Skip to main content

CWE archive

CWE-93 CVEs

Programmatic archive

195 CVEs tagged with CWE-9310 Critical, 54 High, 121 Medium, 10 Low, 0 Unrated.

CVE-2026-15157

Published Jul 29, 2026

undici does not validate the type property of a duck-typed blob-like request body before using it as the Content-Type header on the HTTP/1.1 dispatcher. In undici before 6.28.0, f…

CVSS 4.2 · Medium
evidence mentions
2
Buzz score
21.0

CVE-2026-12357

Published Jul 29, 2026

Heimdall Data Database Proxy generateFileContent CRLF Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affect…

CVSS 7.2 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-59920

Published Jul 29, 2026

Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.136.Final and 4.2.16.Final, Netty's STOMP encoder ( StompSubframeEncoder ) does not…

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-59919

Published Jul 29, 2026

Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.136.Final and 4.2.16.Final, Netty's HAProxy encoder ( HAProxyMessageEncoder ) writes…

CVSS 5.5 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-59921

Published Jul 28, 2026

Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Final and 4.2.16.Final, HttpPostRequestEncoder constructs multipart HTTP request bo…

CVSS 5.7 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-57511

Published Jul 28, 2026

SuperPlane before 0.30.0 contains an SMTP header injection vulnerability that allows unauthenticated attackers to inject arbitrary SMTP headers by including CRLF sequences in the…

CVSS 6.3 · Medium
evidence mentions
4
Buzz score
22.6

CVE-2026-16313

Published Jul 28, 2026

A flaw was found in sg3_utils. The sg_inq command, when invoked with the --export option, outputs device identification data without sanitizing control characters in SCSI name str…

CVSS 7.6 · High
evidence mentions
3
Buzz score
25.4

CVE-2026-45070

Published Jul 14, 2026

Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.40, 7.4.12, and 8.0.12, Symfony\Component\Mime\Header\Parame…

CVSS 6.3 · Medium
evidence mentions
6
Buzz score
24.5
Vendor/product tagsBeta · best-effort

CVE-2026-45067

Published Jul 14, 2026

### Description `Symfony\Component\Mime\Address` is the value-object every Symfony Mailer address (to/cc/bcc/from/reply-to) flows through; its constructor is documented as valida…

CVSS 6.3 · Medium
evidence mentions
6
Buzz score
24.5

CVE-2026-15429

Published Jul 14, 2026

A privilege escalation vulnerability exists in the HTTP authentication component in Archer VX1800v v1. Improper handling of user-controlled input may allow newline characters to b…

CVSS 5.1 · Medium
evidence mentions
2
Buzz score
16.0

CVE-2026-50188

Published Jul 9, 2026

Kirby is an open-source content management system. Prior to 4.9.4 and 5.4.4, Kirby sites and plugins using the Kirby Http Remote class, including Remote::request(), Remote::get(),…

CVSS 6.9 · Medium
evidence mentions
5
Buzz score
22.9

CVE-2026-12127

Published Jul 1, 2026

The WPForms – Easy Form Builder for WordPress – Contact Forms, Payment Forms, Surveys, & More plugin for WordPress is vulnerable to Improper Neutralization of CRLF Sequences ('CRL…

CVSS 5.3 · Medium
evidence mentions
12
Buzz score
37.1

CVE-2026-57281

Published Jun 24, 2026

Jenkins Script Security Plugin 1402.v94c9ce464861 and earlier does not reject Groovy AST transformation annotations carrying an extensions member, allowing attackers able to run s…

CVSS 7.5 · High
evidence mentions
4
Buzz score
29.1
Vendor/product tagsBeta · best-effort

CVE-2026-55766

Published Jun 23, 2026

guzzlehttp/psr7 is a PSR-7 HTTP message library implementation in PHP. Prior to 2.12.1, guzzlehttp/psr7 did not reject CR/LF characters in certain first-party HTTP start-line fiel…

CVSS 4.8 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-55603

Published Jun 22, 2026

http-proxy-middleware is node.js http-proxy middleware. From 3.0.4 until 3.0.7 and 4.1.1, fixRequestBody() is the library's documented helper for re-emitting a request body that w…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-47242

Published Jun 22, 2026

Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. Prior to 0.6.5 and 0.5.15, when Net::IMAP#id is called with a hash argument, although th…

CVSS 5.8 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-47240

Published Jun 22, 2026

Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. Prior to 0.6.5 and 0.5.15, several Net::IMAP commands accept a "raw data" argument that…

CVSS 5.8 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-50269

Published Jun 22, 2026

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.0, attacker-controlled input included into multipart/payload headers can be used to m…

CVSS 2.7 · Low
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2026-11373

Published Jun 22, 2026

Net::Statsite::Client versions through 1.1.0 for Perl allow metric injections. Net::Statsite::Client is a client for the statsite protocol, which is a variant of statsd. Newline…

CVSS 9.1 · Critical
evidence mentions
6
Buzz score
39.5

CVE-2026-9679

Published Jun 17, 2026

Impact: undici's cookie parser in parseSetCookie percent-decodes cookie values via qsUnescape, turning encoded sequences like %0D%0A, %00, %3B, and %3D into their literal byte equ…

CVSS 5.9 · Medium
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-12143

Published Jun 12, 2026

form-data is a library for creating readable multipart/form-data streams. In versions through 4.0.5, the `field` argument to `FormData#append` and the `filename` option are concat…

CVSS 8.7 · High
evidence mentions
31
Buzz score
50.0

CVE-2026-50629

Published Jun 12, 2026

The 'clientId' parameter from incoming HTTP requests is directly concatenated into OAuth2 server log warning messages without sanitizing control characters. This allows an attacke…

CVSS 5.3 · Medium
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-49214

Published Jun 11, 2026

guzzlehttp/psr7 is a PSR-7 HTTP message library implementation in PHP. Versions prior to 2.10.2 did not reject ASCII control characters, whitespace, or DEL in first-party URI host…

CVSS 5.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-50639

Published Jun 10, 2026

Metrics::Any::Adapter::SignalFx versions before 0.04 for Perl does not protect against metric injections. The statsd protocol (and extensions such as dogstatsd) allow mutiple met…

CVSS 6.5 · Medium
evidence mentions
4
Buzz score
26.1
Vendor/product tagsBeta · best-effort

CVE-2026-50638

Published Jun 10, 2026

Metrics::Any::Adapter::DogStatsd versions before 0.04 for Perl does not protect against metric injections. The statsd protocol (and extensions such as dogstatsd) allow mutiple me…

CVSS 9.1 · Critical
evidence mentions
4
Buzz score
26.1
Vendor/product tagsBeta · best-effort
Showing 1-25 of 195 CVEsPage 1 of 8