PoC Archive PoC Archive

tag

Crlf-Injection

Oracle E-Business Suite Pre-Authentication RCE Chain (CVE-2025-61882) KEV RW EPSS 100%
CVE-2025-61882 (Oracle Security Alert, out-of-band, October 2025) web Patched
CVE-2025-61882webCRITICAL 9.8Patched2026-08-09pgAdmin 4 Restore Feature Regex-Bypass Command Injection RCE (CVE-2025-13780)
CVE-2025-13780 web Unverified
CVE-2025-13780webCRITICAL 9.1Unverified2026-07-06CRLF Email Header Injection in Plunk via Raw MIME Construction (CVE-2026-34975)
CVE-2026-34975 web Patched
CVE-2026-34975webHIGH 8.5Patched2026-07-05Apache APISIX forward-auth CRLF Header Injection — CVE-2026-31908
CVE-2026-31908 web Patched
CVE-2026-31908webCRITICAL 10Patched2026-07-05curl SMTP EXPN Recipient CRLF Command Injection
None assigned as of 2026-07-03 network Unverified
None assigned as of 2026-07-03networkMEDIUMUnverified2026-07-03cPanel & WHM Authentication Bypass via Session-File CRLF Injection (CVE-2026-41940) KEV RW EPSS 99%
CVE-2026-41940 web Patched
CVE-2026-41940webCRITICAL 10Patched2026-05-16