İçeriğe atla
Noroxi

CWE-113 · 102 kayıt

Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Request/Response Splitting')

Bu sınıftaki CVE’ler

102 kayıt

  • CVE-2024-52875
    44Planlayın

    An issue was discovered in GFI Kerio Control 9.2.5 through 9.4.5.

    YüksekCVSS 8,8Kavram kanıtıEPSS %29

    gfi · kerio control31 Oca 2025

  • CVE-2019-25101
    39İzleyin

    OnShift TurboGears HTTP Header controllers.py response splitting

    KritikCVSS 9,8İstismar yokEPSS %1

    turbogears project · turbogears4 Şub 2023

  • CVE-2026-38967
    39İzleyin

    CrowCpp Crow through v1.3.1 HTTP is vulnerable to response header injection via unvalidated response header values.

    KritikCVSS 9,8İstismar yokEPSS %1

    2 Haz 2026

  • CVE-2022-37436
    38İzleyin

    Apache HTTP Server: mod_proxy prior to 2.4.55 allows a backend to trigger HTTP response splitting

    OrtaCVSS 5,3İstismar yokEPSS %56

    apache · http server17 Oca 2023

  • CVE-2026-67289
    37İzleyin

    FreeRDP before 3.29.0 HTTP Proxy Request Injection via Redirection

    KritikCVSS 9,3İstismar yokEPSS %1

    freerdp · freerdp1 Ağu 2026

  • CVE-2018-13814
    36İzleyin

    A vulnerability has been identified in SIMATIC HMI Comfort Panels 4" - 22" (All versions < V14), SIMATIC HMI Comfort Outdoor Panels 7" & 15"

    YüksekCVSS 8,8İstismar yokEPSS %2

    siemens · simatic hmi comfort panels firmware13 Ara 2018

  • CVE-2016-8024
    35İzleyin

    Improper neutralization of CRLF sequences in HTTP headers vulnerability in Intel Security VirusScan Enterprise Linux (VSEL) 2.0.3 (and earli

    YüksekCVSS 8,1Kavram kanıtıEPSS %9

    mcafee · virusscan enterprise14 Mar 2017

  • CVE-2018-0689
    35İzleyin

    HTTP header injection vulnerability in SEIKO EPSON printers and scanners (DS-570W firmware versions released prior to 2018 March 13, DS-780N

    YüksekCVSS 8,8İstismar yokEPSS %2

    epson · ds-570w firmware9 Oca 2019

  • CVE-2018-11347
    35İzleyin

    The YunoHost 2.7.2 through 2.7.14 web application is affected by one HTTP Response Header Injection.

    YüksekCVSS 8,8İstismar yokEPSS %1

    yunohost · yunohost4 Ara 2018

  • CVE-2023-32708
    35İzleyin

    HTTP Response Splitting via the ‘rest’ SPL Command

    YüksekCVSS 8,8İstismar yokEPSS %1

    splunk · splunk1 Haz 2023

  • CVE-2026-75419
    35İzleyin

    go-wind-cms (GoWind) before 1.0.0 has a missing authorization vulnerability.

    YüksekCVSS 8,8İstismar yokEPSS %1

    27 Ağu 2026

  • CVE-2021-40336
    35İzleyin

    HTTP Response Splitting in Hitachi Energy’s MSM Product

    YüksekCVSS 8,8İstismar yokEPSS %0

    hitachienergy · modular switchgear monitoring firmware25 Tem 2022

  • CVE-2025-53007
    35İzleyin

    arduino-esp32 vulnerable to CRLF injection in WebServer.cpp

    YüksekCVSS 8,9İstismar yokEPSS %0

    espressif · arduino-esp3226 Haz 2025

  • CVE-2025-55271
    35İzleyin

    HCL Aftermarket DPC is affected by HTTP Response Splitting vulnerability

    YüksekCVSS 8,8İstismar yokEPSS %0

    hcltech · aftermarket cloud26 Mar 2026

  • CVE-2018-3911
    34İzleyin

    An exploitable HTTP header injection vulnerability exists in the remote servers of Samsung SmartThings Hub STH-ETH-250 - Firmware version 0.

    YüksekCVSS 8,6İstismar yokEPSS %1

    samsung · sth-eth-250 firmware23 Ağu 2018

  • CVE-2026-39915
    34İzleyin

    TIM Flow < 26.0.6 CRLF Injection via rt Parameter

    YüksekCVSS 8,5İstismar yokEPSS %0

    tim solutions · tim flow24 Ağu 2026

  • CVE-2025-61689
    34İzleyin

    HTTP.jl vulnerable to Header injection/Response splitting via header construction.

    YüksekCVSS 8,7İstismar yokEPSS %0

    juliaweb · http.jl10 Eki 2025

  • CVE-2024-23644
    32İzleyin

    trillium-http and trillium-client vulnerable to HTTP Request/Response Splitting

    YüksekCVSS 8,1İstismar yokEPSS %1

    trillium · trillium24 Oca 2024

  • CVE-2026-85077
    32İzleyin

    Sanic: HTTP response header injection via missing CR/LF validation in Sanic HTTP/1.1 responses

    YüksekCVSS 8,2İstismar yokEPSS %0

    sanic-org · sanic17 Eyl 2026

  • CVE-2020-5247
    31İzleyin

    HTTP Response Splitting in Puma

    YüksekCVSS 7,5İstismar yokEPSS %3

    puma · puma28 Şub 2020

  • CVE-2018-7830
    31İzleyin

    Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting') vulnerability exists in the embedded web servers in al

    YüksekCVSS 7,5İstismar yokEPSS %2

    schneider-electric · modicom m340 firmware30 Kas 2018

  • CVE-2022-3215
    30İzleyin

    NIOHTTP1 and projects using it for generating HTTP responses can be subject to a HTTP Response Injection attack.

    YüksekCVSS 7,5İstismar yokEPSS %1

    apple · swiftnio28 Eyl 2022

  • CVE-2023-42450
    30İzleyin

    Mastodon Server-Side Request Forgery vulnerability

    YüksekCVSS 7,5İstismar yokEPSS %0

    joinmastodon · mastodon19 Eyl 2023

  • CVE-2015-1445
    29İzleyin

    HTTP header injection in the httpd package in fli4l before 3.10.1 and 4.0 before 2015-01-30.

    YüksekCVSS 7,2İstismar yokEPSS %2

    fli4l · fli4l28 Ağu 2017

  • CVE-2025-40927
    29İzleyin

    CGI::Simple versions 1.281 and earlier for Perl has a HTTP response splitting flaw

    YüksekCVSS 7,3İstismar yokEPSS %0

    manwar · cgi::simple28 Ağu 2025

Tüm zafiyet sınıfları