Vulnerability index

Browse CVEs

18 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
HIGH 7.5 CVE-2024-34069 Werkzeug is a comprehensive WSGI web application library. The debugger in affected versions of Werkzeug can allow an attacker to execute code on a de… Debian Linux 3.0.3+ Fix from $1,9502024-05-06 HIGH 8.8 CVE-2021-44227 In GNU Mailman before 2.1.38, a list member or moderator can get a CSRF token and craft an admin request (using that token) to set a new admin passwo… Debian Linux 2.1.38+ Fix from $1,9502021-12-02 HIGH 8.0 CVE-2021-42097 GNU Mailman before 2.1.35 may allow remote Privilege Escalation. A csrf_token value is not specific to a single user account. An attacker can obtain … Debian Linux 2.1.35+ Fix from $1,9502021-10-21 MEDIUM 6.5 CVE-2020-12626 An issue was discovered in Roundcube Webmail before 1.4.4. A CSRF attack can cause an authenticated user to be logged out because POST was not consid… Debian Linux 1.4.4+ Fix from $1,6002020-05-04 MEDIUM 6.5 CVE-2012-4385 letodms 3.3.6 has CSRF via change password Debian Linux No fix yet Fix from $1,6002019-11-13 MEDIUM 6.5 CVE-2013-6275 Multiple CSRF issues in Horde Groupware Webmail Edition 5.1.2 and earlier in basic.php. Debian Linux after 5.1.2 Fix from $1,6002019-11-05 HIGH 8.8 CVE-2013-6364 Horde Groupware Webmail Edition has CSRF and XSS when saving search as a virtual address book Debian Linux No fix yet Fix from $1,9502019-11-05 MEDIUM 5.3 CVE-2013-6365 Horde Groupware Web mail 5.1.2 has CSRF with requests to change permissions Debian Linux Patch available Fix from $1,6002019-11-05 HIGH 8.8 CVE-2019-16993 In phpBB before 3.1.7-PL1, includes/acp/acp_bbcodes.php has improper verification of a CSRF token on the BBCode page in the Administration Control Pa… Debian Linux after 3.1.7 Fix from $1,9502019-09-30 HIGH 8.8 CVE-2019-12466 Wikimedia MediaWiki through 1.32.1 allows CSRF. Debian Linux after 1.32.1 Fix from $1,9502019-07-10 HIGH 8.8 CVE-2017-0362 Mediawiki before 1.28.1 / 1.27.2 / 1.23.16 contains a flaw where the "Mark all pages visited" on the watchlist does not require a CSRF token. Debian Linux 1.27.2 / 1.28.1+ Fix from $1,9502018-04-13 HIGH 8.8 CVE-2018-8764 Roland Gruber Softwareentwicklung LDAP Account Manager before 6.3 places a CSRF token in the sec_token parameter of a URI, which makes it easier for … Debian Linux 6.3+ Fix from $1,9502018-03-27 HIGH 8.8 CVE-2015-5395 Cross-site request forgery (CSRF) vulnerability in SOGo before 3.1.0. Debian Linux 3.1.0+ Fix from $1,9502017-09-20 HIGH 8.8 CVE-2017-7178 CSRF was discovered in the web UI in Deluge before 1.3.14. The exploitation methodology involves (1) hosting a crafted plugin that executes an arbitr… Debian Linux 1.3.14+ Fix from $1,9502017-03-18 MEDIUM 6.8 CVE-2015-7984 Multiple cross-site request forgery (CSRF) vulnerabilities in Horde before 5.2.8, Horde Groupware before 5.2.11, and Horde Groupware Webmail Edition … Debian Linux 5.2.8 / 5.2.11+ Fix from $1,6002015-11-19 MEDIUM 6.8 CVE-2014-5204 wp-includes/pluggable.php in WordPress before 3.9.2 rejects invalid CSRF nonces with a different timing depending on which characters in the nonce ar… Debian Linux after 3.9.1 Fix from $1,6002014-08-18 MEDIUM 6.8 CVE-2014-2327 Cross-site request forgery (CSRF) vulnerability in Cacti 0.8.7g, 0.8.8b, and earlier allows remote attackers to hijack the authentication of users fo… Debian Linux after 0.8.8b Fix from $1,6002014-04-23 MEDIUM 6.8 CVE-2011-2522EPSS 10% Multiple cross-site request forgery (CSRF) vulnerabilities in the Samba Web Administration Tool (SWAT) in Samba 3.x before 3.5.10 allow remote attack… Debian Linux 3.3.16 / 3.4.14+ Fix from $1,6002011-07-29