Skip to main content

CWE archive

CWE-644 CVEs

Programmatic archive

58 CVEs tagged with CWE-6444 Critical, 12 High, 37 Medium, 5 Low, 0 Unrated.

CVE-2026-21762

Published Jul 17, 2026

HCL DevOps Loop is affected by missing HTTP security headers. Missing security headers may reduce browser protections against common web-based attacks such as clickjacking, MIME-t…

CVSS 3.7 · Low
evidence mentions
1
Buzz score
11.9

CVE-2026-54477

Published Jul 3, 2026

The admin panel lacks standard security headers, enabling clickjacking and cross-site scripting attacks.

CVSS 5.1 · Medium
evidence mentions
3
Buzz score
28.9

CVE-2026-55791

Published Jul 2, 2026

Craft CMS is a content management system (CMS). Versions 4.0.0-RC1 and above, prior to 4.18.0 and 5.0.0-RC1, and above, prior to 5.10.0, are vulnerable to Server-Side Request Forg…

CVSS 6.9 · Medium
evidence mentions
2
Buzz score
16.0

CVE-2024-51454

Published Jun 22, 2026

IBM Engineering Workflow Management 7.0.2 through 7.0.2 Interim Fix 035, 7.0.3 through 7.0.3 Interim Fix 017, and 7.1 through 7.1 Interim Fix 004 is vulnerable to HTTP header inje…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2026-10836

Published Jun 17, 2026

Improper handling of HTTP headers that allows a remote attacker to manipulate the value of the Host header using specially crafted requests. A successful exploit could result in t…

CVSS 5.1 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-4096

Published Jun 11, 2026

IBM DevOps Plan 3.0.0 through 3.0.6 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. This could allow an attacker to conduct var…

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-48126

Published May 26, 2026

Algernon is a small self-contained pure-Go web server. Prior to 1.17.8, when algernon is started with --domain (or --letsencrypt, which silently turns on --domain at engine/flags.…

CVSS 8.2 · High
evidence mentions
1
Buzz score
11.9

CVE-2025-66485

Published Apr 1, 2026

IBM Aspera Shares 1.9.9 through 1.11.0 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers.  This could allow an attacker to conduct…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2026-33149

Published Mar 26, 2026

Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. Versions up to and including 2.5.3 set ALLOWED_HOSTS = '*' by default, which c…

CVSS 8.1 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-13213

Published Mar 10, 2026

IBM Aspera Orchestrator 3.0.0 through 4.1.2 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. This could allow an attacker to con…

CVSS 5.4 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-36227

Published Mar 10, 2026

IBM Aspera Faspex 5 5.0.0 through 5.0.14.3 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers.  This could allow an attacker to con…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-70948

Published Mar 5, 2026

A host header injection vulnerability in the mailer component of @perfood/couch-auth v0.26.0 allows attackers to obtain reset tokens and execute an account takeover via spoofing t…

CVSS 9.3 · Critical

CVE-2026-1698

Published Feb 26, 2026

A HTTP Host header attack vulnerability affects WebClient and the WebScheduler web apps of PcVue in version 15.0.0 through 16.3.3 included, allowing a remote attacker to inject ha…

CVSS 5.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-26747

Published Feb 20, 2026

A Host Header Poisoning vulnerability exists in Monica 4.1.2 due to improper handling of the HTTP Host header in app/Providers/AppServiceProvider.php, combined with the default mi…

CVSS 9.1 · Critical
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2025-27901

Published Feb 17, 2026

IBM DB2 Recovery Expert for LUW 5.5 Interim Fix 002 IBM Db2 Recovery Expert for Linux, UNIX and Windows is vulnerable to HTTP header injection, caused by improper validation of in…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-51451

Published Feb 4, 2026

IBM Concert 1.0.0 through 2.1.0 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. This could allow an attacker to conduct variou…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-52660

Published Jan 19, 2026

HCL AION is affected by an Unrestricted File Upload vulnerability. This can allow malicious file uploads, potentially resulting in unauthorized code execution or system compromise.

CVSS 2.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-64425

Published Jan 5, 2026

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. In Coolify versions up to and including v4.0.0-beta.434, an attacker can initia…

CVSS 8.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-67724

Published Dec 12, 2025

Tornado is a Python web framework and asynchronous networking library. In versions 6.5.2 and below, the supplied reason phrase is used unescaped in HTTP headers (where it could be…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-13803

Published Dec 1, 2025

A vulnerability was identified in MediaCrush 1.0.0/1.0.1. The affected element is an unknown function of the file /mediacrush/paths.py of the component Header Handler. Such manipu…

CVSS 6.9 · Medium
evidence mentions
4
Buzz score
22.6

CVE-2025-13434

Published Nov 20, 2025

A weakness has been identified in jameschz Hush Framework 2.0. The impacted element is an unknown function of the file Hush\hush-lib\hush\Util.php of the component HTTP Host Heade…

CVSS 5.5 · Medium
evidence mentions
4
Buzz score
27.1
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2025-36223

Published Nov 12, 2025

IBM OpenPages 9.0 and 9.1 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. This could allow an attacker to conduct various attac…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-25 of 58 CVEsPage 1 of 3