Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
By Recent Activity
csrf vulnerabilities and exploits
(subscribe to this query)
6.8
CVSSv2
CVE-2020-35217
Vert.x-Web framework v4.0 milestone 1-4 does not perform a correct CSRF verification. Instead of comparing the CSRF token in the request with the CSRF token in the cookie, it compares the CSRF token in the cookie against a CSRF token that is stored in the session. An attacker...
Eclipse Vert.x-web 4.0.0
4.3
CVSSv2
CVE-2022-20613
A cross-site request forgery (CSRF) vulnerability in Jenkins Mailer Plugin 391.ve4a_38c1b_cf4b_ and earlier allows attackers to use the DNS used by the Jenkins instance to resolve an attacker-specified hostname....
Jenkins Mailer 391.ve4a 38c1b Cf4b
Jenkins Mailer
Oracle Communications Cloud Native Core Automated Test Suite 1.9.0
2 Github repositories available
NA
CVE-2023-4959
A flaw was found in Quay. Cross-site request forgery (CSRF) attacks force a user to perform unwanted actions in an application. During the pentest, it was detected that the config-editor page is vulnerable to CSRF. The config-editor page is used to configure the Quay instance....
Redhat Quay 3.0.0
5
CVSSv2
CVE-2016-7401
The cookie parsing code in Django before 1.8.15 and 1.9.x before 1.9.10, when used on a site with Google Analytics, allows remote attackers to bypass an intended CSRF protection mechanism by setting arbitrary cookies....
Canonical Ubuntu Linux 16.04
Canonical Ubuntu Linux 14.04
Canonical Ubuntu Linux 12.04
Djangoproject Django 1.9.6
Djangoproject Django 1.9.5
Djangoproject Django 1.9.4
Djangoproject Django 1.9.3
Djangoproject Django 1.9.2
Djangoproject Django 1.9.9
Djangoproject Django 1.9.1
Djangoproject Django 1.9.0
Djangoproject Django 1.9.8
Djangoproject Django 1.9.7
Djangoproject Django
Debian Debian Linux 8.0
2 Github repositories available
6.8
CVSSv2
CVE-2021-40662
A Cross-Site Request Forgery (CSRF) in Chamilo LMS 1.11.14 allows attackers to execute arbitrary commands on victim hosts via user interaction with a crafted URL....
Chamilo Chamilo 1.11.14
1 Github repository available
5.1
CVSSv2
CVE-2021-26103
An insufficient verification of data authenticity vulnerability (CWE-345) in the user interface of FortiProxy verison 2.0.3 and below, 1.2.11 and below and FortiGate verison 7.0.0, 6.4.6 and below, 6.2.9 and below of SSL VPN portal may allow a remote, unauthenticated attacker to...
Fortinet Fortiproxy
Fortinet Fortios
Fortinet Fortios 7.0.0
4.3
CVSSv2
CVE-2020-8167
A CSRF vulnerability exists in rails <= 6.0.3 rails-ujs module that could allow attackers to send CSRF tokens to wrong domains....
Rubyonrails Rails
Debian Debian Linux 10.0
6.8
CVSSv2
CVE-2018-14057
Pimcore before 5.3.0 allows remote attackers to conduct cross-site request forgery (CSRF) attacks by leveraging validation of the X-pimcore-csrf-token anti-CSRF token only in the "Settings > Users / Roles" function....
Pimcore Pimcore
1 EDB exploit available
4.3
CVSSv2
CVE-2014-3655
JBoss KeyCloak is vulnerable to soft token deletion via CSRF...
Redhat Keycloak
Redhat Jboss Enterprise Web Server 1.0.0
NA
CVE-2023-48017
Dreamer_cms 4.1.3 is vulnerable to Cross Site Request Forgery (CSRF) via Add permissions to CSRF in Permission Management....
Dreamer Cms Project Dreamer Cms 4.1.3
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
XSS
CVE-2023-48314
CVE-2023-6376
CVE-2023-46384
arbitrary code
CVE-2023-42917
CVE-2023-48842
CVE-2023-42916
firewall
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
6
7
8
9
NEXT »