CWE-644 · 58 records
Improper Neutralization of HTTP Headers for Scripting Syntax
CVEs in this class
58 records
| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
39Monitor | CVE-2023-47143No exploit | IBM Tivoli Application Dependency Discovery Manager HOST header injectionibm · tivoli application dependency discovery manager · CWE-644 | Critical9.8 | — | 0.8% | Feb 2, 2024 |
39Monitor | CVE-2024-39736No exploit | IBM Datacap Navigator HTTP HOST header injectionibm · datacap · CWE-644 | Critical9.8 | — | 0.4% | Jul 14, 2024 |
39Monitor | CVE-2025-52660No exploit | HCL AION is affected by an Host Header Injection vulnerabilityhcltech · aion · CWE-644 | Critical9.8 | — | 0.3% | Jan 19, 2026 |
37Monitor | CVE-2025-70948No exploit | A host header injection vulnerability in the mailer component of @perfood/couch-auth v0.26.0 allows attackers to obtain reset tokens and exeCWE-644 | Critical9.3 | — | 0.4% | Mar 5, 2026 |
36Monitor | CVE-2017-6031No exploit | A Header Injection issue was discovered in Certec EDV GmbH atvise scada prior to Version 3.0.certec edv gmbh · atvise scada · CWE-644 | High8.8 | — | 2.8% | May 5, 2017 |
36Monitor | CVE-2026-26747No exploit | A Host Header Poisoning vulnerability exists in Monica 4.1.2 due to improper handling of the HTTP Host header in app/Providers/AppServicePromonicahq · monica · CWE-644 | Critical9.1 | — | 0.6% | Feb 20, 2026 |
36Monitor | CVE-2026-33805No exploit | @fastify/reply-from vulnerable to connection header abuse enabling stripping of proxy-added headersfastify · fastify\/http-proxy · CWE-644 | Critical9.0 | — | 0.6% | Apr 15, 2026 |
35Monitor | CVE-2020-6982No exploit | In Honeywell WIN-PAK 4.7.2, Web and prior versions, the header injection vulnerability has been identified, which may allow remote code exechoneywell · win-pak · CWE-644 | High8.8 | — | 1.1% | Mar 24, 2020 |
35Monitor | CVE-2023-32465No exploit | Dell Power Protect Cyber Recovery, contains an Authentication Bypass vulnerability.dell · powerprotect cyber recovery · CWE-644 | High8.8 | — | 0.7% | Jun 14, 2023 |
34Monitor | CVE-2025-64484No exploit | OAuth2-Proxy vulnerable to header smuggling via underscore, leading to potential privilege escalationoauth2-proxy · oauth2-proxy · CWE-644 | High8.5 | — | 0.6% | Nov 10, 2025 |
34Monitor | CVE-2026-26234No exploit | JUNG Smart Visu Server - Improper Neutralization of HTTP Headers for Scripting Syntaxjung-group · smart visu server firmware · CWE-644 | High8.7 | — | 0.5% | Feb 12, 2026 |
34Monitor | CVE-2025-64425No exploit | Coolify has host header injection in forgot passwordcoollabs · coolify · CWE-644 | High8.5 | — | 0.4% | Jan 5, 2026 |
32Monitor | CVE-2026-33149Proof of concept | Tandoor Recipes Vulnerable to Host Header Injectiontandoor · recipes · CWE-644 | High8.1 | — | 0.4% | Mar 26, 2026 |
31Monitor | CVE-2021-21265No exploit | October CMS vulnerable to Potential Host Header Poisoning on misconfigured serversoctobercms · october · CWE-644 | High7.5 | — | 1.7% | Mar 10, 2021 |
31Monitor | CVE-2026-67179No exploit | Genkit improper host header validationgenkit-ai · genkit · CWE-644 | High7.8 | — | 0.2% | Aug 11, 2026 |
30Monitor | CVE-2024-1064No exploit | Improper Neutralization of HTTP Headers for Scripting Syntax in Crafty Controller 4craftycontrol · crafty controller · CWE-644 | High7.5 | — | 0.8% | Feb 3, 2024 |
30Monitor | CVE-2025-0154No exploit | IBM TXSeries for Multiplatforms information disclosureibm · txseries for multiplatforms · CWE-644 | High7.5 | — | 0.4% | Apr 2, 2025 |
28Monitor | CVE-2023-36921No exploit | Header Injection in SAP Solution Manager (Diagnostic Agent)sap · solution manager · CWE-644 | High7.2 | — | 0.7% | Jul 10, 2023 |
27Monitor | CVE-2025-13803No exploit | MediaCrush Header paths.py http headers for scripting syntaxCWE-644 | Medium6.9 | — | 0.3% | Nov 30, 2025 |
26Monitor | CVE-2022-22399No exploit | IBM Aspera Faspex HTTP header injectionibm · aspera faspex · CWE-644 | Medium6.5 | — | 0.4% | Mar 5, 2024 |
26Monitor | CVE-2026-0516No exploit | A improper neutralization of HTTP Headers for Scripting Syntax vulnerability in SonicOS could allow a remote attacker to manipulate the Hostsonicwall · sonicos · CWE-644 | Medium6.5 | — | 0.3% | Aug 5, 2026 |
26Monitor | CVE-2024-51451No exploit | Multiple Vulnerabilities in IBM Concert Softwareibm · concert · CWE-644 | Medium6.5 | — | 0.2% | Feb 4, 2026 |
26Monitor | CVE-2025-14807No exploit | IBM InfoSphere Information Server is vulnerable to HTTP header injectionibm · infosphere information server · CWE-644 | Medium6.5 | — | 0.2% | Mar 25, 2026 |
26Monitor | CVE-2025-27901No exploit | Multiple vulnerabilities in IBM Java SDK affecting Db2 Recovery Expert for Linux, Unix and Windowsibm · db2 recovery expert · CWE-644 | Medium6.5 | — | 0.2% | Feb 17, 2026 |
24Monitor | CVE-2021-20784No exploit | HTTP header injection vulnerability in Everything version 1.0, 1.1, and 1.2 except the Lite version may allow a remote attacker to inject anvoidtools · everything · CWE-644 | Medium6.1 | — | 1.1% | Jul 13, 2021 |
- CVE-2023-4714339Monitor
IBM Tivoli Application Dependency Discovery Manager HOST header injection
CriticalCVSS 9.8No exploitEPSS 1%ibm · tivoli application dependency discovery managerFeb 2, 2024
- CVE-2024-3973639Monitor
IBM Datacap Navigator HTTP HOST header injection
CriticalCVSS 9.8No exploitEPSS 0%ibm · datacapJul 14, 2024
- CVE-2025-5266039Monitor
HCL AION is affected by an Host Header Injection vulnerability
CriticalCVSS 9.8No exploitEPSS 0%hcltech · aionJan 19, 2026
- CVE-2025-7094837Monitor
A host header injection vulnerability in the mailer component of @perfood/couch-auth v0.26.0 allows attackers to obtain reset tokens and exe
CriticalCVSS 9.3No exploitEPSS 0%Mar 5, 2026
- CVE-2017-603136Monitor
A Header Injection issue was discovered in Certec EDV GmbH atvise scada prior to Version 3.0.
HighCVSS 8.8No exploitEPSS 3%certec edv gmbh · atvise scadaMay 5, 2017
- CVE-2026-2674736Monitor
A Host Header Poisoning vulnerability exists in Monica 4.1.2 due to improper handling of the HTTP Host header in app/Providers/AppServicePro
CriticalCVSS 9.1No exploitEPSS 1%monicahq · monicaFeb 20, 2026
- CVE-2026-3380536Monitor
@fastify/reply-from vulnerable to connection header abuse enabling stripping of proxy-added headers
CriticalCVSS 9.0No exploitEPSS 1%fastify · fastify\/http-proxyApr 15, 2026
- CVE-2020-698235Monitor
In Honeywell WIN-PAK 4.7.2, Web and prior versions, the header injection vulnerability has been identified, which may allow remote code exec
HighCVSS 8.8No exploitEPSS 1%honeywell · win-pakMar 24, 2020
- CVE-2023-3246535Monitor
Dell Power Protect Cyber Recovery, contains an Authentication Bypass vulnerability.
HighCVSS 8.8No exploitEPSS 1%dell · powerprotect cyber recoveryJun 14, 2023
- CVE-2025-6448434Monitor
OAuth2-Proxy vulnerable to header smuggling via underscore, leading to potential privilege escalation
HighCVSS 8.5No exploitEPSS 1%oauth2-proxy · oauth2-proxyNov 10, 2025
- CVE-2026-2623434Monitor
JUNG Smart Visu Server - Improper Neutralization of HTTP Headers for Scripting Syntax
HighCVSS 8.7No exploitEPSS 1%jung-group · smart visu server firmwareFeb 12, 2026
- CVE-2025-6442534Monitor
Coolify has host header injection in forgot password
HighCVSS 8.5No exploitEPSS 0%coollabs · coolifyJan 5, 2026
- CVE-2026-3314932Monitor
Tandoor Recipes Vulnerable to Host Header Injection
HighCVSS 8.1Proof of conceptEPSS 0%tandoor · recipesMar 26, 2026
- CVE-2021-2126531Monitor
October CMS vulnerable to Potential Host Header Poisoning on misconfigured servers
HighCVSS 7.5No exploitEPSS 2%octobercms · octoberMar 10, 2021
- CVE-2026-6717931Monitor
Genkit improper host header validation
HighCVSS 7.8No exploitEPSS 0%genkit-ai · genkitAug 11, 2026
- CVE-2024-106430Monitor
Improper Neutralization of HTTP Headers for Scripting Syntax in Crafty Controller 4
HighCVSS 7.5No exploitEPSS 1%craftycontrol · crafty controllerFeb 3, 2024
- CVE-2025-015430Monitor
IBM TXSeries for Multiplatforms information disclosure
HighCVSS 7.5No exploitEPSS 0%ibm · txseries for multiplatformsApr 2, 2025
- CVE-2023-3692128Monitor
Header Injection in SAP Solution Manager (Diagnostic Agent)
HighCVSS 7.2No exploitEPSS 1%sap · solution managerJul 10, 2023
- CVE-2025-1380327Monitor
MediaCrush Header paths.py http headers for scripting syntax
MediumCVSS 6.9No exploitEPSS 0%Nov 30, 2025
- CVE-2022-2239926Monitor
IBM Aspera Faspex HTTP header injection
MediumCVSS 6.5No exploitEPSS 0%ibm · aspera faspexMar 5, 2024
- CVE-2026-051626Monitor
A improper neutralization of HTTP Headers for Scripting Syntax vulnerability in SonicOS could allow a remote attacker to manipulate the Host
MediumCVSS 6.5No exploitEPSS 0%sonicwall · sonicosAug 5, 2026
- CVE-2024-5145126Monitor
Multiple Vulnerabilities in IBM Concert Software
MediumCVSS 6.5No exploitEPSS 0%ibm · concertFeb 4, 2026
- CVE-2025-1480726Monitor
IBM InfoSphere Information Server is vulnerable to HTTP header injection
MediumCVSS 6.5No exploitEPSS 0%ibm · infosphere information serverMar 25, 2026
- CVE-2025-2790126Monitor
Multiple vulnerabilities in IBM Java SDK affecting Db2 Recovery Expert for Linux, Unix and Windows
MediumCVSS 6.5No exploitEPSS 0%ibm · db2 recovery expertFeb 17, 2026
- CVE-2021-2078424Monitor
HTTP header injection vulnerability in Everything version 1.0, 1.1, and 1.2 except the Lite version may allow a remote attacker to inject an
MediumCVSS 6.1No exploitEPSS 1%voidtools · everythingJul 13, 2021