Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 8.8
CVE-2024-46394
FrogCMS v0.9.5 was discovered to contain a Cross-Site Request Forgery (CSRF) via /admin/?/user/add
Frogcms
No fix yet
HIGH 8.8
CVE-2024-46086
FrogCMS V0.9.5 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/?/plugin/file_manager/delete/123
Frogcms
No fix yet
MEDIUM 6.1
CVE-2024-44064
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LikeBtn Like Button Rating likebtn-like-button.…
Like Button Rating
2.6.54+
HIGH 8.8
CVE-2024-46085
FrogCMS V0.9.5 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/?/plugin/file_manager/rename
Frogcms
Mitigation only
HIGH 8.8
CVE-2024-46362
FrogCMS V0.9.5 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/?/plugin/file_manager/create_directory
Frogcms
No fix yet
MEDIUM 6.5
CVE-2024-8490
The PropertyHive plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.0.19. This is due to missin…
Propertyhive
2.0.20+
MEDIUM 5.4
CVE-2024-8043
The Vikinghammer Tweet WordPress plugin through 0.2.4 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which…
Vikinghammer Tweet
after 0.2.4
MEDIUM 6.5
CVE-2024-8044
The infolinks Ad Wrap WordPress plugin through 1.0.2 does not have CSRF check in place when updating its settings, which could allow attackers to mak…
Infolinks Ad Wrap
after 1.0.2
MEDIUM 6.5
CVE-2024-8047
The Visual Sound (old) WordPress plugin through 1.06 does not have CSRF check in place when updating its settings, which could allow attackers to mak…
Visual Sound
after 1.06
MEDIUM 5.4
CVE-2024-8051
The Special Feed Items WordPress plugin through 1.0.1 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which…
Special Feed Items
after 1.0.1
MEDIUM 6.1
CVE-2024-8052
The Review Ratings WordPress plugin through 1.6 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could…
Review Ratings
after 1.6
MEDIUM 6.5
CVE-2024-8091
The Enhanced Search Box WordPress plugin through 0.6.1 does not have CSRF check in place when updating its settings, which could allow attackers to m…
Enhanced Search Box
after 0.6.1
MEDIUM 5.4
CVE-2024-8092
The Accordion Image Menu WordPress plugin through 3.1.3 does not have CSRF check in some places, and is missing sanitisation as well as escaping, whi…
Accordion Image Menu
after 3.1.3
MEDIUM 6.5
CVE-2024-8093
The Posts reminder WordPress plugin through 0.20 does not have CSRF check in place when updating its settings, which could allow attackers to make a …
Posts Reminder
after 0.20
HIGH 8.1
CVE-2024-6862
A Cross-Site Request Forgery (CSRF) vulnerability exists in lunary-ai/lunary version 1.2.34 due to overly permissive CORS settings. This vulnerabilit…
Lunary
Patch available
HIGH 8.8
CVE-2024-7423
The Stream plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.0.1. This is due to missing or in…
Stream
4.0.2+
MEDIUM 6.8
CVE-2024-7863
The Favicon Generator (CLOSED) WordPress plugin before 2.1 does not validate files to be uploaded and does not have CSRF checks, which could allow at…
Favicon Generator
2.1+
MEDIUM 6.5
CVE-2024-7864
The Favicon Generator (CLOSED) WordPress plugin before 2.1 does not have CSRF and path validation in the output_sub_admin_page_0() function, allowing…
Favicon Generator
2.1+
MEDIUM 6.5
CVE-2024-7862
The blogintroduction-wordpress-plugin WordPress plugin through 0.3.0 does not have CSRF check in place when updating its settings, which could allow …
Blogintroduction Wordpress Plugin
after 0.3.0
MEDIUM 6.1
CVE-2024-7816
The Gixaw Chat WordPress plugin through 1.0 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could all…
Gixaw Chat
after 1.0
MEDIUM 6.5
CVE-2024-7817
The Misiek Photo Album WordPress plugin through 1.4.3 does not have CSRF checks in some places, which could allow attackers to make logged in users d…
Misiek Photo Album
after 1.4.3
MEDIUM 6.5
CVE-2024-7820
The ILC Thickbox WordPress plugin through 1.0 does not have CSRF check in place when updating its settings, which could allow attackers to make a log…
Ilc Thickbox
after 1.0
MEDIUM 6.5
CVE-2024-7859
The Visual Sound WordPress plugin through 1.03 does not have CSRF check in place when updating its settings, which could allow attackers to make a lo…
Visual Sound
after 1.03
MEDIUM 6.1
CVE-2024-6017
The Music Request Manager WordPress plugin through 1.3 does not have CSRF check in some places, and is missing sanitisation as well as escaping, whic…
Music Request Manager
after 1.3
CRITICAL 9.8
CVE-2024-44677
eladmin v2.7 and before is vulnerable to Server-Side Request Forgery (SSRF) which allows an attacker to execute arbitrary code via the DatabaseContro…
Eladmin
after 2.7
MEDIUM 6.5
CVE-2024-45504
Cross-site request forgery (CSRF) vulnerability in multiple Alps System Integration products and the OEM products allow a remote unauthenticated atta…
Mitigation only
MEDIUM 6.5
CVE-2024-7688
The AZIndex WordPress plugin through 0.8.1 does not have CSRF checks in some places, which could allow attackers to make logged in admin delete arbit…
Azindex
after 0.8.1
MEDIUM 6.8
CVE-2024-45172
An issue was discovered in za-internet C-MOR Video Surveillance 5.2401 and 6.00PL01. Due to missing protection mechanisms, the C-MOR web interface is…
C Mor Video Surveillance
No fix yet
MEDIUM 6.1
CVE-2024-45527
REDCap 14.7.0 allows HTML injection via the project title of a New Project action. This can lead to resultant logout CSRF via index.php?logout=1, and…
Redcap
No fix yet
HIGH 8.0
CVE-2024-42793
A Cross-Site Request Forgery (CSRF) vulnerability was found in Kashipara Music Management System v1.0 via a crafted request to the /music/ajax.php?ac…
Music Management System
No fix yet