Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2635▼ 212 respecto a la semana anterior
Críticas / altas1376▲ 147 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)81▼ 449 respecto a la semana anterior
12 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.3) | 0.17% | — | Golang GOAIGo-macaron CsrfAI | 29/8/2025 | 17/6/2026 | Hosts listed in TrustedOrigins implicitly allow requests from the corresponding HTTP origins, allowing network MitMs to perform CSRF attacks. After the CVE-2025-24358 fix, a network attacker that places a form at http://example.com can't get it to submit to https://example.com because the Origin header is checked with… | |
| Aplazada | Alta (7) | 0.28% | — | Mojolicious Plugin CsrfAI | 11/6/2025 | 17/6/2026 | Mojolicious::Plugin::CSRF 1.03 for Perl uses a weak random number source for generating CSRF tokens. That version of the module generates tokens as an MD5 of the process id, the current time, and a single call to the built-in rand() function. | |
| Aplazada | Media (5.4) | 0.37% | — | Go-macaron CsrfAI | 15/4/2025 | 17/6/2026 | gorilla/csrf provides Cross Site Request Forgery (CSRF) prevention middleware for Go web applications & services. Prior to 1.7.2, gorilla/csrf does not validate the Origin header against an allowlist. Its executes its validation of the Referer header for cross-origin requests only when it believes the request is being… | |
| Modificada | Media (6.5) | 0.33% | — | Fastify Csrf-protection | 20/4/2023 | 17/6/2026 | @fastify/csrf-protection is a plugin which helps protect Fastify servers against CSRF attacks. The CSRF protection enforced by the @fastify/csrf-protection library in combination with @fastify/cookie can be bypassed from network and same-site attackers under certain conditions. @fastify/csrf-protection supports an… | |
| Modificada | Alta (7.5) | 0.52% | — | Go-macaron Csrf | 30/12/2022 | 17/6/2026 | A vulnerability was found in Macaron csrf and classified as problematic. Affected by this issue is some unknown functionality of the file csrf.go. The manipulation of the argument Generate leads to sensitive cookie without secure attribute. The attack may be launched remotely. The complexity of an attack is rather… | |
| Modificada | Media (6.5) | 0.44% | — | Tiny-csrf Project Tiny-csrf | 7/10/2022 | 17/6/2026 | tiny-csrf is a Node.js cross site request forgery (CSRF) protection middleware. In versions prior to 1.1.0 cookies were not encrypted and thus CSRF tokens were transmitted in the clear. This issue has been addressed in commit `8eead6d` and the patch with be included in version 1.1.0. Users are advised to upgrade.… | |
| Modificada | Alta (8.8) | 0.50% | — | Owasp Csrfguard | 19/8/2021 | 17/6/2026 | In OWASP CSRFGuard through 3.1.0, CSRF can occur because the CSRF cookie may be retrieved by using only a session token. | |
| Modificada | Media (6.5) | 0.83% | — | Fastify-csrf | 19/5/2021 | 17/6/2026 | fastify-csrf is an open-source plugin helps developers protect their Fastify server against CSRF attacks. Versions of fastify-csrf prior to 3.1.0 have a "double submit" mechanism using cookies with an application deployed across multiple subdomains, e.g. "heroku"-style platform as a service. Version 3.1.0 of the… | |
| Modificada | Alta (8.8) | 0.98% | — | Fastify-csrf | 19/1/2021 | 17/6/2026 | This affects the package fastify-csrf before 3.0.0. 1. The generated cookie used insecure defaults, and did not have the httpOnly flag on: cookieOpts: { path: '/', sameSite: true } 2. The CSRF token was available in the GET query parameter | |
| Modificada | Alta (8.8) | 0.62% | — | Csrf Magic Project Csrf Magic | 26/11/2019 | 17/6/2026 | The csrf_callback function in the CSRF Magic library through 2016-03-27 is vulnerable to CSRF protection bypass as it allows one to tamper with the csrf token values. A remote attacker can exploit this by crafting a malicious page and dispersing it to a victim via social engineering, enticing them to click the link.… | |
| Modificada | Alta (8.8) | 0.79% | — | Csrf-magic Project Csrf-magic | 8/8/2018 | 17/6/2026 | In csrf-magic before 1.0.4, if $GLOBALS['csrf']['secret'] is not configured, the Anti-CSRF Token used is predictable and would permit an attacker to bypass the CSRF protections, because an automatically generated secret is not used. | |
| Modificada | Media (5.9) | 1.3% | — | Csrf-lite Project Csrf-lite | 31/5/2018 | 17/6/2026 | csrf-lite is a cross-site request forgery protection library for framework-less node sites. csrf-lite uses `===`, a fail first string comparison, instead of a time constant string comparison This enables an attacker to guess the secret in no more than (16*18)288 guesses, instead of the 16^18 guesses required were the… |