Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
By Recent Activity
csrf vulnerabilities and exploits
(subscribe to this query)
6.8
CVSSv2
CVE-2019-10384
Jenkins 2.191 and earlier, LTS 2.176.2 and earlier allowed users to obtain CSRF tokens without an associated web session ID, resulting in CSRF tokens that did not expire and could be used to bypass CSRF protection for the anonymous user....
Jenkins Jenkins
Oracle Communications Cloud Native Core Automated Test Suite 1.9.0
Redhat Openshift Container Platform 3.11
Redhat Openshift Container Platform 4.1
6.8
CVSSv2
CVE-2015-5318
Jenkins before 1.638 and LTS before 1.625.2 uses a publicly accessible salt to generate CSRF protection tokens, which makes it easier for remote attackers to bypass the CSRF protection mechanism via a brute force attack....
Jenkins Jenkins
Redhat Openshift
Redhat Openshift 2.0
6.8
CVSSv2
CVE-2015-5351
The (1) Manager and (2) Host Manager applications in Apache Tomcat 7.x before 7.0.68, 8.x before 8.0.31, and 9.x before 9.0.0.M2 establish sessions and send CSRF tokens for arbitrary new requests, which allows remote attackers to bypass a CSRF protection mechanism by using a...
Apache Tomcat 7.0.2
Apache Tomcat 8.0.30
Apache Tomcat 7.0.12
Apache Tomcat 7.0.62
Apache Tomcat 8.0.17
Apache Tomcat 7.0.53
Apache Tomcat 7.0.20
Apache Tomcat 7.0.34
Apache Tomcat 8.0.26
Apache Tomcat 7.0.55
Apache Tomcat 7.0.4
Apache Tomcat 7.0.63
Apache Tomcat 8.0.20
Apache Tomcat 7.0.22
Apache Tomcat 7.0.39
Apache Tomcat 7.0.26
Apache Tomcat 9.0.0
Apache Tomcat 7.0.28
Apache Tomcat 8.0.1
Apache Tomcat 8.0.0
Apache Tomcat 7.0.59
Apache Tomcat 7.0.65
Apache Tomcat 7.0.50
Apache Tomcat 7.0.6
Apache Tomcat 8.0.12
Apache Tomcat 7.0.14
Apache Tomcat 8.0.27
Apache Tomcat 8.0.15
Apache Tomcat 7.0.11
Apache Tomcat 7.0.67
Apache Tomcat 7.0.23
Apache Tomcat 7.0.0
Apache Tomcat 8.0.22
Apache Tomcat 8.0.29
Apache Tomcat 7.0.52
Apache Tomcat 7.0.42
Apache Tomcat 7.0.37
Apache Tomcat 7.0.29
Apache Tomcat 8.0.11
Apache Tomcat 8.0.24
Apache Tomcat 8.0.23
Apache Tomcat 7.0.47
Apache Tomcat 7.0.5
Apache Tomcat 8.0.21
Apache Tomcat 7.0.41
Apache Tomcat 7.0.30
Apache Tomcat 7.0.19
Apache Tomcat 7.0.16
Apache Tomcat 7.0.10
Apache Tomcat 8.0.18
Apache Tomcat 7.0.25
Apache Tomcat 7.0.54
Apache Tomcat 7.0.35
Apache Tomcat 7.0.61
Apache Tomcat 8.0.3
Apache Tomcat 7.0.57
Apache Tomcat 8.0.14
Apache Tomcat 7.0.32
Apache Tomcat 7.0.21
Apache Tomcat 7.0.27
Apache Tomcat 7.0.40
Apache Tomcat 7.0.56
Apache Tomcat 8.0.28
Apache Tomcat 7.0.64
Apache Tomcat 7.0.33
Debian Debian Linux 8.0
Debian Debian Linux 7.0
Canonical Ubuntu Linux 12.04
Canonical Ubuntu Linux 16.04
Canonical Ubuntu Linux 15.10
Canonical Ubuntu Linux 14.04
6.8
CVSSv2
CVE-2017-5489
Cross-site request forgery (CSRF) vulnerability in WordPress before 4.7.1 allows remote attackers to hijack the authentication of unspecified victims via vectors involving a Flash file upload....
Wordpress Wordpress
8.5
CVSSv2
CVE-2021-42097
GNU Mailman before 2.1.35 may allow remote Privilege Escalation. A csrf_token value is not specific to a single user account. An attacker can obtain a value within the context of an unprivileged user account, and then use that value in a CSRF attack against an admin (e.g., for...
Gnu Mailman
Debian Debian Linux 10.0
5
CVSSv2
CVE-2015-1840
jquery_ujs.js in jquery-rails before 3.1.3 and 4.x before 4.0.4 and rails.js in jquery-ujs before 1.0.4, as used with Ruby on Rails 3.x and 4.x, allow remote attackers to bypass the Same Origin Policy, and trigger transmission of a CSRF token to a different-domain web server,...
Fedoraproject Fedora 22
Fedoraproject Fedora 21
Rubyonrails Jquery-rails 4.0.0
Rubyonrails Jquery-rails
Rubyonrails Jquery-rails 4.0.1
Rubyonrails Jquery-ujs
Opensuse Opensuse 13.2
Opensuse Opensuse 13.1
1 Github repository available
5
CVSSv2
CVE-2014-0473
The caching framework in Django before 1.4.11, 1.5.x before 1.5.6, 1.6.x before 1.6.3, and 1.7.x before 1.7 beta 2 reuses a cached CSRF token for all anonymous users, which allows remote attackers to bypass CSRF protections by reading the CSRF cookie for anonymous users....
Djangoproject Django 1.5.5
Djangoproject Django 1.5.4
Djangoproject Django 1.5.1
Djangoproject Django 1.5
Djangoproject Django 1.5.3
Djangoproject Django 1.5.2
Djangoproject Django 1.6.1
Djangoproject Django 1.6
Djangoproject Django 1.6.2
Djangoproject Django 1.7
Djangoproject Django
Djangoproject Django 1.4.9
Djangoproject Django 1.4.7
Djangoproject Django 1.4.8
Djangoproject Django 1.4.2
Djangoproject Django 1.4.4
Djangoproject Django 1.4.3
Djangoproject Django 1.4.5
Djangoproject Django 1.4.6
Djangoproject Django 1.4
Djangoproject Django 1.4.1
Canonical Ubuntu Linux 12.04
Canonical Ubuntu Linux 12.10
Canonical Ubuntu Linux 13.10
Canonical Ubuntu Linux 10.04
Canonical Ubuntu Linux 14.04
6.8
CVSSv2
CVE-2017-0362
Mediawiki before 1.28.1 / 1.27.2 / 1.23.16 contains a flaw where the "Mark all pages visited" on the watchlist does not require a CSRF token....
Mediawiki Mediawiki
Debian Debian Linux 7.0
5.8
CVSSv2
CVE-2019-10176
A flaw was found in OpenShift Container Platform, versions 3.11 and later, in which the CSRF tokens used in the cluster console component were found to remain static during a user's session. An attacker with the ability to observe the value of this token would be able to...
Redhat Openshift Container Platform 3.11
Redhat Openshift Container Platform 4.1
4.3
CVSSv2
CVE-2020-28040
WordPress before 5.5.2 allows CSRF attacks that change a theme's background image....
Wordpress Wordpress
Debian Debian Linux 9.0
Debian Debian Linux 10.0
Canonical Ubuntu Linux 18.04
Canonical Ubuntu Linux 20.04
Canonical Ubuntu Linux 16.04
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
XSS
CVE-2023-48314
CVE-2023-6376
CVE-2023-46384
arbitrary code
CVE-2023-42917
CVE-2023-48842
CVE-2023-42916
firewall
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
6
7
NEXT »