Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 6.1
CVE-2024-20986
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4…
Weblogic Server
Mitigation only
MEDIUM 6.1
CVE-2024-20933
Vulnerability in the Oracle Installed Base product of Oracle E-Business Suite (component: Engineering Change Order). Supported versions that are aff…
Installed Base
after 12.2.13
MEDIUM 6.5
CVE-2024-20718
Adobe Commerce versions 2.4.6-p3, 2.4.5-p5, 2.4.4-p6 and earlier are affected by a Cross-Site Request Forgery (CSRF) vulnerability that could result …
Commerce
Mitigation only
MEDIUM 6.5
CVE-2024-23785
Cross-site request forgery vulnerability in Energy Management Controller with Cloud Services JH-RVB1 /JH-RV11 Ver.B0.1.9.1 and earlier allows a remot…
Jh Rvb1 Firmware
Mitigation only
MEDIUM 6.8
CVE-2024-21381
Microsoft Azure Active Directory B2C Spoofing Vulnerability
Azure Active Directory
Patch available
HIGH 8.8
CVE-2024-25914
Cross-Site Request Forgery (CSRF) vulnerability in Photoboxone SMTP Mail.This issue affects SMTP Mail: from n/a through 1.3.20.
Smtp Mail
after 1.3.20
HIGH 8.8
CVE-2023-52431
The Plack::Middleware::XSRFBlock package before 0.0.19 for Perl allows attackers to bypass a CSRF protection mechanism via an empty form value and an…
\
0.0.19+
MEDIUM 5.4
CVE-2023-6499
The lasTunes WordPress plugin through 3.6.1 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could all…
Lastunes
after 3.6.1
HIGH 8.8
CVE-2024-24875
Cross-Site Request Forgery (CSRF) vulnerability in Yannick Lefebvre Link Library.This issue affects Link Library: from n/a through 7.5.13.
Link Library
after 7.5.13
HIGH 8.8
CVE-2024-24884
Cross-Site Request Forgery (CSRF) vulnerability in ARI Soft Contact Form 7 Connector.This issue affects Contact Form 7 Connector: from n/a through 1.…
Contact Form 7 Connector
after 1.2.2
HIGH 8.8
CVE-2024-24887
Cross-Site Request Forgery (CSRF) vulnerability in Contest Gallery Photos and Files Contest Gallery – Contact Form, Upload Form, Social Share and Vot…
Contest Gallery
21.2.9+
HIGH 8.8
CVE-2024-24929
Cross-Site Request Forgery (CSRF) vulnerability in Ryan Duff, Peter Westwood WP Contact Form.This issue affects WP Contact Form: from n/a through 1.6.
Wp Contact Form
after 1.6
HIGH 8.8
CVE-2024-24935
Cross-Site Request Forgery (CSRF) vulnerability in WpSimpleTools Basic Log Viewer.This issue affects Basic Log Viewer: from n/a through 1.0.4.
Basic Log Viewer
after 1.0.4
HIGH 8.8
CVE-2024-25417
flusity-CMS v2.33 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /core/tools/add_translation.php.
Flusity
No fix yet
HIGH 8.8
CVE-2024-25418
flusity-CMS v2.33 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /core/tools/delete_menu.php.
Flusity
No fix yet
HIGH 8.8
CVE-2024-25419
flusity-CMS v2.33 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /core/tools/update_menu.php.
Flusity
No fix yet
HIGH 8.8
CVE-2023-50349
Sametime is impacted by a Cross Site Request Forgery (CSRF) vulnerability. Some REST APIs in the Sametime Proxy application can allow an attacker to…
Sametime
12.0.2+
HIGH 8.8
CVE-2024-24819
icingaweb2-module-incubator is a working project of bleeding edge Icinga Web 2 libraries. In affected versions the class `gipfl\Web\Form` is the base…
Icingaweb2 Module Incubator
0.22.0+
HIGH 8.3
CVE-2024-24820
Icinga Director is a tool designed to make Icinga 2 configuration handling easy. Not any of Icinga Director's configuration forms used to manipulate …
Icinga
1.8.2 / 1.9.2+
HIGH 8.8
CVE-2023-47020
Multiple Cross-Site Request Forgery (CSRF) chaining in NCR Terminal Handler v.1.5.1 allows privileges to be escalated by an attacker through a crafte…
Terminal Handler
No fix yet
HIGH 8.8
CVE-2024-20254
Multiple vulnerabilities in Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an unauthenticated, remote at…
Expressway
after 15.0
HIGH 7.1
CVE-2024-20255
A vulnerability in the SOAP API of Cisco Expressway Series and Cisco TelePresence Video Communication Server could allow an unauthenticated, remote a…
Expressway
15.0+
HIGH 8.8
CVE-2024-20252
Multiple vulnerabilities in Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an unauthenticated, remote at…
Expressway
after 15.0
HIGH 8.8
CVE-2023-38579
The cross-site request forgery token in the request may be predictable or easily guessable allowing attackers to craft a malicious request, which cou…
L206 F2g Firmware
Mitigation only
HIGH 8.8
CVE-2024-24593
A cross-site request forgery (CSRF) vulnerability in all versions up to 1.14.1 of the api server component of Allegro AI’s ClearML platform allows a …
Clearml
after 1.14.1
HIGH 8.8
CVE-2024-0428
The Index Now plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.6.3. This is due to missing or…
Index Now
after 2.6.3
HIGH 8.8
CVE-2024-24468
Cross Site Request Forgery vulnerability in flusity-CMS v.2.33 allows a remote attacker to execute arbitrary code via the add_customblock.php.
Flusity
No fix yet
HIGH 8.8
CVE-2024-24469
Cross Site Request Forgery vulnerability in flusity-CMS v.2.33 allows a remote attacker to execute arbitrary code via the delete_post .php.
Flusity
No fix yet
HIGH 7.5
CVE-2024-23831
LedgerSMB is a free web-based double-entry accounting system. When a LedgerSMB database administrator has an active session in /setup.pl, an attacker…
Ledgersmb
1.10.30 / 1.11.9+
HIGH 8.8
CVE-2024-24470
Cross Site Request Forgery vulnerability in flusity-CMS v.2.33 allows a remote attacker to execute arbitrary code via the update_post.php component.
Flusity
No fix yet