CWE-93 · 220 kayıt
Improper Neutralization of CRLF Sequences ('CRLF Injection')
Bu sınıftaki CVE’ler
222 kayıt
| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
44Planlayın | CVE-2021-39172Kavram kanıtı | New line injection during configuration editioncatchethq · catchet · CWE-93 | Yüksek8,8 | — | %29,2 | 27 Ağu 2021 |
43Planlayın | CVE-2022-0666Kavram kanıtı | CRLF Injection leads to Stack Trace Exposure due to lack of filtering at https://demo.microweber.org/ in microweber/microwebermicroweber · microweber · CWE-93 | Yüksek7,5 | — | %44,3 | 18 Şub 2022 |
41Planlayın | CVE-2024-20337İstismar yok | A vulnerability in the SAML authentication process of Cisco Secure Client could allow an unauthenticated, remote attacker to conduct a carricisco · secure client · CWE-93 | Yüksek8,2 | — | %29,9 | 6 Mar 2024 |
40Planlayın | CVE-2026-72590İstismar yok | alseambusher crontab-ui - Unauthenticated RCE via Newline Injection in env_vars Parameteralseambusher · crontab-ui · CWE-93 | Kritik9,8 | — | %2,0 | 10 Ağu 2026 |
40Planlayın | CVE-2026-77550İstismar yok | A malicious actor with access to the network could exploit an Improper Neutralization of CRLF Sequences vulnerability found in certain devicubiquiti inc · unifi os server · CWE-93 | Kritik10,0 | — | %0,8 | 26 Ağu 2026 |
40Planlayın | CVE-2026-33128İstismar yok | h3 has a Server-Sent Events Injection via Unsanitized Newlines in Event Stream Fieldsh3 · h3 · CWE-93 | Kritik10,0 | — | %0,7 | 20 Mar 2026 |
40Planlayın | CVE-2024-51501İstismar yok | CRLF injection in Refit's [Header], [HeaderCollection] and [Authorize] attributesreactiveui · refit · CWE-93 | Kritik10,0 | — | %0,6 | 4 Kas 2024 |
39İzleyin | CVE-2026-84372İstismar yok | Predis: Redis command injection and denial of service via CRLF smuggling in pipelined commands on aggregate connectionspredis · predis · CWE-93 | Kritik9,8 | — | %0,7 | 1 Eyl 2026 |
39İzleyin | CVE-2026-47890İstismar yok | Spring Framework Server Sent Event stream corruption while rendering fragmentsvmware · spring framework · CWE-93 | Kritik9,8 | — | %0,6 | 27 Ağu 2026 |
39İzleyin | CVE-2026-59313İstismar yok | Server Sent Event stream corruption in Spring MVC functional web frameworkvmware · spring framework · CWE-93 | Kritik9,8 | — | %0,6 | 27 Ağu 2026 |
39İzleyin | CVE-2026-50292İstismar yok | In libinput before 1.30.4 and 1.31.x before 1.31.3, libinput-device-group unescaped phys output can inject udev properties leading to arbitrfreedesktop · libinput · CWE-93 | Kritik9,8 | — | %0,5 | 4 Haz 2026 |
39İzleyin | CVE-2026-39394İstismar yok | CI4MS has an .env CRLF Injection via Unvalidated `host` Parameter in Install Controllerci4-cms-erp · ci4ms · CWE-93 | Kritik9,8 | — | %0,5 | 8 Nis 2026 |
39İzleyin | CVE-2026-11362İstismar yok | DataDog::DogStatsd versions through 0.07 for Perl allow metric injections from event tagsbinary · datadog\ · CWE-93 | Kritik9,8 | — | %0,4 | 5 Haz 2026 |
39İzleyin | CVE-2026-45372İstismar yok | cpp-httplib: HTTP header value percent-decoding in server-side `parse_header` enables CRLF injectionyhirose · cpp-httplib · CWE-93 | Kritik9,9 | — | %0,4 | 29 May 2026 |
38İzleyin | CVE-2026-82854İstismar yok | Nodemailer before 8.0.3 SMTP Command Injection via envelope.sizenodemailer · nodemailer · CWE-93 | Kritik9,3 | — | %2,0 | 31 Ağu 2026 |
37İzleyin | CVE-2026-75925İstismar yok | IXON VPN Client CRLF Injectionixon · ixon vpn client · CWE-93 | Kritik9,4 | — | %0,7 | 4 Eyl 2026 |
37İzleyin | CVE-2026-90937İstismar yok | froxlor before 2.2.5 nginx/Apache Configuration Injection via subdomain redirect URLfroxlor · froxlor · CWE-93 | Kritik9,4 | — | %0,5 | 14 Eyl 2026 |
37İzleyin | CVE-2025-40671İstismar yok | SQL injection vulnerability in AES Multimedia's Gestnetaes multimedia · gestnet · CWE-93 | Kritik9,3 | — | %0,4 | 26 May 2025 |
37İzleyin | CVE-2026-34458İstismar yok | Sandboxie-Plus privilege escalation via INI CRLF injection bypassing EditAdminOnlysandboxie-plus · sandboxie · CWE-93 | Kritik9,3 | — | %0,3 | 5 May 2026 |
37İzleyin | CVE-2026-82973İstismar yok | Improper Neutralization of CRLF Sequences ('CRLF Injection') in docker-mailboxpsyb0t · docker-mailbox · CWE-93 | Kritik9,4 | — | — | Bugün |
36İzleyin | CVE-2016-3115Kavram kanıtı | Multiple CRLF injection vulnerabilities in session.c in sshd in OpenSSH before 7.2p2 allow remote authenticated users to bypass intended sheopenbsd · openssh · CWE-93 | Orta6,4 | — | %37,0 | 22 Mar 2016 |
36İzleyin | CVE-2026-11373İstismar yok | Net::Statsite::Client versions through 1.1.0 for Perl allow metric injectionsjasei · net::statsite::client · CWE-93 | Kritik9,1 | — | %0,6 | 22 Haz 2026 |
36İzleyin | CVE-2026-50638İstismar yok | Metrics::Any::Adapter::DogStatsd versions before 0.04 for Perl does not protect against metric injectionspevans · metrics\ · CWE-93 | Kritik9,1 | — | %0,6 | 10 Haz 2026 |
36İzleyin | CVE-2026-9270İstismar yok | DataDog::DogStatsd versions through 0.07 for Perl allow metric injectionsbinary · datadog\ · CWE-93 | Kritik9,1 | — | %0,5 | 5 Haz 2026 |
36İzleyin | CVE-2026-77549İstismar yok | A malicious actor with access to the network and under certain conditions could exploit an Improper Neutralization of CRLF Sequences vulneraubiquiti inc · unifi os server · CWE-93 | Kritik9,0 | — | %0,5 | 26 Ağu 2026 |
- CVE-2021-3917244Planlayın
New line injection during configuration edition
YüksekCVSS 8,8Kavram kanıtıEPSS %29catchethq · catchet27 Ağu 2021
- CVE-2022-066643Planlayın
CRLF Injection leads to Stack Trace Exposure due to lack of filtering at https://demo.microweber.org/ in microweber/microweber
YüksekCVSS 7,5Kavram kanıtıEPSS %44microweber · microweber18 Şub 2022
- CVE-2024-2033741Planlayın
A vulnerability in the SAML authentication process of Cisco Secure Client could allow an unauthenticated, remote attacker to conduct a carri
YüksekCVSS 8,2İstismar yokEPSS %30cisco · secure client6 Mar 2024
- CVE-2026-7259040Planlayın
alseambusher crontab-ui - Unauthenticated RCE via Newline Injection in env_vars Parameter
KritikCVSS 9,8İstismar yokEPSS %2alseambusher · crontab-ui10 Ağu 2026
- CVE-2026-7755040Planlayın
A malicious actor with access to the network could exploit an Improper Neutralization of CRLF Sequences vulnerability found in certain devic
KritikCVSS 10,0İstismar yokEPSS %1ubiquiti inc · unifi os server26 Ağu 2026
- CVE-2026-3312840Planlayın
h3 has a Server-Sent Events Injection via Unsanitized Newlines in Event Stream Fields
KritikCVSS 10,0İstismar yokEPSS %1h3 · h320 Mar 2026
- CVE-2024-5150140Planlayın
CRLF injection in Refit's [Header], [HeaderCollection] and [Authorize] attributes
KritikCVSS 10,0İstismar yokEPSS %1reactiveui · refit4 Kas 2024
- CVE-2026-8437239İzleyin
Predis: Redis command injection and denial of service via CRLF smuggling in pipelined commands on aggregate connections
KritikCVSS 9,8İstismar yokEPSS %1predis · predis1 Eyl 2026
- CVE-2026-4789039İzleyin
Spring Framework Server Sent Event stream corruption while rendering fragments
KritikCVSS 9,8İstismar yokEPSS %1vmware · spring framework27 Ağu 2026
- CVE-2026-5931339İzleyin
Server Sent Event stream corruption in Spring MVC functional web framework
KritikCVSS 9,8İstismar yokEPSS %1vmware · spring framework27 Ağu 2026
- CVE-2026-5029239İzleyin
In libinput before 1.30.4 and 1.31.x before 1.31.3, libinput-device-group unescaped phys output can inject udev properties leading to arbitr
KritikCVSS 9,8İstismar yokEPSS %1freedesktop · libinput4 Haz 2026
- CVE-2026-3939439İzleyin
CI4MS has an .env CRLF Injection via Unvalidated `host` Parameter in Install Controller
KritikCVSS 9,8İstismar yokEPSS %1ci4-cms-erp · ci4ms8 Nis 2026
- CVE-2026-1136239İzleyin
DataDog::DogStatsd versions through 0.07 for Perl allow metric injections from event tags
KritikCVSS 9,8İstismar yokEPSS %0binary · datadog\5 Haz 2026
- CVE-2026-4537239İzleyin
cpp-httplib: HTTP header value percent-decoding in server-side `parse_header` enables CRLF injection
KritikCVSS 9,9İstismar yokEPSS %0yhirose · cpp-httplib29 May 2026
- CVE-2026-8285438İzleyin
Nodemailer before 8.0.3 SMTP Command Injection via envelope.size
KritikCVSS 9,3İstismar yokEPSS %2nodemailer · nodemailer31 Ağu 2026
- CVE-2026-7592537İzleyin
IXON VPN Client CRLF Injection
KritikCVSS 9,4İstismar yokEPSS %1ixon · ixon vpn client4 Eyl 2026
- CVE-2026-9093737İzleyin
froxlor before 2.2.5 nginx/Apache Configuration Injection via subdomain redirect URL
KritikCVSS 9,4İstismar yokEPSS %0froxlor · froxlor14 Eyl 2026
- CVE-2025-4067137İzleyin
SQL injection vulnerability in AES Multimedia's Gestnet
KritikCVSS 9,3İstismar yokEPSS %0aes multimedia · gestnet26 May 2025
- CVE-2026-3445837İzleyin
Sandboxie-Plus privilege escalation via INI CRLF injection bypassing EditAdminOnly
KritikCVSS 9,3İstismar yokEPSS %0sandboxie-plus · sandboxie5 May 2026
- CVE-2026-8297337İzleyin
Improper Neutralization of CRLF Sequences ('CRLF Injection') in docker-mailbox
KritikCVSS 9,4İstismar yokpsyb0t · docker-mailboxBugün
- CVE-2016-311536İzleyin
Multiple CRLF injection vulnerabilities in session.c in sshd in OpenSSH before 7.2p2 allow remote authenticated users to bypass intended she
OrtaCVSS 6,4Kavram kanıtıEPSS %37openbsd · openssh22 Mar 2016
- CVE-2026-1137336İzleyin
Net::Statsite::Client versions through 1.1.0 for Perl allow metric injections
KritikCVSS 9,1İstismar yokEPSS %1jasei · net::statsite::client22 Haz 2026
- CVE-2026-5063836İzleyin
Metrics::Any::Adapter::DogStatsd versions before 0.04 for Perl does not protect against metric injections
KritikCVSS 9,1İstismar yokEPSS %1pevans · metrics\10 Haz 2026
- CVE-2026-927036İzleyin
DataDog::DogStatsd versions through 0.07 for Perl allow metric injections
KritikCVSS 9,1İstismar yokEPSS %1binary · datadog\5 Haz 2026
- CVE-2026-7754936İzleyin
A malicious actor with access to the network and under certain conditions could exploit an Improper Neutralization of CRLF Sequences vulnera
KritikCVSS 9,0İstismar yokEPSS %1ubiquiti inc · unifi os server26 Ağu 2026