İçeriğe atla
Noroxi

CWE-93 · 220 kayıt

Improper Neutralization of CRLF Sequences ('CRLF Injection')

Bu sınıftaki CVE’ler

222 kayıt

  • CVE-2021-39172
    44Planlayın

    New line injection during configuration edition

    YüksekCVSS 8,8Kavram kanıtıEPSS %29

    catchethq · catchet27 Ağu 2021

  • CVE-2022-0666
    43Planlayın

    CRLF Injection leads to Stack Trace Exposure due to lack of filtering at https://demo.microweber.org/ in microweber/microweber

    YüksekCVSS 7,5Kavram kanıtıEPSS %44

    microweber · microweber18 Şub 2022

  • CVE-2024-20337
    41Planlayın

    A vulnerability in the SAML authentication process of Cisco Secure Client could allow an unauthenticated, remote attacker to conduct a carri

    YüksekCVSS 8,2İstismar yokEPSS %30

    cisco · secure client6 Mar 2024

  • CVE-2026-72590
    40Planlayın

    alseambusher crontab-ui - Unauthenticated RCE via Newline Injection in env_vars Parameter

    KritikCVSS 9,8İstismar yokEPSS %2

    alseambusher · crontab-ui10 Ağu 2026

  • CVE-2026-77550
    40Planlayın

    A malicious actor with access to the network could exploit an Improper Neutralization of CRLF Sequences vulnerability found in certain devic

    KritikCVSS 10,0İstismar yokEPSS %1

    ubiquiti inc · unifi os server26 Ağu 2026

  • CVE-2026-33128
    40Planlayın

    h3 has a Server-Sent Events Injection via Unsanitized Newlines in Event Stream Fields

    KritikCVSS 10,0İstismar yokEPSS %1

    h3 · h320 Mar 2026

  • CVE-2024-51501
    40Planlayın

    CRLF injection in Refit's [Header], [HeaderCollection] and [Authorize] attributes

    KritikCVSS 10,0İstismar yokEPSS %1

    reactiveui · refit4 Kas 2024

  • CVE-2026-84372
    39İzleyin

    Predis: Redis command injection and denial of service via CRLF smuggling in pipelined commands on aggregate connections

    KritikCVSS 9,8İstismar yokEPSS %1

    predis · predis1 Eyl 2026

  • CVE-2026-47890
    39İzleyin

    Spring Framework Server Sent Event stream corruption while rendering fragments

    KritikCVSS 9,8İstismar yokEPSS %1

    vmware · spring framework27 Ağu 2026

  • CVE-2026-59313
    39İzleyin

    Server Sent Event stream corruption in Spring MVC functional web framework

    KritikCVSS 9,8İstismar yokEPSS %1

    vmware · spring framework27 Ağu 2026

  • CVE-2026-50292
    39İzleyin

    In libinput before 1.30.4 and 1.31.x before 1.31.3, libinput-device-group unescaped phys output can inject udev properties leading to arbitr

    KritikCVSS 9,8İstismar yokEPSS %1

    freedesktop · libinput4 Haz 2026

  • CVE-2026-39394
    39İzleyin

    CI4MS has an .env CRLF Injection via Unvalidated `host` Parameter in Install Controller

    KritikCVSS 9,8İstismar yokEPSS %1

    ci4-cms-erp · ci4ms8 Nis 2026

  • CVE-2026-11362
    39İzleyin

    DataDog::DogStatsd versions through 0.07 for Perl allow metric injections from event tags

    KritikCVSS 9,8İstismar yokEPSS %0

    binary · datadog\5 Haz 2026

  • CVE-2026-45372
    39İzleyin

    cpp-httplib: HTTP header value percent-decoding in server-side `parse_header` enables CRLF injection

    KritikCVSS 9,9İstismar yokEPSS %0

    yhirose · cpp-httplib29 May 2026

  • CVE-2026-82854
    38İzleyin

    Nodemailer before 8.0.3 SMTP Command Injection via envelope.size

    KritikCVSS 9,3İstismar yokEPSS %2

    nodemailer · nodemailer31 Ağu 2026

  • CVE-2026-75925
    37İzleyin

    IXON VPN Client CRLF Injection

    KritikCVSS 9,4İstismar yokEPSS %1

    ixon · ixon vpn client4 Eyl 2026

  • CVE-2026-90937
    37İzleyin

    froxlor before 2.2.5 nginx/Apache Configuration Injection via subdomain redirect URL

    KritikCVSS 9,4İstismar yokEPSS %0

    froxlor · froxlor14 Eyl 2026

  • CVE-2025-40671
    37İzleyin

    SQL injection vulnerability in AES Multimedia's Gestnet

    KritikCVSS 9,3İstismar yokEPSS %0

    aes multimedia · gestnet26 May 2025

  • CVE-2026-34458
    37İzleyin

    Sandboxie-Plus privilege escalation via INI CRLF injection bypassing EditAdminOnly

    KritikCVSS 9,3İstismar yokEPSS %0

    sandboxie-plus · sandboxie5 May 2026

  • CVE-2026-82973
    37İzleyin

    Improper Neutralization of CRLF Sequences ('CRLF Injection') in docker-mailbox

    KritikCVSS 9,4İstismar yok

    psyb0t · docker-mailboxBugün

  • CVE-2016-3115
    36İzleyin

    Multiple CRLF injection vulnerabilities in session.c in sshd in OpenSSH before 7.2p2 allow remote authenticated users to bypass intended she

    OrtaCVSS 6,4Kavram kanıtıEPSS %37

    openbsd · openssh22 Mar 2016

  • CVE-2026-11373
    36İzleyin

    Net::Statsite::Client versions through 1.1.0 for Perl allow metric injections

    KritikCVSS 9,1İstismar yokEPSS %1

    jasei · net::statsite::client22 Haz 2026

  • CVE-2026-50638
    36İzleyin

    Metrics::Any::Adapter::DogStatsd versions before 0.04 for Perl does not protect against metric injections

    KritikCVSS 9,1İstismar yokEPSS %1

    pevans · metrics\10 Haz 2026

  • CVE-2026-9270
    36İzleyin

    DataDog::DogStatsd versions through 0.07 for Perl allow metric injections

    KritikCVSS 9,1İstismar yokEPSS %1

    binary · datadog\5 Haz 2026

  • CVE-2026-77549
    36İzleyin

    A malicious actor with access to the network and under certain conditions could exploit an Improper Neutralization of CRLF Sequences vulnera

    KritikCVSS 9,0İstismar yokEPSS %1

    ubiquiti inc · unifi os server26 Ağu 2026

Tüm zafiyet sınıfları