Vulnerability index

Browse CVEs

38 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
Tomcat MEDIUM 6.8
CVE-2013-6357

Cross-site request forgery (CSRF) vulnerability in the Manager application in Apache Tomcat 5.5.25 and earlier allows remote attackers to hijack the …

Fix: after 5.5.25
Fix from $1,600 2013-11-13
Struts MEDIUM 6.8
CVE-2012-4386

The token check mechanism in Apache Struts 2.0.0 through 2.3.4 does not properly validate the token name configuration parameter, which allows remote…

Mitigation only
Fix from $1,600 2012-09-05
Roller MEDIUM 6.8
CVE-2012-2380

Multiple cross-site request forgery (CSRF) vulnerabilities in the admin/editor console in Apache Roller before 5.0.1 allow remote attackers to hijack…

Fix: after 5.0
Fix from $1,600 2012-06-26
Archiva MEDIUM 6.8
CVE-2011-1026

Multiple cross-site request forgery (CSRF) vulnerabilities in Apache Archiva 1.0 through 1.2.2, and 1.3.x before 1.3.5, allow remote attackers to hij…

No fix yet
Fix from $1,600 2011-06-02
Archiva MEDIUM 6.8
CVE-2010-3449

Cross-site request forgery (CSRF) vulnerability in Redback before 1.2.4, as used in Apache Archiva 1.0 through 1.0.3, 1.1 through 1.1.4, 1.2 through …

Fix: after 1.2.3
Fix from $1,600 2010-12-06
Couchdb MEDIUM 6.8
CVE-2010-2234

Cross-site request forgery (CSRF) vulnerability in Apache CouchDB 0.8.0 through 0.11.0 allows remote attackers to hijack the authentication of admini…

Mitigation only
Fix from $1,600 2010-08-19
Activemq MEDIUM 6.8
CVE-2010-1244

Cross-site request forgery (CSRF) vulnerability in createDestination.action in Apache ActiveMQ before 5.3.1 allows remote attackers to hijack the aut…

Fix: after 5.3.0
Fix from $1,600 2010-04-05
Geronimo MEDIUM 6.8
CVE-2009-0039EPSS 11%

Multiple cross-site request forgery (CSRF) vulnerabilities in the web administration console in Apache Geronimo Application Server 2.1 through 2.1.3 …

No fix yet
Fix from $1,600 2009-04-17