V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsProductsVendorsDocs
Filters

All vulnerabilities

309 / 309
CAPEC: CAPEC-33×Clear all
10.0
CVE-2022-22536CVE KEV
SAP NetWeaver Application Server ABAP, SAP NetWeaver Application Server Java, ABAP Platform, SA…
2022-01-01KEV
EPSS97.9%
pct 99
7.5
CVE-2020-9490AST
Apache HTTP Server versions 2.4.20 to 2.4.43. A specially crafted value for the 'Cache-Digest' …
2020-01-01Pre-auth
EPSS89.7%
pct 99
9.9
CVE-2023-41265CVE KEV
An HTTP Request Tunneling vulnerability found in Qlik Sense Enterprise for Windows for versions…
2023-01-01KEV
EPSS85.0%
pct 99
9.8
CVE-2023-25690ANC
Some mod_proxy configurations on Apache HTTP Server versions 2.4.0 through 2.4.55 allow a HTTP …
2023-01-01Pre-auth
EPSS83.8%
pct 99
6.5
CVE-2022-32214DEB
The llhttp parser <v14.20.1, <v16.17.1 and <v18.9.1 in the http module in Node.js does not stri…
2022-01-01Pre-auth
EPSS77.3%
pct 99
4.3
CVE-2021-33037DEB
Apache Tomcat 10.0.0-M1 to 10.0.6, 9.0.0.M1 to 9.0.46 and 8.5.0 to 8.5.66 did not correctly par…
2021-01-01Pre-auth
EPSS75.4%
pct 99
6.5
CVE-2022-32215DEB
The llhttp parser <v14.20.1, <v16.17.1 and <v18.9.1 in the http module in Node.js does not corr…
2022-01-01Pre-auth
EPSS68.8%
pct 99
9.9
CVE-2025-55315MSR
Inconsistent interpretation of http requests ('http request/response smuggling') in ASP.NET Cor…
2025-01-01Microsoft
EPSS66.3%
pct 99
9.8
CVE-2021-30180CVE
Apache Dubbo prior to 2.7.9 support Tag routing which will enable a customer to route the reque…
2021-01-01Pre-auth
EPSS60.4%
pct 99
4.8
CVE-2019-17567AST
Apache HTTP Server versions 2.4.6 to 2.4.46 mod_proxy_wstunnel configured on an URL that is not…
2019-01-01Pre-auth
EPSS60.3%
pct 99
7.5
CVE-2020-11993AST
Apache HTTP Server versions 2.4.20 to 2.4.43 When trace/debug was enabled for the HTTP/2 module…
2020-01-01Pre-auth
EPSS58.7%
pct 98
7.1
CVE-2019-15605AST
HTTP request smuggling in Node.js 10, 12, and 13 causes malicious payload delivery when transfe…
2019-01-01Pre-auth
EPSS57.1%
pct 98
7.5
CVE-2021-40346AST
An integer overflow exists in HAProxy 2.0 through 2.5 in htx_add_header that can be exploited t…
2021-01-01Pre-auth
EPSS56.1%
pct 98
5.4
CVE-2022-21826CVE
Pulse Secure version 9.115 and below may be susceptible to client-side http request smuggling, …
2022-01-01
EPSS45.2%
pct 98
6.5
CVE-2016-6816DEB
The code in Apache Tomcat 9.0.0.M1 to 9.0.0.M11, 8.5.0 to 8.5.6, 8.0.0.RC1 to 8.0.38, 7.0.0 to …
2016-01-01Pre-auth
EPSS39.6%
pct 98
5.9
CVE-2021-23336AST
The package python/cpython from 0 and before 3.6.13, from 3.7.0 and before 3.7.10, from 3.8.0 a…
2021-01-01Pre-auth
EPSS37.3%
pct 98
6.5
CVE-2022-32213DEB
The llhttp parser <v14.20.1, <v16.17.1 and <v18.9.1 in the http module in Node.js does not corr…
2022-01-01Pre-auth
EPSS35.1%
pct 98
4.3
CVE-2005-2089CVE
Microsoft IIS 5.0 and 6.0 allows remote attackers to poison the web cache, bypass web applicati…
2005-01-01
EPSS31.0%
pct 98
8.3
CVE-2022-22720ANC
Apache HTTP Server 2.4.52 and earlier fails to close inbound connection when errors are encount…
2022-01-01Pre-auth
EPSS28.2%
pct 97
9.9
CVE-2023-48365CVE KEV
Qlik Sense Enterprise for Windows before August 2023 Patch 2 allows unauthenticated remote code…
2023-01-01KEV
EPSS24.7%
pct 97
9.8
CVE-2017-7658DEB
In Eclipse Jetty Server, versions 9.2.x and older, 9.3.x (all non HTTP/1.x configurations), and…
2017-01-01Pre-auth
EPSS21.0%
pct 97
4.3
CVE-2005-2088DEB
The Apache HTTP server before 1.3.34, and 2.0.x before 2.0.55, when acting as an HTTP proxy, al…
2005-01-01
EPSS20.5%
pct 97
5.9
CVE-2021-21295DEB
Netty is an open-source, asynchronous event-driven network application framework for rapid deve…
2021-01-01Pre-auth
EPSS18.9%
pct 96
6.5
CVE-2022-26377ANC
Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') vulnerability in mod_pr…
2022-01-01Pre-auth
EPSS18.9%
pct 96
5.4
CVE-2020-8287AST
Node.js versions before 10.23.1, 12.20.1, 14.15.4, 15.5.1 allow two copies of a header field in…
2020-01-01Pre-auth
EPSS16.3%
pct 96
9.8
CVE-2017-7657DEB
In Eclipse Jetty, versions 9.2.x and older, 9.3.x (all configurations), and 9.4.x (non-default …
2017-01-01Pre-auth
EPSS16.2%
pct 96
5.3
CVE-2019-20372DEB
NGINX before 1.17.7, with certain error_page configurations, allows HTTP request smuggling, as …
2019-01-01Pre-auth
EPSS15.0%
pct 96
7.5
CVE-2019-20445DEB
HttpObjectDecoder.java in Netty before 4.1.44 allows a Content-Length header to be accompanied …
2019-01-01Pre-auth
EPSS13.5%
pct 95
6.8
CVE-2019-18678AST
An issue was discovered in Squid 3.x and 4.x through 4.8. It allows attackers to smuggle HTTP r…
2019-01-01Pre-auth
EPSS10.9%
pct 95
6.5
CVE-2019-18277AST
A flaw was found in HAProxy before 2.0.6. In legacy mode, messages featuring a transfer-encodin…
2019-01-01Pre-auth
EPSS10.0%
pct 95
4.3
CVE-2020-1935DEB
In Apache Tomcat 9.0.0.M1 to 9.0.30, 8.5.0 to 8.5.50 and 7.0.0 to 7.0.99 the HTTP header parsin…
2020-01-01Pre-auth
EPSS9.4%
pct 94
9.8
CVE-2015-5739DEB
The net/http library in net/textproto/reader.go in Go before 1.4.3 does not properly parse HTTP…
2015-01-01Pre-auth
EPSS9.4%
pct 94
4.3
CVE-2019-17569DEB
The refactoring present in Apache Tomcat 9.0.28 to 9.0.30, 8.5.48 to 8.5.50 and 7.0.98 to 7.0.9…
2019-01-01Pre-auth
EPSS8.9%
pct 94
7.5
CVE-2019-20444DEB
HttpObjectDecoder.java in Netty before 4.1.44 allows an HTTP header that lacks a colon, which m…
2019-01-01Pre-auth
EPSS8.7%
pct 94
4.2
CVE-2019-0197AST
A vulnerability was found in Apache HTTP Server 2.4.34 to 2.4.38. When HTTP/2 was enabled for a…
2019-01-01
EPSS8.4%
pct 94
7.5
CVE-2019-16869DEB
Netty before 4.1.42.Final mishandles whitespace before the colon in HTTP headers (such as a "Tr…
2019-01-01Pre-auth
EPSS8.4%
pct 94
8.6
CVE-2020-25097AST
An issue was discovered in Squid through 4.13 and 5.x through 5.0.4. Due to improper input vali…
2020-01-01Pre-auth
EPSS8.2%
pct 94
9.8
CVE-2022-29361CVE
Improper parsing of HTTP requests in Pallets Werkzeug v2.1.0 and below allows attackers to perf…
2022-01-01Pre-auth
EPSS7.7%
pct 93
7.5
CVE-2017-7656DEB
In Eclipse Jetty, versions 9.2.x and older, 9.3.x (all configurations), and 9.4.x (non-default …
2017-01-01Pre-auth
EPSS6.4%
pct 92
6.5
CVE-2018-8004DEB
There are multiple HTTP smuggling and cache poisoning issues when clients making malicious requ…
2018-01-01
EPSS6.3%
pct 92
Select a vulnerability on the left to open the preview.