Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 8.8
CVE-2024-22568
FlyCms v1.0 contains a Cross-Site Request Forgery (CSRF) vulnerability via /system/score/del.
Flycms
No fix yet
HIGH 8.8
CVE-2024-22591
FlyCms v1.0 contains a Cross-Site Request Forgery (CSRF) vulnerability via /system/user/group_save.
Flycms
No fix yet
HIGH 8.8
CVE-2024-22592
FlyCms v1.0 contains a Cross-Site Request Forgery (CSRF) vulnerability via /system/user/group_update
Flycms
No fix yet
HIGH 8.8
CVE-2024-22593
FlyCms v1.0 contains a Cross-Site Request Forgery (CSRF) vulnerability via /system/admin/add_group_save
Flycms
No fix yet
HIGH 8.8
CVE-2024-22416
pyLoad is a free and open-source Download Manager written in pure Python. The `pyload` API allows any API call to be made using GET requests. Since t…
Pyload Ng
0.5.0b3.dev78+
HIGH 8.8
CVE-2024-22715
Stupid Simple CMS <=1.2.4 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin-edit.php.
Stupid Simple Cms
after 1.2.4
HIGH 8.8
CVE-2022-41990
Cross-Site Request Forgery (CSRF) vulnerability in Vinoj Cardoza 3D Tag Cloud allows Stored XSS.This issue affects 3D Tag Cloud: from n/a through 3.8.
Cardoza 3d Tag Cloud
after 3.8
MEDIUM 6.5
CVE-2023-5006
The WP Discord Invite WordPress plugin before 2.5.1 does not protect some of its actions against CSRF attacks, allowing an unauthenticated attacker t…
Wp Discord Invite
2.5.1+
MEDIUM 6.1
CVE-2024-20940
Vulnerability in the Oracle Knowledge Management product of Oracle E-Business Suite (component: Create, Update, Authoring Flow). Supported versions …
Knowledge Management
after 12.2.13
MEDIUM 6.1
CVE-2024-20942
Vulnerability in the Oracle Complex Maintenance, Repair, and Overhaul product of Oracle Supply Chain (component: LOV). Supported versions that are a…
Complex Maintenance\, Repair\, And Overhaul
Patch available
MEDIUM 5.4
CVE-2024-20944
Vulnerability in the Oracle iSupport product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 1…
Isupport
after 12.2.13
MEDIUM 6.1
CVE-2024-20934
Vulnerability in the Oracle Installed Base product of Oracle E-Business Suite (component: Engineering Change Order). Supported versions that are aff…
Installed Base
after 12.2.13
MEDIUM 5.4
CVE-2023-7083
The Voting Record WordPress plugin through 2.0 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could …
Voting Record
after 2.0
HIGH 8.1
CVE-2022-3899
The 3dprint WordPress plugin before 3.5.6.9 does not protect against CSRF attacks in the modified version of Tiny File Manager included with the plug…
3dprint
3.5.6.9+
MEDIUM 6.5
CVE-2023-0824
The User registration & user profile WordPress plugin through 2.0 does not have CSRF check in some places, and is missing sanitisation as well as esc…
Userplus
after 2.0
MEDIUM 6.1
CVE-2021-24870
The WP Fastest Cache WordPress plugin before 0.9.5 is lacking a CSRF check in its wpfc_save_cdn_integration AJAX action, and does not sanitise and es…
Wp Fastest Cache
0.9.5+
MEDIUM 6.1
CVE-2022-1617
The WP-Invoice WordPress plugin through 4.3.1 does not have CSRF check in place when updating its settings, and is lacking sanitisation as well as es…
Wp Invoice
after 4.3.1
MEDIUM 6.1
CVE-2022-1618
The Coru LFMember WordPress plugin through 1.0.2 does not have CSRF check in place when adding a new game, and is lacking sanitisation as well as esc…
Coru Lfmember
after 1.0.2
HIGH 8.0
CVE-2024-0555
A Cross-Site Request Forgery (CSRF) vulnerability has been found on WIC1200, affecting version 1.1. An authenticated user could lead another user int…
Wic1200 Firmware
Mitigation only
HIGH 8.8
CVE-2024-0522
A vulnerability was found in Allegro RomPager 4.01. It has been classified as problematic. Affected is an unknown function of the file usertable.htm?…
Rompager
Mitigation only
HIGH 8.8
CVE-2023-51063
QStar Archive Solutions Release RELEASE_3-0 Build 7 Patch 0 was discovered to contain a DOM Based Reflected Cross Site Scripting (XSS) vulnerability …
Archive Storage Manager
No fix yet
HIGH 8.8
CVE-2023-51949
Verydows v2.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /protected/controller/backend/role_controller
Verydows
No fix yet
MEDIUM 5.4
CVE-2023-4247
The GiveWP plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.33.3. This is due to missing or incor…
Givewp
after 2.33.3
HIGH 8.8
CVE-2023-5448
The WP Register Profile With Shortcode plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.5.9. This…
Wp Register Profile With Shortcode
after 3.5.9
MEDIUM 6.5
CVE-2023-5455
A Cross-site request forgery vulnerability exists in ipa/session/login_password in all supported versions of IPA. This flaw allows an attacker to tri…
Fedora
Mitigation only
HIGH 8.1
CVE-2023-48258
The vulnerability allows a remote attacker to delete arbitrary files on the file system via a crafted URL or HTTP
request through a victim’s session.
Nexo Os
after 1500-sp2
MEDIUM 5.4
CVE-2023-50932
An issue was discovered in savignano S/Notify before 4.0.2 for Confluence. While an administrative user is logged on, the configuration settings of S…
S Notify
4.0.2+
MEDIUM 5.4
CVE-2023-50931
An issue was discovered in savignano S/Notify before 2.0.1 for Bitbucket. While an administrative user is logged on, the configuration settings of S/…
S Notify
2.0.1+
HIGH 7.1
CVE-2023-50930
An issue was discovered in savignano S/Notify before 4.0.2 for Jira. While an administrative user is logged on, the configuration settings of S/Notif…
S Notify
4.0.2+
MEDIUM 5.4
CVE-2023-6788
The Metform Elementor Contact Form Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.8…
Metform Elementor Contact Form Builder
after 3.8.1