Перейти к содержимому
Noroxi

CWE-93 · 222 записей

Improper Neutralization of CRLF Sequences ('CRLF Injection')

CVE этого класса

222 записей

  • CVE-2021-39172
    44В плане

    New line injection during configuration edition

    ВысокаяCVSS 8,8Proof of conceptEPSS 29 %

    catchethq · catchet27 авг. 2021 г.

  • CVE-2022-0666
    43В плане

    CRLF Injection leads to Stack Trace Exposure due to lack of filtering at https://demo.microweber.org/ in microweber/microweber

    ВысокаяCVSS 7,5Proof of conceptEPSS 44 %

    microweber · microweber18 февр. 2022 г.

  • CVE-2024-20337
    41В плане

    A vulnerability in the SAML authentication process of Cisco Secure Client could allow an unauthenticated, remote attacker to conduct a carri

    ВысокаяCVSS 8,2Эксплойта нетEPSS 30 %

    cisco · secure client6 мар. 2024 г.

  • CVE-2026-72590
    40В плане

    alseambusher crontab-ui - Unauthenticated RCE via Newline Injection in env_vars Parameter

    КритическаяCVSS 9,8Эксплойта нетEPSS 2 %

    alseambusher · crontab-ui10 авг. 2026 г.

  • CVE-2026-77550
    40В плане

    A malicious actor with access to the network could exploit an Improper Neutralization of CRLF Sequences vulnerability found in certain devic

    КритическаяCVSS 10,0Эксплойта нетEPSS 1 %

    ubiquiti inc · unifi os server26 авг. 2026 г.

  • CVE-2026-33128
    40В плане

    h3 has a Server-Sent Events Injection via Unsanitized Newlines in Event Stream Fields

    КритическаяCVSS 10,0Эксплойта нетEPSS 1 %

    h3 · h320 мар. 2026 г.

  • CVE-2024-51501
    40В плане

    CRLF injection in Refit's [Header], [HeaderCollection] and [Authorize] attributes

    КритическаяCVSS 10,0Эксплойта нетEPSS 1 %

    reactiveui · refit4 нояб. 2024 г.

  • CVE-2026-84372
    39Наблюдать

    Predis: Redis command injection and denial of service via CRLF smuggling in pipelined commands on aggregate connections

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    predis · predis1 сент. 2026 г.

  • CVE-2026-59313
    39Наблюдать

    Server Sent Event stream corruption in Spring MVC functional web framework

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    vmware · spring framework27 авг. 2026 г.

  • CVE-2026-47890
    39Наблюдать

    Spring Framework Server Sent Event stream corruption while rendering fragments

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    vmware · spring framework27 авг. 2026 г.

  • CVE-2026-50292
    39Наблюдать

    In libinput before 1.30.4 and 1.31.x before 1.31.3, libinput-device-group unescaped phys output can inject udev properties leading to arbitr

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    freedesktop · libinput4 июн. 2026 г.

  • CVE-2026-39394
    39Наблюдать

    CI4MS has an .env CRLF Injection via Unvalidated `host` Parameter in Install Controller

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    ci4-cms-erp · ci4ms8 апр. 2026 г.

  • CVE-2026-11362
    39Наблюдать

    DataDog::DogStatsd versions through 0.07 for Perl allow metric injections from event tags

    КритическаяCVSS 9,8Эксплойта нетEPSS 0 %

    binary · datadog\5 июн. 2026 г.

  • CVE-2026-45372
    39Наблюдать

    cpp-httplib: HTTP header value percent-decoding in server-side `parse_header` enables CRLF injection

    КритическаяCVSS 9,9Эксплойта нетEPSS 0 %

    yhirose · cpp-httplib29 мая 2026 г.

  • CVE-2026-82854
    38Наблюдать

    Nodemailer before 8.0.3 SMTP Command Injection via envelope.size

    КритическаяCVSS 9,3Эксплойта нетEPSS 2 %

    nodemailer · nodemailer31 авг. 2026 г.

  • CVE-2026-75925
    37Наблюдать

    IXON VPN Client CRLF Injection

    КритическаяCVSS 9,4Эксплойта нетEPSS 1 %

    ixon · ixon vpn client4 сент. 2026 г.

  • CVE-2026-90937
    37Наблюдать

    froxlor before 2.2.5 nginx/Apache Configuration Injection via subdomain redirect URL

    КритическаяCVSS 9,4Эксплойта нетEPSS 0 %

    froxlor · froxlor14 сент. 2026 г.

  • CVE-2025-40671
    37Наблюдать

    SQL injection vulnerability in AES Multimedia's Gestnet

    КритическаяCVSS 9,3Эксплойта нетEPSS 0 %

    aes multimedia · gestnet26 мая 2025 г.

  • CVE-2026-34458
    37Наблюдать

    Sandboxie-Plus privilege escalation via INI CRLF injection bypassing EditAdminOnly

    КритическаяCVSS 9,3Эксплойта нетEPSS 0 %

    sandboxie-plus · sandboxie5 мая 2026 г.

  • CVE-2026-82973
    37Наблюдать

    Improper Neutralization of CRLF Sequences ('CRLF Injection') in docker-mailbox

    КритическаяCVSS 9,4Эксплойта нет

    psyb0t · docker-mailboxСегодня

  • CVE-2016-3115
    36Наблюдать

    Multiple CRLF injection vulnerabilities in session.c in sshd in OpenSSH before 7.2p2 allow remote authenticated users to bypass intended she

    СредняяCVSS 6,4Proof of conceptEPSS 37 %

    openbsd · openssh22 мар. 2016 г.

  • CVE-2026-11373
    36Наблюдать

    Net::Statsite::Client versions through 1.1.0 for Perl allow metric injections

    КритическаяCVSS 9,1Эксплойта нетEPSS 1 %

    jasei · net::statsite::client22 июн. 2026 г.

  • CVE-2026-50638
    36Наблюдать

    Metrics::Any::Adapter::DogStatsd versions before 0.04 for Perl does not protect against metric injections

    КритическаяCVSS 9,1Эксплойта нетEPSS 1 %

    pevans · metrics\10 июн. 2026 г.

  • CVE-2026-9270
    36Наблюдать

    DataDog::DogStatsd versions through 0.07 for Perl allow metric injections

    КритическаяCVSS 9,1Эксплойта нетEPSS 1 %

    binary · datadog\5 июн. 2026 г.

  • CVE-2026-77549
    36Наблюдать

    A malicious actor with access to the network and under certain conditions could exploit an Improper Neutralization of CRLF Sequences vulnera

    КритическаяCVSS 9,0Эксплойта нетEPSS 1 %

    ubiquiti inc · unifi os server26 авг. 2026 г.

Все классы уязвимостей