Weakness and search-intent cluster
Curated intelligence cluster
CSRF vulnerabilities
5 of 5 pages in this cluster are on CISA's KEV catalog, and 5 are past its remediation deadline.
Pages
5
Ransomware-linked
0
confirmed
Public PoC
4
repositories found
5 pages · showing 1–5 · sorted by kev listed ↓
| Title | Vendor | Signals | |||||
|---|---|---|---|---|---|---|---|
| CVE-2008-4128 | Cisco IOS Cross-Site Request Forgery Vulnerability | Cisco | 2026-07-13 | 2008-09-18 | 34% | 9.3 | 9 |
| CVE-2023-2533 | PaperCut MF/NG 22.0.10 (Build 65996 2023-03-27) - Remote code execution via CSRF | PaperCut | 2025-07-28 | 2023-06-20 | 29% | 8.8 | 72![]() |
| CVE-2014-100005 | D-Link DIR-600 Router Cross-Site Request Forgery (CSRF) Vulnerability | dlink | 2024-05-16 | 2015-01-13 | 42% | 8 | 1 |
| CVE-2016-6277 | NETGEAR Multiple Routers Remote Code Execution Vulnerability | NETGEAR | 2022-03-07 | 2016-12-14 | 100% | 8.8 | 226![]() |
| CVE-2020-10181 | Sumavision EMR Cross-Site Request Forgery (CSRF) Vulnerability | Sumavision | 2021-11-03 | 2020-03-11 | 15% | 9.8 | none yet |
Field coverage across these 5 pages: KEV listing date 5 · CVSS base score 5 · publication date 5 · EPSS 5 · threat-intel signals 2. Rows with no value on the column being sorted are listed last in both directions rather than counted as zero.
Reading a row
- ransomware
- CISA records known use in ransomware campaigns. Varies across this index, which is why it is on the row.
- PoC
- Public proof-of-concept repositories this deployment found on GitHub, and how many.
- EPSS
- FIRST's estimate of the probability the CVE is exploited in the next 30 days. Present on every record here.
- CVSS
- Base score, from scored sources only. "n/a" means no source scored it — not that the score is low.
