Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 8.8
CVE-2016-8941
IBM Tivoli Storage Productivity Center is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorize…
Spectrum Control
Patch available
HIGH 8.8
CVE-2016-5937
IBM Kenexa LCMS Premier on Cloud is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized acti…
Kenexa Lcms Premier
Patch available
HIGH 8.8
CVE-2016-6045
IBM Tivoli Storage Manager Operations Center is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unaut…
Tivoli Storage Manager
Patch available
HIGH 8.8
CVE-2016-3029
IBM Security Access Manager for Web is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized a…
Security Access Manager 9.0 Firmware
Patch available
HIGH 8.8
CVE-2016-9218
A vulnerability in Cisco Hybrid Meeting Server could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack …
Hybrid Meeting Server
Mitigation only
HIGH 8.8
CVE-2017-3794
A vulnerability in Cisco WebEx Meetings Server could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack …
Webex Meetings Server
Mitigation only
HIGH 8.8
CVE-2016-6521
Cross-site request forgery (CSRF) vulnerability in Grails console (aka Grails Debug Console and Grails Web Console) 2.0.7, 1.5.10, and earlier allows…
Grails
after 1.5.9
HIGH 8.8
CVE-2016-3406
Multiple cross-site request forgery (CSRF) vulnerabilities in Zimbra Collaboration before 8.7.0 allow remote attackers to hijack the authentication o…
Zimbra Collaboration Suite
after 8.6.0
MEDIUM 6.5
CVE-2016-6897EPSS 28%
Cross-site request forgery (CSRF) vulnerability in the wp_ajax_update_plugin function in wp-admin/includes/ajax-actions.php in WordPress before 4.6 a…
WordPress
after 4.5.5
HIGH 8.8
CVE-2016-7980
Cross-site request forgery (CSRF) vulnerability in ecrire/exec/valider_xml.php in SPIP 3.1.2 and earlier allows remote attackers to hijack the authen…
Spip
after 3.1.2
HIGH 8.0
CVE-2016-7904
Cross-site request forgery (CSRF) vulnerability in CMS Made Simple before 2.1.6 allows remote attackers to hijack the authentication of administrator…
Cms Made Simple
after 2.1.5
HIGH 8.8
CVE-2017-5492
Cross-site request forgery (CSRF) vulnerability in the widget-editing accessibility-mode feature in WordPress before 4.7.1 allows remote attackers to…
WordPress
after 4.7
HIGH 8.8
CVE-2017-5489
Cross-site request forgery (CSRF) vulnerability in WordPress before 4.7.1 allows remote attackers to hijack the authentication of unspecified victims…
WordPress
after 4.7
HIGH 8.0
CVE-2016-8201
A CSRF vulnerability in Brocade Virtual Traffic Manager versions released prior to and including 11.0 could allow an attacker to trick a logged-in us…
Virtual Traffic Manager
after 11.0
HIGH 8.8
CVE-2017-5473
Cross-site request forgery (CSRF) vulnerability in ntopng through 2.4 allows remote attackers to hijack the authentication of arbitrary users, as dem…
Ntopng
after 2.4
HIGH 8.8
CVE-2017-5475
comment.php in Serendipity through 2.0.5 allows CSRF in deleting any comments.
Serendipity
after 2.0.5
HIGH 8.8
CVE-2017-5476
Serendipity through 2.0.5 allows CSRF for the installation of an event plugin or a sidebar plugin.
Serendipity
after 2.0.5
HIGH 8.8
CVE-2016-4808
Web2py versions 2.14.5 and below was affected by CSRF (Cross Site Request Forgery) vulnerability, which allows an attacker to trick a logged in user …
Web2py
after 2.14.5
HIGH 8.8
CVE-2015-4593
eClinicalWorks Population Health (CCMR) suffers from a cross-site request forgery (CSRF) vulnerability in portalUserService.jsp which allows remote a…
Population Health
No fix yet
HIGH 8.0
CVE-2016-7454
CSRF vulnerability on Technicolor TC dpc3941T (formerly Cisco dpc3941T) devices with firmware dpc3941-P20-18-v303r20421733-160413a-CMCST allows an at…
Xfinity Gateway Router Dpc3941t Firmware
No fix yet
HIGH 8.8
CVE-2016-7885
Adobe Experience Manager versions 6.2 and earlier have a vulnerability that could be used in Cross-Site Request Forgery attacks.
Experience Manager
after 6.2.0
HIGH 8.8
CVE-2016-6277 KEVEPSS 100%
NETGEAR R6250 before 1.0.4.6.Beta, R6400 before 1.0.1.18.Beta, R6700 before 1.0.1.14.Beta, R6900, R7000 before 1.0.7.6.Beta, R7100LG before 1.0.0.28.…
D6220 Firmware
after 1.0.7.2_1.1.93
HIGH 8.8
CVE-2016-6468
A vulnerability in the web-based management interface of Cisco Emergency Responder could allow an unauthenticated, remote attacker to conduct a cross…
Emergency Responder
Mitigation only
CRITICAL 9.8
CVE-2016-9866
An issue was discovered in phpMyAdmin. When the arg_separator is different from its default & value, the CSRF token was not properly stripped from th…
phpMyAdmin
Patch available
HIGH 8.0
CVE-2016-2884
Cross-site request forgery (CSRF) vulnerability in IBM Forms Experience Builder 8.5.x and 8.6.x before 8.6.3.1, in an unspecified non-default configu…
Forms Experience Builder
Patch available
HIGH 8.0
CVE-2016-2878
Multiple cross-site request forgery (CSRF) vulnerabilities in IBM QRadar SIEM 7.1 before MR2 Patch 13 and 7.2 before 7.2.7 allow remote attackers to …
Qradar Security Information And Event Manager
Mitigation only
HIGH 8.8
CVE-2016-2963
Cross-site request forgery (CSRF) vulnerability in IBM BigFix Remote Control before 9.1.3 allows remote attackers to hijack the authentication of arb…
Bigfix Remote Control
after 9.1.2
HIGH 8.8
CVE-2016-8673
A vulnerability has been identified in SIMATIC CP 343-1 Advanced (incl. SIPLUS NET variant) (All versions < V3.0.53), SIMATIC CP 443-1 Advanced (incl…
Simatic S7 300 Cpu Firmware
Mitigation only
MEDIUM 6.5
CVE-2016-6454
A cross-site request forgery (CSRF) vulnerability in the web interface of the Cisco Hosted Collaboration Mediation Fulfillment application could allo…
Hosted Collaboration Mediation Fulfillment
Mitigation only
HIGH 8.8
CVE-2016-6444
A vulnerability in Cisco Meeting Server could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack against…
Meeting Server
Mitigation only