Top technology
Linux 13140
Google 12530
Microsoft 12379
Oracle 6737
Apple 6692
Adobe 6387
Ibm 6330
Cisco 5757
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 5.4
CVE-2025-24713
Cross-Site Request Forgery (CSRF) vulnerability in Wow-Company Button Generator – easily Button Builder button-generation allows Cross Site Request F…
Mitigation only
MEDIUM 5.4
CVE-2025-24714
Cross-Site Request Forgery (CSRF) vulnerability in Wow-Company Bubble Menu – circle floating menu bubble-menu allows Cross Site Request Forgery.This …
Mitigation only
MEDIUM 5.4
CVE-2025-24715
Cross-Site Request Forgery (CSRF) vulnerability in Wow-Company Counter Box counter-box allows Cross Site Request Forgery.This issue affects Counter B…
Counter Box
2.0.6+
MEDIUM 5.4
CVE-2025-24647
Cross-Site Request Forgery (CSRF) vulnerability in datafeedr WooCommerce Cloak Affiliate Links woocommerce-cloak-affiliate-links allows Cross Site Re…
Mitigation only
HIGH 7.1
CVE-2025-24636
Cross-Site Request Forgery (CSRF) vulnerability in Rick Laymance MachForm Shortcode machform-shortcode allows Stored XSS.This issue affects MachForm …
Mitigation only
MEDIUM 5.4
CVE-2025-24622
Cross-Site Request Forgery (CSRF) vulnerability in PickPlugins Job Board Manager job-board-manager allows Cross Site Request Forgery.This issue affec…
Mitigation only
MEDIUM 6.5
CVE-2025-24572
Cross-Site Request Forgery (CSRF) vulnerability in Epsiloncool WP Fast Total Search fulltext-search allows Cross Site Request Forgery.This issue affe…
Mitigation only
HIGH 7.1
CVE-2025-24555
Cross-Site Request Forgery (CSRF) vulnerability in subscriptiondna Subscription DNA subscriptiondna allows Stored XSS.This issue affects Subscription…
Mitigation only
HIGH 7.1
CVE-2025-24561
Cross-Site Request Forgery (CSRF) vulnerability in awcode ReviewsTap reviewstap allows Stored XSS.This issue affects ReviewsTap: from n/a through <= …
Mitigation only
HIGH 7.1
CVE-2025-24562
Cross-Site Request Forgery (CSRF) vulnerability in Optimal Access KBucket kbucket allows Stored XSS.This issue affects KBucket: from n/a through <= 4…
Mitigation only
MEDIUM 5.4
CVE-2025-24546
Cross-Site Request Forgery (CSRF) vulnerability in RSTheme Ultimate Coming Soon & Maintenance ultimate-coming-soon allows Cross Site Request Forgery.…
Ultimate Coming Soon \& Maintenance
1.1.0+
HIGH 7.1
CVE-2025-22768
Cross-Site Request Forgery (CSRF) vulnerability in JinHan Park Rocket Media Library Mime Type rocket-media-library-mime-type allows Stored XSS.This i…
Mitigation only
HIGH 7.3
CVE-2024-56924
A Cross Site Request Forgery (CSRF) vulnerability in Code Astro Internet banking system 2.0.0 allows remote attackers to execute arbitrary JavaScript…
Internet Banking System
No fix yet
HIGH 8.8
CVE-2025-24398
Jenkins Bitbucket Server Integration Plugin 2.1.0 through 4.1.3 (both inclusive) allows attackers to craft URLs that would bypass the CSRF protection…
Bitbucket Server Integration
4.1.4+
HIGH 7.1
CVE-2025-23803
Cross-Site Request Forgery (CSRF) vulnerability in Rik Schennink Snippy snippy allows Reflected XSS.This issue affects Snippy: from n/a through <= 1.…
Mitigation only
HIGH 7.1
CVE-2025-23806
Cross-Site Request Forgery (CSRF) vulnerability in ThemeFarmer Ultimate Subscribe ultimate-subscribe allows Reflected XSS.This issue affects Ultimate…
Mitigation only
MEDIUM 6.1
CVE-2025-21550
Vulnerability in the Oracle Financial Services Behavior Detection Platform product of Oracle Financial Services Applications (component: Web UI). Su…
Financial Services Behavior Detection Platform
Mitigation only
MEDIUM 6.1
CVE-2025-21538
Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Web Runtime SEC). Supported versions that are affected …
Jd Edwards Enterpriseone Tools
9.2.9.2+
MEDIUM 5.4
CVE-2025-21526
Vulnerability in the Primavera P6 Enterprise Project Portfolio Management product of Oracle Construction and Engineering (component: Web Access). Su…
Primavera P6 Enterprise Project Portfolio Management
after 23.12.10.0
MEDIUM 6.1
CVE-2025-21513
Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Web Runtime SEC). Supported versions that are affected …
Jd Edwards Enterpriseone Tools
9.2.9.0+
MEDIUM 5.4
CVE-2025-21507
Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Web Runtime SEC). Supported versions that are affected …
Jd Edwards Enterpriseone Tools
9.2.9.0+
MEDIUM 6.1
CVE-2025-21489
Vulnerability in the Oracle Advanced Outbound Telephony product of Oracle E-Business Suite (component: Region Mapping). Supported versions that are …
E Business Suite
after 12.2.10
MEDIUM 6.1
CVE-2024-54792
A Cross-Site Request Forgery (CSRF) vulnerability has been found in SpagoBI v3.5.1 in the user administration panel. An authenticated user can lead a…
Spagobi
No fix yet
HIGH 8.2
CVE-2024-53829
CodeChecker is an analyzer tooling, defect database and viewer extension for the Clang Static Analyzer and Clang Tidy.
Cross-site request forgery al…
Codechecker
6.24.5+
HIGH 7.1
CVE-2025-24001
Cross-Site Request Forgery (CSRF) vulnerability in Ngô Thắng IT PPO Call To Actions ppo-call-to-actions allows Cross Site Request Forgery.This issue …
Mitigation only
MEDIUM 6.1
CVE-2024-13444
The wp-greet plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 6.2. This is due to missing or in…
Mitigation only
MEDIUM 6.1
CVE-2024-12005
The WP-BibTeX plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.0.1. This is due to missing or…
Wp Bibtex
3.0.2+
HIGH 8.1
CVE-2025-23044
PwnDoc is a penetration test report generator. There is no CSRF protection in pwndoc, allowing attackers to send requests on a logged-in user's behal…
Pwndoc
0.9.0+
MEDIUM 6.1
CVE-2024-13432
The Webcamconsult plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.5.0. This is due to missin…
Mitigation only
MEDIUM 6.1
CVE-2024-12385
The WP Abstracts plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.7.2. This is due to missing…
Wp Abstracts
2.7.3+