CWE-93 · 222 записей
Improper Neutralization of CRLF Sequences ('CRLF Injection')
CVE этого класса
222 записей
| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
44В плане | CVE-2021-39172Proof of concept | New line injection during configuration editioncatchethq · catchet · CWE-93 | Высокая8,8 | — | 29,2 % | 27 авг. 2021 г. |
43В плане | CVE-2022-0666Proof of concept | CRLF Injection leads to Stack Trace Exposure due to lack of filtering at https://demo.microweber.org/ in microweber/microwebermicroweber · microweber · CWE-93 | Высокая7,5 | — | 44,3 % | 18 февр. 2022 г. |
41В плане | CVE-2024-20337Эксплойта нет | A vulnerability in the SAML authentication process of Cisco Secure Client could allow an unauthenticated, remote attacker to conduct a carricisco · secure client · CWE-93 | Высокая8,2 | — | 29,9 % | 6 мар. 2024 г. |
40В плане | CVE-2026-72590Эксплойта нет | alseambusher crontab-ui - Unauthenticated RCE via Newline Injection in env_vars Parameteralseambusher · crontab-ui · CWE-93 | Критическая9,8 | — | 2,0 % | 10 авг. 2026 г. |
40В плане | CVE-2026-77550Эксплойта нет | A malicious actor with access to the network could exploit an Improper Neutralization of CRLF Sequences vulnerability found in certain devicubiquiti inc · unifi os server · CWE-93 | Критическая10,0 | — | 0,8 % | 26 авг. 2026 г. |
40В плане | CVE-2026-33128Эксплойта нет | h3 has a Server-Sent Events Injection via Unsanitized Newlines in Event Stream Fieldsh3 · h3 · CWE-93 | Критическая10,0 | — | 0,7 % | 20 мар. 2026 г. |
40В плане | CVE-2024-51501Эксплойта нет | CRLF injection in Refit's [Header], [HeaderCollection] and [Authorize] attributesreactiveui · refit · CWE-93 | Критическая10,0 | — | 0,6 % | 4 нояб. 2024 г. |
39Наблюдать | CVE-2026-84372Эксплойта нет | Predis: Redis command injection and denial of service via CRLF smuggling in pipelined commands on aggregate connectionspredis · predis · CWE-93 | Критическая9,8 | — | 0,7 % | 1 сент. 2026 г. |
39Наблюдать | CVE-2026-59313Эксплойта нет | Server Sent Event stream corruption in Spring MVC functional web frameworkvmware · spring framework · CWE-93 | Критическая9,8 | — | 0,6 % | 27 авг. 2026 г. |
39Наблюдать | CVE-2026-47890Эксплойта нет | Spring Framework Server Sent Event stream corruption while rendering fragmentsvmware · spring framework · CWE-93 | Критическая9,8 | — | 0,6 % | 27 авг. 2026 г. |
39Наблюдать | CVE-2026-50292Эксплойта нет | In libinput before 1.30.4 and 1.31.x before 1.31.3, libinput-device-group unescaped phys output can inject udev properties leading to arbitrfreedesktop · libinput · CWE-93 | Критическая9,8 | — | 0,5 % | 4 июн. 2026 г. |
39Наблюдать | CVE-2026-39394Эксплойта нет | CI4MS has an .env CRLF Injection via Unvalidated `host` Parameter in Install Controllerci4-cms-erp · ci4ms · CWE-93 | Критическая9,8 | — | 0,5 % | 8 апр. 2026 г. |
39Наблюдать | CVE-2026-11362Эксплойта нет | DataDog::DogStatsd versions through 0.07 for Perl allow metric injections from event tagsbinary · datadog\ · CWE-93 | Критическая9,8 | — | 0,4 % | 5 июн. 2026 г. |
39Наблюдать | CVE-2026-45372Эксплойта нет | cpp-httplib: HTTP header value percent-decoding in server-side `parse_header` enables CRLF injectionyhirose · cpp-httplib · CWE-93 | Критическая9,9 | — | 0,4 % | 29 мая 2026 г. |
38Наблюдать | CVE-2026-82854Эксплойта нет | Nodemailer before 8.0.3 SMTP Command Injection via envelope.sizenodemailer · nodemailer · CWE-93 | Критическая9,3 | — | 2,0 % | 31 авг. 2026 г. |
37Наблюдать | CVE-2026-75925Эксплойта нет | IXON VPN Client CRLF Injectionixon · ixon vpn client · CWE-93 | Критическая9,4 | — | 0,7 % | 4 сент. 2026 г. |
37Наблюдать | CVE-2026-90937Эксплойта нет | froxlor before 2.2.5 nginx/Apache Configuration Injection via subdomain redirect URLfroxlor · froxlor · CWE-93 | Критическая9,4 | — | 0,5 % | 14 сент. 2026 г. |
37Наблюдать | CVE-2025-40671Эксплойта нет | SQL injection vulnerability in AES Multimedia's Gestnetaes multimedia · gestnet · CWE-93 | Критическая9,3 | — | 0,4 % | 26 мая 2025 г. |
37Наблюдать | CVE-2026-34458Эксплойта нет | Sandboxie-Plus privilege escalation via INI CRLF injection bypassing EditAdminOnlysandboxie-plus · sandboxie · CWE-93 | Критическая9,3 | — | 0,3 % | 5 мая 2026 г. |
37Наблюдать | CVE-2026-82973Эксплойта нет | Improper Neutralization of CRLF Sequences ('CRLF Injection') in docker-mailboxpsyb0t · docker-mailbox · CWE-93 | Критическая9,4 | — | — | Сегодня |
36Наблюдать | CVE-2016-3115Proof of concept | Multiple CRLF injection vulnerabilities in session.c in sshd in OpenSSH before 7.2p2 allow remote authenticated users to bypass intended sheopenbsd · openssh · CWE-93 | Средняя6,4 | — | 37,0 % | 22 мар. 2016 г. |
36Наблюдать | CVE-2026-11373Эксплойта нет | Net::Statsite::Client versions through 1.1.0 for Perl allow metric injectionsjasei · net::statsite::client · CWE-93 | Критическая9,1 | — | 0,6 % | 22 июн. 2026 г. |
36Наблюдать | CVE-2026-50638Эксплойта нет | Metrics::Any::Adapter::DogStatsd versions before 0.04 for Perl does not protect against metric injectionspevans · metrics\ · CWE-93 | Критическая9,1 | — | 0,6 % | 10 июн. 2026 г. |
36Наблюдать | CVE-2026-9270Эксплойта нет | DataDog::DogStatsd versions through 0.07 for Perl allow metric injectionsbinary · datadog\ · CWE-93 | Критическая9,1 | — | 0,5 % | 5 июн. 2026 г. |
36Наблюдать | CVE-2026-77549Эксплойта нет | A malicious actor with access to the network and under certain conditions could exploit an Improper Neutralization of CRLF Sequences vulneraubiquiti inc · unifi os server · CWE-93 | Критическая9,0 | — | 0,5 % | 26 авг. 2026 г. |
- CVE-2021-3917244В плане
New line injection during configuration edition
ВысокаяCVSS 8,8Proof of conceptEPSS 29 %catchethq · catchet27 авг. 2021 г.
- CVE-2022-066643В плане
CRLF Injection leads to Stack Trace Exposure due to lack of filtering at https://demo.microweber.org/ in microweber/microweber
ВысокаяCVSS 7,5Proof of conceptEPSS 44 %microweber · microweber18 февр. 2022 г.
- CVE-2024-2033741В плане
A vulnerability in the SAML authentication process of Cisco Secure Client could allow an unauthenticated, remote attacker to conduct a carri
ВысокаяCVSS 8,2Эксплойта нетEPSS 30 %cisco · secure client6 мар. 2024 г.
- CVE-2026-7259040В плане
alseambusher crontab-ui - Unauthenticated RCE via Newline Injection in env_vars Parameter
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %alseambusher · crontab-ui10 авг. 2026 г.
- CVE-2026-7755040В плане
A malicious actor with access to the network could exploit an Improper Neutralization of CRLF Sequences vulnerability found in certain devic
КритическаяCVSS 10,0Эксплойта нетEPSS 1 %ubiquiti inc · unifi os server26 авг. 2026 г.
- CVE-2026-3312840В плане
h3 has a Server-Sent Events Injection via Unsanitized Newlines in Event Stream Fields
КритическаяCVSS 10,0Эксплойта нетEPSS 1 %h3 · h320 мар. 2026 г.
- CVE-2024-5150140В плане
CRLF injection in Refit's [Header], [HeaderCollection] and [Authorize] attributes
КритическаяCVSS 10,0Эксплойта нетEPSS 1 %reactiveui · refit4 нояб. 2024 г.
- CVE-2026-8437239Наблюдать
Predis: Redis command injection and denial of service via CRLF smuggling in pipelined commands on aggregate connections
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %predis · predis1 сент. 2026 г.
- CVE-2026-5931339Наблюдать
Server Sent Event stream corruption in Spring MVC functional web framework
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %vmware · spring framework27 авг. 2026 г.
- CVE-2026-4789039Наблюдать
Spring Framework Server Sent Event stream corruption while rendering fragments
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %vmware · spring framework27 авг. 2026 г.
- CVE-2026-5029239Наблюдать
In libinput before 1.30.4 and 1.31.x before 1.31.3, libinput-device-group unescaped phys output can inject udev properties leading to arbitr
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %freedesktop · libinput4 июн. 2026 г.
- CVE-2026-3939439Наблюдать
CI4MS has an .env CRLF Injection via Unvalidated `host` Parameter in Install Controller
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %ci4-cms-erp · ci4ms8 апр. 2026 г.
- CVE-2026-1136239Наблюдать
DataDog::DogStatsd versions through 0.07 for Perl allow metric injections from event tags
КритическаяCVSS 9,8Эксплойта нетEPSS 0 %binary · datadog\5 июн. 2026 г.
- CVE-2026-4537239Наблюдать
cpp-httplib: HTTP header value percent-decoding in server-side `parse_header` enables CRLF injection
КритическаяCVSS 9,9Эксплойта нетEPSS 0 %yhirose · cpp-httplib29 мая 2026 г.
- CVE-2026-8285438Наблюдать
Nodemailer before 8.0.3 SMTP Command Injection via envelope.size
КритическаяCVSS 9,3Эксплойта нетEPSS 2 %nodemailer · nodemailer31 авг. 2026 г.
- CVE-2026-7592537Наблюдать
IXON VPN Client CRLF Injection
КритическаяCVSS 9,4Эксплойта нетEPSS 1 %ixon · ixon vpn client4 сент. 2026 г.
- CVE-2026-9093737Наблюдать
froxlor before 2.2.5 nginx/Apache Configuration Injection via subdomain redirect URL
КритическаяCVSS 9,4Эксплойта нетEPSS 0 %froxlor · froxlor14 сент. 2026 г.
- CVE-2025-4067137Наблюдать
SQL injection vulnerability in AES Multimedia's Gestnet
КритическаяCVSS 9,3Эксплойта нетEPSS 0 %aes multimedia · gestnet26 мая 2025 г.
- CVE-2026-3445837Наблюдать
Sandboxie-Plus privilege escalation via INI CRLF injection bypassing EditAdminOnly
КритическаяCVSS 9,3Эксплойта нетEPSS 0 %sandboxie-plus · sandboxie5 мая 2026 г.
- CVE-2026-8297337Наблюдать
Improper Neutralization of CRLF Sequences ('CRLF Injection') in docker-mailbox
КритическаяCVSS 9,4Эксплойта нетpsyb0t · docker-mailboxСегодня
- CVE-2016-311536Наблюдать
Multiple CRLF injection vulnerabilities in session.c in sshd in OpenSSH before 7.2p2 allow remote authenticated users to bypass intended she
СредняяCVSS 6,4Proof of conceptEPSS 37 %openbsd · openssh22 мар. 2016 г.
- CVE-2026-1137336Наблюдать
Net::Statsite::Client versions through 1.1.0 for Perl allow metric injections
КритическаяCVSS 9,1Эксплойта нетEPSS 1 %jasei · net::statsite::client22 июн. 2026 г.
- CVE-2026-5063836Наблюдать
Metrics::Any::Adapter::DogStatsd versions before 0.04 for Perl does not protect against metric injections
КритическаяCVSS 9,1Эксплойта нетEPSS 1 %pevans · metrics\10 июн. 2026 г.
- CVE-2026-927036Наблюдать
DataDog::DogStatsd versions through 0.07 for Perl allow metric injections
КритическаяCVSS 9,1Эксплойта нетEPSS 1 %binary · datadog\5 июн. 2026 г.
- CVE-2026-7754936Наблюдать
A malicious actor with access to the network and under certain conditions could exploit an Improper Neutralization of CRLF Sequences vulnera
КритическаяCVSS 9,0Эксплойта нетEPSS 1 %ubiquiti inc · unifi os server26 авг. 2026 г.