Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
HIGH 7.5
CVE-2024-34069
Werkzeug is a comprehensive WSGI web application library. The debugger in affected versions of Werkzeug can allow an attacker to execute code on a de…
Debian Linux
3.0.3+
HIGH 8.8
CVE-2021-44227
In GNU Mailman before 2.1.38, a list member or moderator can get a CSRF token and craft an admin request (using that token) to set a new admin passwo…
Debian Linux
2.1.38+
HIGH 8.0
CVE-2021-42097
GNU Mailman before 2.1.35 may allow remote Privilege Escalation. A csrf_token value is not specific to a single user account. An attacker can obtain …
Debian Linux
2.1.35+
MEDIUM 6.5
CVE-2020-12626
An issue was discovered in Roundcube Webmail before 1.4.4. A CSRF attack can cause an authenticated user to be logged out because POST was not consid…
Debian Linux
1.4.4+
MEDIUM 6.5
CVE-2012-4385
letodms 3.3.6 has CSRF via change password
Debian Linux
No fix yet
MEDIUM 6.5
CVE-2013-6275
Multiple CSRF issues in Horde Groupware Webmail Edition 5.1.2 and earlier in basic.php.
Debian Linux
after 5.1.2
HIGH 8.8
CVE-2013-6364
Horde Groupware Webmail Edition has CSRF and XSS when saving search as a virtual address book
Debian Linux
No fix yet
MEDIUM 5.3
CVE-2013-6365
Horde Groupware Web mail 5.1.2 has CSRF with requests to change permissions
Debian Linux
Patch available
HIGH 8.8
CVE-2019-16993
In phpBB before 3.1.7-PL1, includes/acp/acp_bbcodes.php has improper verification of a CSRF token on the BBCode page in the Administration Control Pa…
Debian Linux
after 3.1.7
HIGH 8.8
CVE-2019-12466
Wikimedia MediaWiki through 1.32.1 allows CSRF.
Debian Linux
after 1.32.1
HIGH 8.8
CVE-2017-0362
Mediawiki before 1.28.1 / 1.27.2 / 1.23.16 contains a flaw where the "Mark all pages visited" on the watchlist does not require a CSRF token.
Debian Linux
1.27.2 / 1.28.1+
HIGH 8.8
CVE-2018-8764
Roland Gruber Softwareentwicklung LDAP Account Manager before 6.3 places a CSRF token in the sec_token parameter of a URI, which makes it easier for …
Debian Linux
6.3+
HIGH 8.8
CVE-2015-5395
Cross-site request forgery (CSRF) vulnerability in SOGo before 3.1.0.
Debian Linux
3.1.0+
HIGH 8.8
CVE-2017-7178
CSRF was discovered in the web UI in Deluge before 1.3.14. The exploitation methodology involves (1) hosting a crafted plugin that executes an arbitr…
Debian Linux
1.3.14+
MEDIUM 6.8
CVE-2015-7984
Multiple cross-site request forgery (CSRF) vulnerabilities in Horde before 5.2.8, Horde Groupware before 5.2.11, and Horde Groupware Webmail Edition …
Debian Linux
5.2.8 / 5.2.11+
MEDIUM 6.8
CVE-2014-5204
wp-includes/pluggable.php in WordPress before 3.9.2 rejects invalid CSRF nonces with a different timing depending on which characters in the nonce ar…
Debian Linux
after 3.9.1
MEDIUM 6.8
CVE-2014-2327
Cross-site request forgery (CSRF) vulnerability in Cacti 0.8.7g, 0.8.8b, and earlier allows remote attackers to hijack the authentication of users fo…
Debian Linux
after 0.8.8b
MEDIUM 6.8
CVE-2011-2522EPSS 10%
Multiple cross-site request forgery (CSRF) vulnerabilities in the Samba Web Administration Tool (SWAT) in Samba 3.x before 3.5.10 allow remote attack…
Debian Linux
3.3.16 / 3.4.14+