Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 6.8
CVE-2015-5188
Cross-site request forgery (CSRF) vulnerability in the Web Console (web-console) in Red Hat Enterprise Application Platform before 6.4.4 and WildFly …
Jboss Enterprise Application Platform
after 6.4.3
MEDIUM 5.1
CVE-2015-5665
Cross-site request forgery (CSRF) vulnerability in LOCKON EC-CUBE 2.11.0 through 2.13.3 allows remote attackers to hijack the authentication of arbit…
Ec Cube
Mitigation only
MEDIUM 6.8
CVE-2015-5660
Cross-site request forgery (CSRF) vulnerability in eXtplorer before 2.1.8 allows remote attackers to hijack the authentication of arbitrary users for…
Extplorer
after 2.1.7
MEDIUM 6.8
CVE-2015-7366
Multiple cross-site request forgery (CSRF) vulnerabilities in Revive Adserver before 3.2.2 allow remote attackers to hijack the authentication of use…
Revive Adserver
after 3.2.1
MEDIUM 6.8
CVE-2015-7364
The HTML_Quickform library, as used in Revive Adserver before 3.2.2, allows remote attackers to bypass the CSRF protection mechanism via an empty tok…
Revive Adserver
after 3.2.1
MEDIUM 6.0
CVE-2015-2026
Cross-site request forgery (CSRF) vulnerability in IBM WebSphere eXtreme Scale 7.1.0 before 7.1.0.3 and 7.1.1 before 7.1.1.1 allows remote authentica…
Websphere Extreme Scale
Patch available
MEDIUM 6.8
CVE-2015-0145
Cross-site request forgery (CSRF) vulnerability in IBM OpenPages GRC Platform 6.2 before IF7, 6.2.1 before 6.2.1.1 IF5, 7.0 before FP4, and 7.1 befor…
Openpages Grc Platform
Patch available
MEDIUM 6.8
CVE-2015-7612
Multiple cross-site request forgery (CSRF) vulnerabilities in the Organizations page in Enterprise Manager in McAfee Vulnerability Manager (MVM) 7.5.…
Vulnerability Manager
after 7.5.9
MEDIUM 6.8
CVE-2015-5075
Cross-site request forgery (CSRF) vulnerability in X2Engine X2CRM before 5.2 allows remote attackers to hijack the authentication of administrators f…
X2crm
after 5.0.9
MEDIUM 6.8
CVE-2015-6007
Cross-site request forgery (CSRF) vulnerability in Web Reference Database (aka refbase) through 0.9.6 allows remote attackers to hijack the authentic…
Refbase
after 0.9.6
MEDIUM 6.8
CVE-2015-6468
Cross-site request forgery (CSRF) vulnerability in Resource Data Management Data Manager before 2.2 allows remote attackers to hijack the authenticat…
Data Manager
after 2.1
MEDIUM 6.8
CVE-2015-6304
Cross-site request forgery (CSRF) vulnerability in Cisco TelePresence Server software 3.0(2.24) allows remote attackers to hijack the authentication …
Telepresence Server Software
Mitigation only
MEDIUM 6.8
CVE-2015-5991
Cross-site request forgery (CSRF) vulnerability in form2WlanSetup.cgi on Philippine Long Distance Telephone (PLDT) SpeedSurf 504AN devices with firmw…
Speedsurf 504an Firmware
Mitigation only
MEDIUM 6.8
CVE-2015-2916
Cross-site request forgery (CSRF) vulnerability on Securifi Almond devices with firmware before AL1-R201EXP10-L304-W34 and Almond-2015 devices with f…
Almond 2015 Firmware
Patch available
MEDIUM 5.1
CVE-2015-7233
Cross-site request forgery (CSRF) vulnerability in the OSF module 7.x-3.x before 7.x-3.1 for Drupal, when the OSF Import module is enabled, allows re…
Open Semantic Framework
Patch available
MEDIUM 6.8
CVE-2015-6973EPSS 65%
Multiple cross-site request forgery (CSRF) vulnerabilities in Ignite Realtime Openfire 3.10.2 allow remote attackers to hijack the authentication of …
Openfire
No fix yet
MEDIUM 6.8
CVE-2015-6966
Multiple cross-site request forgery (CSRF) vulnerabilities in Nibbleblog before 4.0.5 allow remote attackers to hijack the authentication of administ…
Nibbleblog
after 4.0.4
MEDIUM 6.8
CVE-2015-6965
Multiple cross-site request forgery (CSRF) vulnerabilities in the Contact Form Generator plugin 2.0.1 and earlier for WordPress allow remote attacker…
Contact Form Generator
after 2.0.1
MEDIUM 6.8
CVE-2015-6944
Cross-site request forgery (CSRF) vulnerability in JSP/MySQL Administrador Web 1 allows remote attackers to hijack the authentication of users for re…
Jsp\/mysql Administrador Web
No fix yet
MEDIUM 6.8
CVE-2015-5631
Cross-site request forgery (CSRF) vulnerability in the Remote UI on Canon PIXMA MG7500 printers allows remote attackers to hijack the authentication …
Pixma Mg7500 Series Inkjet Printer
Mitigation only
MEDIUM 6.8
CVE-2015-6827
Cross-site request forgery (CSRF) vulnerability in Auto-Exchanger 5.1.0 allows remote attackers to hijack the authentication of users for requests th…
Auto Exchanger
No fix yet
MEDIUM 6.8
CVE-2015-6545
Cross-site request forgery (CSRF) vulnerability in ajax.php in Cerb before 7.0.4 allows remote attackers to hijack the authentication of administrato…
Cerb
after 7.0.3
HIGH 7.5
CVE-2015-6728
The ApiBase::getWatchlistUser function in MediaWiki before 1.23.10, 1.24.x before 1.24.3, and 1.25.x before 1.25.2 does not perform token comparison …
Mediawiki
after 1.23.9
MEDIUM 6.8
CVE-2015-6655
Cross-site request forgery (CSRF) vulnerability in Pligg CMS 2.0.2 allows remote attackers to hijack the authentication of administrators for request…
Pligg Cms
No fix yet
MEDIUM 6.8
CVE-2014-2330
Multiple cross-site request forgery (CSRF) vulnerabilities in the Multisite GUI in Check_MK before 1.2.5i2 allow remote attackers to hijack the authe…
Check Mk
after 1.2.3
HIGH 7.5
CVE-2015-5698
Cross-site request forgery (CSRF) vulnerability in the web server on Siemens SIMATIC S7-1200 CPU devices with firmware before 4.1.3 allows remote att…
Simatic S7 1200 Cpu Firmware
after 4.1.2
MEDIUM 6.0
CVE-2015-5412
Cross-site request forgery (CSRF) vulnerability in HP Version Control Repository Manager (VCRM) before 7.5.0 allows remote authenticated users to hij…
Version Control Repository Manager
after 7.4.0
MEDIUM 6.8
CVE-2015-6262
Cross-site request forgery (CSRF) vulnerability in Cisco Prime Infrastructure 1.2(0.103) and 2.0(0.0) allows remote attackers to hijack the authentic…
Prime Infrastructure
Mitigation only
MEDIUM 6.8
CVE-2015-6660
The Form API in Drupal 6.x before 6.37 and 7.x before 7.39 does not properly validate the form token, which allows remote attackers to conduct CSRF a…
Drupal
Patch available
MEDIUM 6.8
CVE-2015-2905
Cross-site request forgery (CSRF) vulnerability on Actiontec GT784WN modems with firmware before NCS01-1.0.13 allows remote attackers to hijack the a…
Ncs01 Firmware
after 1.0.12