Cisco Prime Collaboration Provisioning Tool through 12.2 could allow an unauthenticated, remote atta…
Prime Collaboration Provisioning
Mitigation only
HIGH 8.8
CVE-2017-10677
Cross-Site Request Forgery (CSRF) exists on Linksys EA4500 devices with Firmware Version before 2.1.41.164606, as demonstrated by a request to apply.…
Ea4500 Firmware
after 2.0.36
HIGH 8.8
CVE-2017-12584
There is no CSRF mitigation in SLiMS 8 Akasia through 8.3.1. Also, an entire user profile (including the password) can be updated without sending the…
Senayan Library Management System
after 8.3.1
HIGH 8.8
CVE-2017-9863
An issue was discovered in SMA Solar Technology products. If a user simultaneously has Sunny Explorer running and visits a malicious host, cross-site…
Sunny Boy 3600 Firmware
Mitigation only
HIGH 7.5
CVE-2017-12439
SocuSoft Flash Slideshow Maker Professional through v5.20, when the advanced configuration is used, has an xml_path HTTP parameter that trusts user-s…
Flash Slideshow Maker
after 5.20
HIGH 8.8
CVE-2017-2138
Cross-site request forgery (CSRF) vulnerability in CS-Cart Japanese Edition v4.3.10 and earlier (excluding v2 and v3), CS-Cart Multivendor Japanese E…
Cs Cart
after 4.3.10
HIGH 8.8
CVE-2017-11648
Techroutes TR 1803-3G Wireless Cellular Router/Modem 2.4.25 devices do not possess any protection against a CSRF vulnerability, as demonstrated by a …
Tr 1803 3g Firmware
Mitigation only
HIGH 8.8
CVE-2017-11726
services/system_io/actionprocessor/System.rails in ConnectWise Manage 2017.5 is vulnerable to Cross-Site Request Forgery (CSRF), as demonstrated by c…
Manage
No fix yet
HIGH 8.8
CVE-2016-9714
IBM InfoSphere Master Data Management Server 10.1, 11.0, 11.3, 11.4, 11.5, and 11.6 is vulnerable to cross-site request forgery which could allow an …
Infosphere Master Data Management Server
Patch available
HIGH 8.8
CVE-2016-9716
IBM InfoSphere Master Data Management Server 11.0, 11.3, 11.4, 11.5, and 11.6 is vulnerable to cross-site request forgery which could allow an attack…
Infosphere Master Data Management Server
Patch available
HIGH 8.8
CVE-2017-9489
The Comcast firmware on Cisco DPC3939B (firmware version dpc3939b-v303r204217-150321a-CMCST) devices allows configuration changes via CSRF.
Dpc3939b Firmware
No fix yet
HIGH 8.8
CVE-2017-9490
The Comcast firmware on Arris TG1682G (eMTA&DOCSIS version 10.0.132.SIP.PC20.CT, software version TG1682_2.2p7s2_PROD_sey) devices allows configurati…
Dpc3939b Firmware
No fix yet
HIGH 8.8
CVE-2017-11646
NetComm Wireless 4GT101W routers with Hardware: 0.01 / Software: V1.1.8.8 / Bootloader: 1.1.3 are vulnerable to CSRF attacks, as demonstrated by usin…
4gt101w Software
Mitigation only
HIGH 8.8
CVE-2017-11679
Cross-Site Request Forgery (CSRF) exists in Hashtopus 1.5g via the password parameter to admin.php in an a=config action.
Hashtopus
No fix yet
HIGH 8.8
CVE-2017-11680
Cross-Site Request Forgery (CSRF) exists in Hashtopussy 0.4.0, allowing an admin password change via users.php.
Hashtopussy
after 0.4.0
HIGH 8.8
CVE-2017-9413
Multiple cross-site request forgery (CSRF) vulnerabilities in the Podcast feature in Subsonic 6.1.1 allow remote attackers to hijack the authenticati…
Subsonic
No fix yet
HIGH 8.8
CVE-2017-2273
Cross-site request forgery (CSRF) vulnerability in WMR-433 firmware Ver.1.02 and earlier, WMR-433W firmware Ver.1.40 and earlier allows remote attack…
Wmr 433 Firmware
after 1.40
HIGH 7.5
CVE-2017-9415
Cross-site request forgery (CSRF) vulnerability in subsonic 6.1.1 allows remote attackers with knowledge of the target username to hijack the authent…
Subsonic
No fix yet
HIGH 8.8
CVE-2015-4639
Cross-site scripting (XSS) vulnerability in opac-addbybiblionumber.pl in Koha 3.14.x before 3.14.16, 3.16.x before 3.16.12, and 3.20.x before 3.20.1 …
Koha
Mitigation only