All vulnerabilities
155 / 155
Sort
7.5
CVE-2022-0666CVE
CRLF Injection leads to Stack Trace Exposure due to lack of filtering at https://demo.microwebe…
2022-01-01Pre-auth
EPSS44.3%
pct 98
6.4
CVE-2016-3115DEB
Multiple CRLF injection vulnerabilities in session.c in sshd in OpenSSH before 7.2p2 allow remo…
2016-01-01
EPSS37.0%
pct 98
8.2
CVE-2024-20337ANC
A vulnerability in the SAML authentication process of Cisco Secure Client could allow an unauth…
2024-01-01Pre-auth
EPSS29.9%
pct 97
8.8
CVE-2021-39172DEB
Cachet is an open source status page system. Prior to version 2.5.1, authenticated users, regar…
2021-01-01
EPSS29.2%
pct 97
3.7
CVE-2016-4975DEB
Possible CRLF injection allowing HTTP response splitting attacks for sites which use mod_userdi…
2016-01-01Pre-auth
EPSS19.8%
pct 97
7.5
CVE-2019-10678DEB
Domoticz before 4.10579 neglects to categorize \n and \r as insecure argument options.
2019-01-01Pre-auth
EPSS17.3%
pct 96
7.5
CVE-2018-19585DEB
GitLab CE/EE versions 8.18 up to 11.x before 11.3.11, 11.4.x before 11.4.8, and 11.5.x before 1…
2018-01-01Pre-auth
EPSS14.5%
pct 96
6.5
CVE-2019-9947AST
An issue was discovered in urllib2 in Python 2.x through 2.7.16 and urllib in Python 3.x throug…
2019-01-01Pre-auth
EPSS5.4%
pct 91
6.5
CVE-2019-9740AST
An issue was discovered in urllib2 in Python 2.x through 2.7.16 and urllib in Python 3.x throug…
2019-01-01Pre-auth
EPSS5.4%
pct 91
6.1
CVE-2017-5868CVE
CRLF injection vulnerability in the web interface in OpenVPN Access Server 2.1.4 allows remote …
2017-01-01Pre-auth
EPSS4.6%
pct 90
5.3
CVE-2015-9096DEB
Net::SMTP in Ruby before 2.4.0 is vulnerable to SMTP command injection via CRLF sequences in a …
2015-01-01Pre-auth
EPSS3.6%
pct 88
6.1
CVE-2015-9097DEB
The mail gem before 2.5.5 for Ruby (aka A Really Ruby Mail Library) is vulnerable to SMTP comma…
2015-01-01Pre-auth
EPSS3.4%
pct 87
5.3
CVE-2017-6508DEB
CRLF injection vulnerability in the url_parse function in url.c in Wget through 1.19.1 allows r…
2017-01-01Pre-auth
EPSS3.1%
pct 85
6.1
CVE-2023-4768CVE
A CRLF injection vulnerability has been found in ManageEngine Desktop Central affecting version…
2023-01-01Pre-auth
EPSS2.9%
pct 84
6.1
CVE-2023-4767CVE
A CRLF injection vulnerability has been found in ManageEngine Desktop Central affecting version…
2023-01-01Pre-auth
EPSS2.9%
pct 84
6.8
CVE-2020-11078AST
In httplib2 before version 0.18.0, an attacker controlling unescaped part of uri for `httplib2.…
2020-01-01Pre-auth
EPSS2.6%
pct 83
5.4
CVE-2016-4993DEB
CRLF injection vulnerability in the Undertow web server in WildFly 10.0.0, as used in Red Hat J…
2016-01-01Pre-auth
EPSS2.6%
pct 83
5.3
CVE-2018-12537CVE
In Eclipse Vert.x version 3.0 to 3.5.1, the HttpServer response headers and HttpClient request …
2018-01-01Pre-auth
EPSS2.5%
pct 82
6.1
CVE-2014-2017CVE
CRLF injection vulnerability in OXID eShop Professional Edition before 4.7.11 and 4.8.x before …
2014-01-01Pre-auth
EPSS2.4%
pct 82
5.3
CVE-2018-1000164DEB
gunicorn version 19.4.5 contains a CWE-113: Improper Neutralization of CRLF Sequences in HTTP H…
2018-01-01Pre-auth
EPSS2.4%
pct 82
5.3
CVE-2019-9741DEB
An issue was discovered in net/http in Go 1.11.5. CRLF injection is possible if the attacker co…
2019-01-01Pre-auth
EPSS2.3%
pct 81
7.5
CVE-2021-31164CVE
Apache Unomi prior to version 1.5.5 allows CRLF log injection because of the lack of escaping i…
2021-01-01Pre-auth
EPSS2.3%
pct 80
6.5
CVE-2019-11236AST
In the urllib3 library through 1.24.1 for Python, CRLF injection is possible if the attacker co…
2019-01-01Pre-auth
EPSS2.1%
pct 78
8.6
CVE-2026-39983ANC
basic-ftp is an FTP client for Node.js. Prior to 5.2.1, basic-ftp allows FTP command injection …
2026-01-01Pre-auth
EPSS1.9%
pct 77
6.1
CVE-2016-5331CVE
CRLF injection vulnerability in VMware vCenter Server 6.0 before U2 and ESXi 6.0 allows remote …
2016-01-01Pre-auth
EPSS1.9%
pct 77
6.1
CVE-2016-6484CVE
CRLF injection vulnerability in Infoblox Network Automation NetMRI before 7.1.1 allows remote a…
2016-01-01Pre-auth
EPSS1.8%
pct 76
6.5
CVE-2016-9964DEB
redirect() in bottle.py in bottle 0.12.10 doesn't filter a "\r\n" sequence, which leads to a CR…
2016-01-01Pre-auth
EPSS1.8%
pct 75
5.5
CVE-2025-59419ANC
Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.…
2025-01-01Pre-auth
EPSS1.6%
pct 72
6.9
CVE-2025-57804AST
h2 is a pure-Python implementation of a HTTP/2 protocol stack. Prior to version 4.3.0, an HTTP/…
2025-01-01Pre-auth
EPSS1.6%
pct 72
5.3
CVE-2026-23829ANC
Mailpit is an email testing tool and API for developers. Prior to version 1.28.3, Mailpit's SMT…
2026-01-01Pre-auth
EPSS1.4%
pct 69
7.5
CVE-2007-0892CVE
CRLF injection vulnerability in phpMyVisites before 2.2 allows remote attackers to inject arbit…
2007-01-01
EPSS1.4%
pct 68
4.7
CVE-2020-3561CVE
A vulnerability in the Clientless SSL VPN (WebVPN) of Cisco Adaptive Security Appliance (ASA) S…
2020-01-01Pre-auth
EPSS1.3%
pct 65
5.3
CVE-2022-35948DEB
undici is an HTTP/1.1 client, written from scratch for Node.js.`=< undici@5.8.0` users are vuln…
2022-01-01Pre-auth
EPSS1.2%
pct 64
4.9
CVE-2014-9563CVE
CRLF injection vulnerability in the web-based management (WBM) interface in Unify (former Sieme…
2014-01-01
EPSS1.2%
pct 64
6.1
CVE-2017-2111CVE
HTTP header injection vulnerability in TS-WPTCAM firmware version 1.18 and earlier, TS-WPTCAM2 …
2017-01-01Pre-auth
EPSS1.2%
pct 63
7.5
CVE-2018-12477CVE
A Improper Neutralization of CRLF Sequences vulnerability in Open Build Service allows remote a…
2018-01-01Pre-auth
EPSS1.2%
pct 63
7.5
CVE-2023-26130DEB
Versions of the package yhirose/cpp-httplib before 0.12.4 are vulnerable to CRLF Injection when…
2023-01-01Pre-auth
EPSS1.1%
pct 62
6.1
CVE-2014-9564CVE
CRLF injection vulnerability in IBM Flex System EN6131 40Gb Ethernet and IB6131 40Gb Infiniband…
2014-01-01Pre-auth
EPSS1.1%
pct 62
6.5
CVE-2023-23936DEB
Undici is an HTTP/1.1 client for Node.js. Starting with version 2.0.0 and prior to version 5.19…
2023-01-01Pre-auth
EPSS1.1%
pct 62
6.5
CVE-2022-31150DEB
undici is an HTTP/1.1 client, written from scratch for Node.js. It is possible to inject CRLF s…
2022-01-01Pre-auth
EPSS1.1%
pct 61
Select a vulnerability on the left to open the preview.