Weakness and search-intent cluster
Curated intelligence cluster
CSRF vulnerabilities
5 of 6 pages in this cluster are on CISA's KEV catalog, and 5 are past its remediation deadline.
Pages
6
Ransomware-linked
0
confirmed
Public PoC
5
repositories found
6 pages · showing 1–6 · sorted by kev listed ↓
| Title | Vendor | Signals | |||||
|---|---|---|---|---|---|---|---|
| CVE-2008-4128 | Cisco IOS Cross-Site Request Forgery Vulnerability | Cisco | 2026-07-13 | 2008-09-18 | 34% | 9.3 | 10 |
| CVE-2023-2533 | PaperCut MF/NG 22.0.10 (Build 65996 2023-03-27) - Remote code execution via CSRF | PaperCut | 2025-07-28 | 2023-06-20 | 29% | 8.8 | 715![]() |
| CVE-2014-100005 | D-Link DIR-600 Router Cross-Site Request Forgery (CSRF) Vulnerability | dlink | 2024-05-16 | 2015-01-13 | 43% | 8 | 1 |
| CVE-2016-6277 | NETGEAR Multiple Routers Remote Code Execution Vulnerability | NETGEAR | 2022-03-07 | 2016-12-14 | 100% | 8.8 | 246![]() |
| CVE-2020-10181 | Sumavision EMR Cross-Site Request Forgery (CSRF) Vulnerability | Sumavision | 2021-11-03 | 2020-03-11 | 15% | 9.8 | none yet |
| CVE-2025-15399 | Multiple vulnerabilities affect IBM License Key Server Administration and Reporting Tool and IBM LKS Administration Agent | IBM | n/a | 2026-09-18 | 0% | 10 | 5 |
Field coverage across these 6 pages: KEV listing date 5 · CVSS base score 6 · publication date 6 · EPSS 6 · threat-intel signals 2. Rows with no value on the column being sorted are listed last in both directions rather than counted as zero.
Reading a row
- ransomware
- CISA records known use in ransomware campaigns. Varies across this index, which is why it is on the row.
- PoC
- Public proof-of-concept repositories this deployment found on GitHub, and how many.
- EPSS
- FIRST's estimate of the probability the CVE is exploited in the next 30 days. Present on every record here.
- CVSS
- Base score, from scored sources only. "n/a" means no source scored it — not that the score is low.
