Skip to content
Noroxi

CWE-644 · 58 records

Improper Neutralization of HTTP Headers for Scripting Syntax

CVEs in this class

58 records

  • IBM Tivoli Application Dependency Discovery Manager HOST header injection

    CriticalCVSS 9.8No exploitEPSS 1%

    ibm · tivoli application dependency discovery managerFeb 2, 2024

  • IBM Datacap Navigator HTTP HOST header injection

    CriticalCVSS 9.8No exploitEPSS 0%

    ibm · datacapJul 14, 2024

  • HCL AION is affected by an Host Header Injection vulnerability

    CriticalCVSS 9.8No exploitEPSS 0%

    hcltech · aionJan 19, 2026

  • A host header injection vulnerability in the mailer component of @perfood/couch-auth v0.26.0 allows attackers to obtain reset tokens and exe

    CriticalCVSS 9.3No exploitEPSS 0%

    Mar 5, 2026

  • CVE-2017-6031
    36Monitor

    A Header Injection issue was discovered in Certec EDV GmbH atvise scada prior to Version 3.0.

    HighCVSS 8.8No exploitEPSS 3%

    certec edv gmbh · atvise scadaMay 5, 2017

  • A Host Header Poisoning vulnerability exists in Monica 4.1.2 due to improper handling of the HTTP Host header in app/Providers/AppServicePro

    CriticalCVSS 9.1No exploitEPSS 1%

    monicahq · monicaFeb 20, 2026

  • @fastify/reply-from vulnerable to connection header abuse enabling stripping of proxy-added headers

    CriticalCVSS 9.0No exploitEPSS 1%

    fastify · fastify\/http-proxyApr 15, 2026

  • CVE-2020-6982
    35Monitor

    In Honeywell WIN-PAK 4.7.2, Web and prior versions, the header injection vulnerability has been identified, which may allow remote code exec

    HighCVSS 8.8No exploitEPSS 1%

    honeywell · win-pakMar 24, 2020

  • Dell Power Protect Cyber Recovery, contains an Authentication Bypass vulnerability.

    HighCVSS 8.8No exploitEPSS 1%

    dell · powerprotect cyber recoveryJun 14, 2023

  • OAuth2-Proxy vulnerable to header smuggling via underscore, leading to potential privilege escalation

    HighCVSS 8.5No exploitEPSS 1%

    oauth2-proxy · oauth2-proxyNov 10, 2025

  • JUNG Smart Visu Server - Improper Neutralization of HTTP Headers for Scripting Syntax

    HighCVSS 8.7No exploitEPSS 1%

    jung-group · smart visu server firmwareFeb 12, 2026

  • Coolify has host header injection in forgot password

    HighCVSS 8.5No exploitEPSS 0%

    coollabs · coolifyJan 5, 2026

  • Tandoor Recipes Vulnerable to Host Header Injection

    HighCVSS 8.1Proof of conceptEPSS 0%

    tandoor · recipesMar 26, 2026

  • October CMS vulnerable to Potential Host Header Poisoning on misconfigured servers

    HighCVSS 7.5No exploitEPSS 2%

    octobercms · octoberMar 10, 2021

  • Genkit improper host header validation

    HighCVSS 7.8No exploitEPSS 0%

    genkit-ai · genkitAug 11, 2026

  • CVE-2024-1064
    30Monitor

    Improper Neutralization of HTTP Headers for Scripting Syntax in Crafty Controller 4

    HighCVSS 7.5No exploitEPSS 1%

    craftycontrol · crafty controllerFeb 3, 2024

  • CVE-2025-0154
    30Monitor

    IBM TXSeries for Multiplatforms information disclosure

    HighCVSS 7.5No exploitEPSS 0%

    ibm · txseries for multiplatformsApr 2, 2025

  • Header Injection in SAP Solution Manager (Diagnostic Agent)

    HighCVSS 7.2No exploitEPSS 1%

    sap · solution managerJul 10, 2023

  • MediaCrush Header paths.py http headers for scripting syntax

    MediumCVSS 6.9No exploitEPSS 0%

    Nov 30, 2025

  • IBM Aspera Faspex HTTP header injection

    MediumCVSS 6.5No exploitEPSS 0%

    ibm · aspera faspexMar 5, 2024

  • CVE-2026-0516
    26Monitor

    A improper neutralization of HTTP Headers for Scripting Syntax vulnerability in SonicOS could allow a remote attacker to manipulate the Host

    MediumCVSS 6.5No exploitEPSS 0%

    sonicwall · sonicosAug 5, 2026

  • Multiple Vulnerabilities in IBM Concert Software

    MediumCVSS 6.5No exploitEPSS 0%

    ibm · concertFeb 4, 2026

  • IBM InfoSphere Information Server is vulnerable to HTTP header injection

    MediumCVSS 6.5No exploitEPSS 0%

    ibm · infosphere information serverMar 25, 2026

  • Multiple vulnerabilities in IBM Java SDK affecting Db2 Recovery Expert for Linux, Unix and Windows

    MediumCVSS 6.5No exploitEPSS 0%

    ibm · db2 recovery expertFeb 17, 2026

  • HTTP header injection vulnerability in Everything version 1.0, 1.1, and 1.2 except the Lite version may allow a remote attacker to inject an

    MediumCVSS 6.1No exploitEPSS 1%

    voidtools · everythingJul 13, 2021

All vulnerability classes