Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 8.8
CVE-2024-28431
DedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via the component /dede/catalog_del.php.
Dedecms
No fix yet
HIGH 8.8
CVE-2024-28432
DedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via the component /dede/article_edit.php.
Dedecms
No fix yet
MEDIUM 6.5
CVE-2024-2416
Cross-Site Request Forgery vulnerability in Movistar's 4G router affecting version ES_WLD71-T1_v2.0.201820. This vulnerability allows an attacker to …
Mitigation only
MEDIUM 6.5
CVE-2024-2354
A vulnerability, which was classified as problematic, was found in Dreamer CMS 4.1.3. Affected is an unknown function of the file /admin/menu/toEdit.…
Dreamer Cms
Mitigation only
HIGH 8.8
CVE-2024-0203
The Digits plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 8.4.1. This is due to missing nonce val…
Digits
after 8.4.2
MEDIUM 6.1
CVE-2024-2215
A cross-site request forgery (CSRF) vulnerability in Jenkins docker-build-step Plugin 2.11 and earlier allows attackers to connect to an attacker-spe…
Docker Build Step
after 2.11
HIGH 7.4
CVE-2024-27694
FlyCms v1.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via the /system/share/ztree_category_edit.
Flycms
No fix yet
HIGH 8.1
CVE-2024-26469
Server-Side Request Forgery (SSRF) vulnerability in Tunis Soft "Product Designer" (productdesigner) module for PrestaShop before version 1.178.36, al…
Product Designer
1.178.36+
MEDIUM 6.5
CVE-2024-2134
A vulnerability has been found in Bdtask Hospita AutoManager up to 20240223 and classified as problematic. This vulnerability affects unknown code of…
Hospital Automanager
after 2024-02-23
MEDIUM 6.3
CVE-2024-27559
Stupid Simple CMS v1.2.4 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /save_settings.php
Stupid Simple Cms
after 1.2.4
HIGH 8.8
CVE-2024-27689
Stupid Simple CMS v1.2.4 was discovered to contain a Cross-Site Request Forgery (CSRF) via /update-article.php.
Stupid Simple Cms
after 1.2.4
MEDIUM 6.1
CVE-2023-52555
In mongo-express 1.0.2, /admin allows CSRF, as demonstrated by deletion of a Collection.
Mongo Express
No fix yet
MEDIUM 6.5
CVE-2023-28949
IBM Engineering Requirements Management DOORS 9.7.2.7 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious …
Engineering Requirements Management Doors
Mitigation only
MEDIUM 6.1
CVE-2024-21752
Cross-Site Request Forgery (CSRF) vulnerability in Ernest Marcinko Ajax Search Lite allows Reflected XSS.This issue affects Ajax Search Lite: from n/…
Ajax Search
4.11.5+
HIGH 8.8
CVE-2023-51531
Cross-Site Request Forgery (CSRF) vulnerability in Thrive Themes Thrive Automator.This issue affects Thrive Automator: from n/a through 1.17.
Thrive Automator
1.17.1+
HIGH 8.8
CVE-2023-51696
Cross-Site Request Forgery (CSRF) vulnerability in СleanTalk - Anti-Spam Protection Spam protection, Anti-Spam, FireWall by CleanTalk.This issue affe…
Anti Spam
6.21+
HIGH 8.8
CVE-2023-51528
Cross-Site Request Forgery (CSRF) vulnerability in Senol Sahin AI Power: Complete AI Pack – Powered by GPT-4.This issue affects AI Power: Complete AI…
Aipower
1.8.13+
HIGH 8.8
CVE-2023-51529
Cross-Site Request Forgery (CSRF) vulnerability in HasThemes HT Mega – Absolute Addons For Elementor.This issue affects HT Mega – Absolute Addons For…
Ht Mega
2.3.4+
HIGH 8.8
CVE-2023-51530
Cross-Site Request Forgery (CSRF) vulnerability in GS Plugins Logo Slider – Logo Showcase, Logo Carousel, Logo Gallery and Client Logo Presentation.T…
Logo Slider
3.5.2+
HIGH 8.8
CVE-2024-25930
Cross-Site Request Forgery (CSRF) vulnerability in Nuggethon Custom Order Statuses for WooCommerce.This issue affects Custom Order Statuses for WooCo…
Custom Order Status Manager For Woocommerce
after 1.5.2
HIGH 8.8
CVE-2024-25931
Cross-Site Request Forgery (CSRF) vulnerability in Heureka Group Heureka.This issue affects Heureka: from n/a through 1.0.8.
Heureka
1.1.0+
HIGH 8.8
CVE-2024-25932
Cross-Site Request Forgery (CSRF) vulnerability in Manish Kumar Agarwal Change Table Prefix change-table-prefix allows Cross Site Request Forgery.Thi…
Change Table Prefix
after 2.0
HIGH 8.8
CVE-2024-24701
Cross-Site Request Forgery (CSRF) vulnerability in Native Grid LLC A no-code page builder for beautiful performance-based content.This issue affects …
Setka Workflow
after 2.1.20
HIGH 8.8
CVE-2024-23519
Cross-Site Request Forgery (CSRF) vulnerability in M&S Consulting Email Before Download.This issue affects Email Before Download: from n/a through 6.…
Email Before Download
after 6.9.7
HIGH 8.8
CVE-2024-22939
Cross Site Request Forgery vulnerability in FlyCms v.1.0 allows a remote attacker to execute arbitrary code via the system/article/category_edit comp…
Flycms
No fix yet
MEDIUM 6.1
CVE-2024-0590
The Microsoft Clarity plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.9.3. This is due to mi…
Clarity
0.9.4+
MEDIUM 5.3
CVE-2024-0516
The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to unauthorized post metadata update due to a missing capability check on…
Royal Elementor Addons
1.3.88+
HIGH 8.8
CVE-2024-23910
Cross-site request forgery (CSRF) vulnerability in ELECOM wireless LAN routers and wireless LAN repeater allows a remote unauthenticated attacker to …
Wrc 1167gs2 B Firmware
1.27 / 1.31+
MEDIUM 5.4
CVE-2024-26450
An issue exists within Piwigo before v.14.2.0 allowing a malicious user to take over the application. This exploit involves chaining a Cross Site Req…
Piwigo
Mitigation only
HIGH 8.8
CVE-2023-52047
Dedecms v5.7.112 was discovered to contain a Cross-Site Request Forgery (CSRF) in the file manager.
Dedecms
Mitigation only