All vulnerabilities
113 / 113
Sort
9.8
CVE-2023-25690ANC
Some mod_proxy configurations on Apache HTTP Server versions 2.4.0 through 2.4.55 allow a HTTP …
2023-01-01Pre-auth
EPSS83.8%
pct 99
5.3
CVE-2022-37436AST
Prior to Apache HTTP Server 2.4.55, a malicious backend can cause the response headers to be tr…
2022-01-01Pre-auth
EPSS57.9%
pct 98
8.8
CVE-2024-52875CVE
An issue was discovered in GFI Kerio Control 9.2.5 through 9.4.5. The dest GET parameter passed…
2024-01-01Pre-auth
EPSS27.3%
pct 97
3.7
CVE-2016-4975DEB
Possible CRLF injection allowing HTTP response splitting attacks for sites which use mod_userdi…
2016-01-01Pre-auth
EPSS19.8%
pct 97
5.3
CVE-2016-5699DEB
CRLF injection vulnerability in the HTTPConnection.putheader function in urllib2 and urllib in …
2016-01-01
EPSS9.9%
pct 94
8.1
CVE-2016-8024CVE
Improper neutralization of CRLF sequences in HTTP headers vulnerability in Intel Security Virus…
2016-01-01Pre-auth
EPSS8.7%
pct 94
7.5
CVE-2016-2216DEB
The HTTP header parsing code in Node.js 0.10.x before 0.10.42, 0.11.6 through 0.11.16, 0.12.x b…
2016-01-01Pre-auth
EPSS7.0%
pct 93
4.3
CVE-2014-8150DEB
CRLF injection vulnerability in libcurl 6.0 through 7.x before 7.40.0, when using an HTTP proxy…
2014-01-01
EPSS6.8%
pct 93
6.5
CVE-2020-26116AST
http.client in Python 3.x before 3.5.10, 3.6.x before 3.6.12, 3.7.x before 3.7.9, and 3.8.x bef…
2020-01-01Pre-auth
EPSS6.3%
pct 92
4.7
CVE-2017-17742AST
Ruby before 2.2.10, 2.3.x before 2.3.7, 2.4.x before 2.4.4, 2.5.x before 2.5.1, and 2.6.0-previ…
2017-01-01Pre-auth
EPSS5.8%
pct 92
6.5
CVE-2019-9947AST
An issue was discovered in urllib2 in Python 2.x through 2.7.16 and urllib in Python 3.x throug…
2019-01-01Pre-auth
EPSS5.4%
pct 91
6.5
CVE-2019-9740AST
An issue was discovered in urllib2 in Python 2.x through 2.7.16 and urllib in Python 3.x throug…
2019-01-01Pre-auth
EPSS5.4%
pct 91
7.2
CVE-2018-12116AST
Node.js: All versions prior to Node.js 6.15.0 and 8.14.0: HTTP request splitting: If Node.js ca…
2018-01-01Pre-auth
EPSS4.6%
pct 90
5.3
CVE-2019-16254AST
Ruby through 2.4.7, 2.5.x through 2.5.6, and 2.6.x through 2.6.4 allows HTTP Response Splitting…
2019-01-01Pre-auth
EPSS4.6%
pct 90
4.3
CVE-2015-0881DEB
CRLF injection vulnerability in Squid before 3.1.1 allows remote attackers to inject arbitrary …
2015-01-01
EPSS4.5%
pct 90
4.8
CVE-2016-5325DEB
CRLF injection vulnerability in the ServerResponse#writeHead function in Node.js 0.10.x before …
2016-01-01Pre-auth
EPSS4.1%
pct 89
6.5
CVE-2019-18348AST
An issue was discovered in urllib2 in Python 2.x through 2.7.17 and urllib in Python 3.x throug…
2019-01-01Pre-auth
EPSS3.5%
pct 87
7.5
CVE-2015-8852DEB
Varnish 3.x before 3.0.7, when used in certain stacked installations, allows remote attackers t…
2015-01-01Pre-auth
EPSS3.4%
pct 87
6.1
CVE-2018-16979CVE
Monstra CMS V3.0.4 allows HTTP header injection in the plugins/captcha/crypt/cryptographp.php c…
2018-01-01Pre-auth
EPSS3.0%
pct 85
3.1
CVE-2015-8935DEB
The sapi_header_op function in main/SAPI.c in PHP before 5.4.38, 5.5.x before 5.5.22, and 5.6.x…
2015-01-01Pre-auth
EPSS2.9%
pct 85
4.8
CVE-2020-2800ANC
Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Lightweigh…
2020-01-01Pre-auth
EPSS2.9%
pct 85
4.0
CVE-2024-24795ANC
HTTP Response splitting in multiple modules in Apache HTTP Server allows an attacker that can i…
2024-01-01Pre-auth
EPSS2.9%
pct 84
4.3
CVE-2014-9650DEB
CRLF injection vulnerability in the management plugin in RabbitMQ 2.1.0 through 3.4.x before 3.…
2014-01-01
EPSS2.6%
pct 83
6.8
CVE-2020-11078AST
In httplib2 before version 0.18.0, an attacker controlling unescaped part of uri for `httplib2.…
2020-01-01Pre-auth
EPSS2.6%
pct 83
5.4
CVE-2016-4993DEB
CRLF injection vulnerability in the Undertow web server in WildFly 10.0.0, as used in Red Hat J…
2016-01-01Pre-auth
EPSS2.6%
pct 83
6.5
CVE-2019-12387AST
In Twisted before 19.2.1, twisted.web did not validate or sanitize URIs or HTTP methods, allowi…
2019-01-01Pre-auth
EPSS2.5%
pct 82
5.3
CVE-2020-5247DEB
In Puma (RubyGem) before 4.3.2 and before 3.12.3, if an application using Puma allows untrusted…
2020-01-01
EPSS2.5%
pct 82
5.3
CVE-2018-12537CVE
In Eclipse Vert.x version 3.0 to 3.5.1, the HttpServer response headers and HttpClient request …
2018-01-01Pre-auth
EPSS2.5%
pct 82
4.3
CVE-2012-5486DEB
ZPublisher.HTTPRequest._scrubHeader in Zope 2 before 2.13.19, as used in Plone before 4.3 beta …
2012-01-01
EPSS2.4%
pct 82
5.3
CVE-2018-1000164DEB
gunicorn version 19.4.5 contains a CWE-113: Improper Neutralization of CRLF Sequences in HTTP H…
2018-01-01Pre-auth
EPSS2.4%
pct 82
7.5
CVE-2018-7830CVE
Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting') vulnerabi…
2018-01-01Pre-auth
EPSS2.4%
pct 82
5.3
CVE-2019-9741DEB
An issue was discovered in net/http in Go 1.11.5. CRLF injection is possible if the attacker co…
2019-01-01Pre-auth
EPSS2.3%
pct 81
8.8
CVE-2021-33621AST
The cgi gem before 0.1.0.2, 0.2.x before 0.2.2, and 0.3.x before 0.3.5 for Ruby allows HTTP res…
2021-01-01
EPSS2.3%
pct 80
6.5
CVE-2020-26137AST
urllib3 before 1.25.9 allows CRLF injection if the attacker controls the HTTP request method, a…
2020-01-01Pre-auth
EPSS2.2%
pct 80
3.7
CVE-2017-10295ANC
Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcompone…
2017-01-01Pre-auth
EPSS2.2%
pct 80
7.5
CVE-2023-27522ANC
HTTP Response Smuggling vulnerability in Apache HTTP Server via mod_proxy_uwsgi. This issue aff…
2023-01-01Pre-auth
EPSS2.1%
pct 79
6.5
CVE-2019-11236AST
In the urllib3 library through 1.24.1 for Python, CRLF injection is possible if the attacker co…
2019-01-01Pre-auth
EPSS2.1%
pct 78
5.1
CVE-2007-5595DEB
CRLF injection vulnerability in the drupal_goto function in includes/common.inc Drupal 4.7.x be…
2007-01-01
EPSS2.0%
pct 78
7.2
CVE-2015-1445CVE
HTTP header injection in the httpd package in fli4l before 3.10.1 and 4.0 before 2015-01-30.
2015-01-01
EPSS1.8%
pct 75
5.4
CVE-2018-1067DEB
In Undertow before versions 7.1.2.CR1, 7.1.2.GA it was found that the fix for CVE-2016-4993 was…
2018-01-01Pre-auth
EPSS1.8%
pct 75
Select a vulnerability on the left to open the preview.