Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 8.0
CVE-2016-9991
IBM Sterling Order Management 9.2 through 9.5 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unau…
Sterling Selling And Fulfillment Foundation
Patch available
HIGH 8.8
CVE-2017-9517
atmail before 7.8.0.2 has CSRF, allowing an attacker to upload and import users via CSV.
Atmail
after 7.8.0.1
HIGH 8.8
CVE-2017-9518
atmail before 7.8.0.2 has CSRF, allowing an attacker to change the SMTP hostname and hijack all emails.
Atmail
after 7.8.0.1
HIGH 8.8
CVE-2017-9519
atmail before 7.8.0.2 has CSRF, allowing an attacker to create a user account.
Atmail
after 7.8.0.1
HIGH 8.8
CVE-2017-9444
BigTree CMS through 4.2.18 has CSRF related to the core\admin\modules\users\profile\update.php script (modify user information), the index.php/admin/…
Bigtree Cms
after 4.2.18
HIGH 8.8
CVE-2017-8836
CSRF exists on Peplink Balance 305, 380, 580, 710, 1350, and 2500 devices with firmware before fw-b305hw2_380hw6_580hw2_710hw3_1350hw2_2500-7.0.1-bui…
B305hw2 Firmware
No fix yet
HIGH 8.8
CVE-2016-8229
A cross-site request forgery vulnerability in Lenovo Service Bridge before version 4 could be exploited by an attacker with access to the DHCP server…
Lenovo Service Bridge
Mitigation only
HIGH 8.8
CVE-2017-9379
Multiple CSRF issues exist in BigTree CMS through 4.2.18 - the clear parameter to core\admin\modules\dashboard\vitals-statistics\404\clear.php and th…
Bigtree Cms
after 4.2.18
HIGH 8.8
CVE-2017-9365
CSRF exists in BigTree CMS through 4.2.18 with the force parameter to /admin/pages/revisions.php - for example: /admin/pages/revisions/1/?force=false…
Bigtree Cms
after 4.2.18
HIGH 8.8
CVE-2017-7917
A Cross-Site Request Forgery issue was discovered in Moxa OnCell G3110-HSPA Version 1.3 build 15082117 and previous versions, OnCell G3110-HSDPA Vers…
Oncell G3110 Hspa Firmware
after 1.4
HIGH 8.8
CVE-2017-9033
Cross-site request forgery (CSRF) vulnerability in Trend Micro ServerProtect for Linux 3.0 before CP 1531 allows remote attackers to hijack the authe…
Serverprotect
Patch available
HIGH 8.8
CVE-2015-3191
With Cloud Foundry Runtime cf-release versions v209 or earlier, UAA Standalone versions 2.2.6 or earlier and Pivotal Cloud Foundry Runtime 1.4.5 or e…
Cf Release
after 209
HIGH 8.0
CVE-2017-5657
Several REST service endpoints of Apache Archiva are not protected against Cross Site Request Forgery (CSRF) attacks. A malicious site opened in the …
Archiva
after 2.2.1
HIGH 8.8
CVE-2016-4854
Cross-site request forgery (CSRF) vulnerability in L-04D firmware version V10a and V10b allows remote attackers to hijack the authentication of admin…
L 04d Firmware
Mitigation only
HIGH 8.8
CVE-2016-4904
Cross-site request forgery (CSRF) vulnerability in WP-OliveCart versions prior to 3.1.3 and WP-OliveCartPro versions prior to 3.1.8 allows remote att…
Olivecart
after 3.1.7
HIGH 8.8
CVE-2017-6634
A vulnerability in the Device Manager web interface of Cisco Industrial Ethernet 1000 Series Switches 1.3 could allow an unauthenticated, remote atta…
Industrial Ethernet 1000 Series Firmware
Mitigation only
MEDIUM 6.5
CVE-2017-7620
MantisBT before 1.3.11, 2.x before 2.3.3, and 2.4.x before 2.4.1 omits a backslash check in string_api.php and consequently has conflicting interpret…
Mantisbt
after 1.3.10
HIGH 8.6
CVE-2017-9062
In WordPress before 4.7.5, there is improper handling of post meta data values in the XML-RPC API.
WordPress
after 4.7.4
HIGH 8.8
CVE-2017-9064
In WordPress before 4.7.5, a Cross Site Request Forgery (CSRF) vulnerability exists in the filesystem credentials dialog because a nonce is not requi…
WordPress
after 4.7.4
HIGH 8.8
CVE-2016-3403
Multiple cross-site request forgery (CSRF) vulnerabilities in the Admin Console in Zimbra Collaboration before 8.6.0 Patch 8 allow remote attackers t…
Zimbra Collaboration Suite
after 8.6.0
HIGH 8.8
CVE-2017-7661
Apache CXF Fediz ships with a number of container-specific plugins to enable WS-Federation for applications. A CSRF (Cross Style Request Forgery) sty…
Cxf Fediz
after 1.4.0
HIGH 8.8
CVE-2017-7662
Apache CXF Fediz ships with an OpenId Connect (OIDC) service which has a Client Registration Service, which is a simple web application that allows c…
Cxf Fediz
after 1.3.2
HIGH 8.8
CVE-2017-8928
mailcow 0.14, as used in "mailcow: dockerized" and other products, has CSRF.
Mailcow\
Patch available
HIGH 8.8
CVE-2017-8930
Multiple cross-site request forgery (CSRF) vulnerabilities in Simple Invoices 2013.1.beta.8 allow remote attackers to hijack the authentication of ad…
Simple Invoices
Mitigation only
HIGH 8.8
CVE-2016-4876
Cross-site request forgery (CSRF) vulnerability in baserCMS version 3.0.10 and earlier allows remote attackers to hijack the authentication of admini…
Basercms
Patch available
HIGH 8.8
CVE-2016-4878
Cross-site request forgery (CSRF) vulnerability in baserCMS version 3.0.10 and earlier allows remote attackers to hijack the authentication of admini…
Basercms
Patch available
HIGH 8.8
CVE-2016-4879
Cross-site request forgery (CSRF) vulnerability in baserCMS plugin Mail version 3.0.10 and earlier allows remote attackers to hijack the authenticati…
Basercms
after 3.0.10
HIGH 8.8
CVE-2016-4881
Cross-site request forgery (CSRF) vulnerability in baserCMS plugin Blog version 3.0.10 and earlier allows remote attackers to hijack the authenticati…
Basercms
Patch available
HIGH 8.8
CVE-2016-4882
Cross-site request forgery (CSRF) vulnerability in baserCMS version 3.0.10 and earlier allows remote attackers to hijack the authentication of admini…
Basercms
Patch available
HIGH 8.8
CVE-2016-4884
Cross-site request forgery (CSRF) vulnerability in baserCMS plugin Blog version 3.0.10 and earlier allows remote attackers to hijack the authenticati…
Basercms
Patch available