All vulnerabilities
9197 / 9197
Sort
8.8
CVE-2016-6277CVE KEV
NETGEAR R6250 before 1.0.4.6.Beta, R6400 before 1.0.1.18.Beta, R6700 before 1.0.1.14.Beta, R690…
2016-01-01KEV
EPSS99.8%
pct 99
5.0
CVE-2014-0054DEB
The Jaxb2RootElementHttpMessageConverter in Spring MVC in Spring Framework before 3.2.8 and 4.0…
2014-01-01
EPSS91.4%
pct 99
5.0
CVE-2013-6429DEB
The SourceHttpMessageConverter in Spring MVC in Spring Framework before 3.2.5 and 4.0.0.M1 thro…
2013-01-01
EPSS90.5%
pct 99
8.8
CVE-2022-41622CVE
In all versions,
BIG-IP and BIG-IQ are vulnerable to cross-site request forgery (CSRF) attack…
2022-01-01Pre-auth
EPSS88.0%
pct 99
5.5
CVE-2016-3718DEB KEV
The (1) HTTP and (2) FTP coders in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allow rem…
2016-01-01KEV
EPSS76.9%
pct 99
4.2
CVE-2018-1000600CVE
A exposure of sensitive information vulnerability exists in Jenkins GitHub Plugin 1.29.1 and ea…
2018-01-01
EPSS76.2%
pct 99
8.8
CVE-2018-7700CVE
DedeCMS 5.7 has CSRF with an impact of arbitrary code execution, because the partcode parameter…
2018-01-01Pre-auth
EPSS71.7%
pct 99
6.8
CVE-2015-2295CVE
Cross-site request forgery (CSRF) vulnerability in system_firmware_restorefullbackup.php in the…
2015-01-01
EPSS65.9%
pct 99
6.8
CVE-2015-6973CVE
Multiple cross-site request forgery (CSRF) vulnerabilities in Ignite Realtime Openfire 3.10.2 a…
2015-01-01
EPSS64.8%
pct 99
6.5
CVE-2022-28731DEB
A carefully crafted request on UserPreferences.jsp could trigger an CSRF vulnerability on Apach…
2022-01-01Pre-auth
EPSS56.3%
pct 98
4.3
CVE-2021-21745CVE
ZTE MF971R product has a Referer authentication bypass vulnerability. Without CSRF verification…
2021-01-01Pre-auth
EPSS55.7%
pct 98
4.3
CVE-2007-0044CVE
Adobe Acrobat Reader Plugin before 8.0.0 for the Firefox, Internet Explorer, and Opera web brow…
2007-01-01
EPSS55.5%
pct 98
8.8
CVE-2019-16667CVE
diag_command.php in pfSense 2.4.4-p3 allows CSRF via the txtCommand or txtRecallBuffer field, a…
2019-01-01Pre-auth
EPSS54.5%
pct 98
4.3
CVE-2020-2184CVE
A cross-site request forgery vulnerability in Jenkins CVS Plugin 2.15 and earlier allows attack…
2020-01-01Pre-auth
EPSS44.5%
pct 98
8.8
CVE-2019-9787DEB
WordPress before 5.1.1 does not properly filter comment content, leading to Remote Code Executi…
2019-01-01Pre-auth
EPSS43.8%
pct 98
8.0
CVE-2014-100005CVE KEV
Multiple cross-site request forgery (CSRF) vulnerabilities in D-Link DIR-600 router (rev. Bx) w…
2014-01-01KEV
EPSS42.4%
pct 98
9.1
CVE-2022-0482CVE
Exposure of Private Personal Information to an Unauthorized Actor in GitHub repository alextsel…
2022-01-01Pre-auth
EPSS38.1%
pct 98
8.8
CVE-2022-27226CVE
A CSRF issue in /api/crontab on iRZ Mobile Routers through 2022-03-16 allows a threat actor to …
2022-01-01Pre-auth
EPSS34.5%
pct 98
8.8
CVE-2017-1000479CVE
pfSense versions 2.4.1 and lower are vulnerable to clickjacking attacks in the CSRF error page …
2017-01-01Pre-auth
EPSS32.8%
pct 98
8.8
CVE-2019-0235CVE
Apache OFBiz 17.12.01 is vulnerable to some CSRF attacks.
2019-01-01Pre-auth
EPSS32.7%
pct 98
8.8
CVE-2023-2533CVE KEV
A Cross-Site Request Forgery (CSRF) vulnerability has been identified in
PaperCut NG/MF, which,…
2023-01-01KEV
EPSS29.5%
pct 97
4.6
CVE-2011-4642CVE
mappy.py in Splunk Web in Splunk 4.2.x before 4.2.5 does not properly restrict use of the mappy…
2011-01-01
EPSS28.9%
pct 97
6.5
CVE-2016-6897DEB
Cross-site request forgery (CSRF) vulnerability in the wp_ajax_update_plugin function in wp-adm…
2016-01-01Pre-auth
EPSS28.3%
pct 97
4.3
CVE-2022-23111CVE
A cross-site request forgery (CSRF) vulnerability in Jenkins Publish Over SSH Plugin 1.22 and e…
2022-01-01Pre-auth
EPSS27.6%
pct 97
9.8
CVE-2022-1020CVE
The Product Table for WooCommerce (wooproducttable) WordPress plugin before 3.1.2 does not have…
2022-01-01Pre-auth
EPSS26.2%
pct 97
8.8
CVE-2013-3568CVE
Cross-site request forgery (CSRF) vulnerability in Cisco Linksys WRT110 allows remote attackers…
2013-01-01Pre-auth
EPSS24.6%
pct 97
4.3
CVE-2014-4671CVE
Adobe Flash Player before 13.0.0.231 and 14.x before 14.0.0.145 on Windows and OS X and before …
2014-01-01
EPSS23.0%
pct 97
8.8
CVE-2023-48292CVE
The XWiki Admin Tools Application provides tools to help the administration of XWiki. Starting …
2023-01-01Pre-auth
EPSS22.9%
pct 97
8.6
CVE-2023-36052CVE
Azure CLI REST Command Information Disclosure Vulnerability
2023-01-01Pre-auth
EPSS21.5%
pct 97
6.5
CVE-2019-12616DEB
An issue was discovered in phpMyAdmin before 4.9.0. A vulnerability was found that allows an at…
2019-01-01Pre-auth
EPSS19.2%
pct 96
8.8
CVE-2023-22457CVE
CKEditor Integration UI adds support for editing wiki pages using CKEditor. Prior to versions 1…
2023-01-01Pre-auth
EPSS18.7%
pct 96
8.8
CVE-2019-12624CVE
A vulnerability in the web-based management interface of Cisco IOS XE New Generation Wireless C…
2019-01-01Pre-auth
EPSS18.7%
pct 96
8.8
CVE-2019-7262CVE
Linear eMerge E3-Series devices allow Cross-Site Request Forgery (CSRF).
2019-01-01Pre-auth
EPSS16.3%
pct 96
8.8
CVE-2017-9414CVE
Cross-site request forgery (CSRF) vulnerability in the Subscribe to Podcast feature in Subsonic…
2017-01-01Pre-auth
EPSS15.7%
pct 96
8.8
CVE-2020-5776CVE
Currently, all versions of MAGMI are vulnerable to CSRF due to the lack of CSRF tokens. RCE (vi…
2020-01-01Pre-auth
EPSS14.7%
pct 96
6.5
CVE-2019-19833CVE
In Tautulli 2.1.9, CSRF in the /shutdown URI allows an attacker to shut down the remote media s…
2019-01-01Pre-auth
EPSS14.7%
pct 96
9.8
CVE-2020-10181CVE KEV
goform/formEMR30 in Sumavision Enhanced Multimedia Router (EMR) 3.0.4.27 allows creation of arb…
2020-01-01KEV
EPSS14.2%
pct 96
8.8
CVE-2019-7391CVE
ZyXEL VMG3312-B10B DSL-491HNU-B1B v2 devices allow login/login-page.cgi CSRF.
2019-01-01Pre-auth
EPSS13.6%
pct 95
8.8
CVE-2019-6967CVE
AirTies Air5341 1.0.0.12 devices allow cgi-bin/login CSRF.
2019-01-01Pre-auth
EPSS13.5%
pct 95
7.5
CVE-2024-2449CVE
A cross-site request forgery vulnerability has been identified in LoadMaster. It is possible f…
2024-01-01Pre-auth
EPSS12.9%
pct 95
Select a vulnerability on the left to open the preview.