Skip to main content

CWE archive

CWE-444 CVEs

Programmatic archive

354 CVEs tagged with CWE-44464 Critical, 125 High, 149 Medium, 16 Low, 0 Unrated.

CVE-2021-32715

Published Jul 7, 2021

hyper is an HTTP library for rust. hyper's HTTP/1 server code had a flaw that incorrectly parses and accepts requests with a `Content-Length` header with a prefixed plus sign, whe…

CVSS 3.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2021-30180

Published Jun 1, 2021

Apache Dubbo prior to 2.7.9 support Tag routing which will enable a customer to route the request to the right server. These rules are used by the customers when making a request…

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2021-31922

Published May 14, 2021

An HTTP Request Smuggling vulnerability in Pulse Secure Virtual Traffic Manager before 21.1 could allow an attacker to smuggle an HTTP request through an HTTP/2 Header. This vulne…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2021-23339

Published Feb 17, 2021

This affects all versions before 10.1.14 and from 10.2.0 to 10.2.4 of package com.typesafe.akka:akka-http-core. It allows multiple Transfer-Encoding headers.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-23336

Published Feb 15, 2021

The package python/cpython from 0 and before 3.6.13, from 3.7.0 and before 3.7.10, from 3.8.0 and before 3.8.8, from 3.9.0 and before 3.9.2 are vulnerable to Web Cache Poisoning v…

CVSS 5.9 · Medium

CVE-2021-21299

Published Feb 11, 2021

hyper is an open-source HTTP library for Rust (crates.io). In hyper from version 0.12.0 and before versions 0.13.10 and 0.14.3 there is a vulnerability that can enable a request s…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-28483

Published Jan 20, 2021

This affects all versions of package github.com/gin-gonic/gin. When gin is exposed directly to the internet, a client's IP can be spoofed by setting the X-Forwarded-For header.

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2020-28473

Published Jan 18, 2021

The package bottle from 0 and before 0.12.19 are vulnerable to Web Cache Poisoning by using a vector called parameter cloaking. When the attacker can separate query parameters usi…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-21445

Published Jan 12, 2021

SAP Commerce Cloud, versions - 1808, 1811, 1905, 2005, 2011, allows an authenticated attacker to include invalidated data in the HTTP response Content Type header, due to improper…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-17509

Published Jan 11, 2021

ATS negative cache option is vulnerable to a cache poisoning attack. If you have this option enabled, please upgrade or disable this feature. Apache Traffic Server versions 7.0.0…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-35863

Published Dec 31, 2020

An issue was discovered in the hyper crate before 0.12.34 for Rust. HTTP request smuggling can occur. Remote code execution can occur in certain situations with an HTTP server on…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-26281

Published Dec 21, 2020

async-h1 is an asynchronous HTTP/1.1 parser for Rust (crates.io). There is a request smuggling vulnerability in async-h1 before version 2.3.0. This vulnerability affects any webse…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort
Showing 251-275 of 354 CVEsPage 11 of 15