Solr
Vendor:
First CVE: Oct 28, 2009 · Active for 16 years
47
Total CVEs
More Total CVEs than 97% of tracked products
3.6
Avg CVEs / Year
Higher CVE frequency than 83% of tracked products
7.3
Avg CVSS
Higher Avg CVSS than 46% of tracked products
6.4%
KEV Rate
Higher KEV Rate than 97% of tracked products
Trends Over Time
The number and severity of CVEs published that impact Solr over time
Volume of CVEsAvg CVSS Base Score
First CVE
Oct 28, 2009
16 years ago
Most Recent CVE
Jun 1, 2026
53 days ago
CVE Severity & Scoring
Solr47 CVEs
32%
45%
21%
All CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local2 (4.3%)
Network39 (83.0%)
Unknown6 (12.8%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low39 (83.0%)
High2 (4.3%)
Unknown6 (12.8%)
User Interaction
None37 (78.7%)
Unknown6 (12.8%)
Required4 (8.5%)
Privileges Required
Low13 (27.7%)
High2 (4.3%)
None26 (55.3%)
Unknown6 (12.8%)
Top CVEs
Signals from CVEs in this product scope (47 CVEs).
47 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-17558HIGH Apache Solr 5.0.0 to Apache Solr 8.3.1 are vulnerable to a Remote Code Execution through the VelocityResponseWriter. A Velocity template can be provided through Velocity templates | Dec 30, 2019 | 7.5 | 98 | YES | YES |
CVE-2023-44487HIGH The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through | Oct 10, 2023 | 7.5 | 97 | YES | YES |
CVE-2019-0193HIGH In Apache Solr, the DataImportHandler, an optional but popular module to pull in data from databases and other sources, has a feature in which the whole DIH configuration can come | Aug 1, 2019 | 7.2 | 95 | YES | YES |
CVE-2017-12629CRITICAL Remote code execution occurs in Apache Solr before 7.1 with Apache Lucene before 7.1 by exploiting XXE in conjunction with use of a Config API add-listener command to reach the Run | Oct 14, 2017 | 9.8 | 90 | NO | YES |
CVE-2024-45216CRITICAL Improper Authentication vulnerability in Apache Solr.
Solr instances using the PKIAuthenticationPlugin, which is enabled by default when Solr Authentication is used, are vulnerabl | Oct 16, 2024 | 9.8 | 86 | NO | YES |
CVE-2021-27905CRITICAL The ReplicationHandler (normally registered at "/replication" under a Solr core) in Apache Solr has a "masterUrl" (also "leaderUrl" alias) parameter that is used to designate anoth | Apr 13, 2021 | 9.8 | 86 | NO | YES |
CVE-2023-50386HIGH Improper Control of Dynamically-Managed Code Resources, Unrestricted Upload of File with Dangerous Type, Inclusion of Functionality from Untrusted Control Sphere vulnerability in A | Feb 9, 2024 | 8.8 | 82 | NO | YES |
CVE-2019-0192CRITICAL In Apache Solr versions 5.0.0 to 5.5.5 and 6.0.0 to 6.6.5, the Config API allows to configure the JMX server via an HTTP POST request. By pointing it to a malicious RMI server, an | Mar 7, 2019 | 9.8 | 82 | NO | YES |
CVE-2020-13957CRITICAL Apache Solr versions 6.6.0 to 6.6.6, 7.0.0 to 7.7.3 and 8.0.0 to 8.6.2 prevents some features considered dangerous (which could be used for remote code execution) to be configured | Oct 13, 2020 | 9.8 | 73 | NO | NO |
CVE-2023-50290MEDIUM Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Solr.
The Solr Metrics API publishes all unprotected environment variables available to each Apac | Jan 15, 2024 | 6.5 | 70 | NO | YES |
Exploit Exposure
Signals from CVEs in this product scope (47 CVEs).
CISA KEV
3 CVEs
6.4% of CVEs· 97th percentile
Metasploit
2 CVEs
4.3% of CVEs· 96th percentile
Nuclei
7 CVEs
14.9% of CVEs· 98th percentile
ExploitDB
3 CVEs
6.4% of CVEs· 88th percentile
Social Chatter
Signals from CVEs in this product scope (47 CVEs).
Media Mentions
Signals from CVEs in this product scope (47 CVEs).
Top CNAs Publishing CVEs For Solr
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 8.9 | 1 | 7.5 | 19.4% | 0 | 0 |
| 8.8.1 | 3 | 5.2 | 33.9% | 0 | 0 |
| 8.6.2 | 1 | 8.8 | 4.4% | 0 | 0 |
| 8.6.0 | 1 | 8.8 | 4.4% | 0 | 0 |
| 8.4.1 | 1 | 9.1 | 4.7% | 0 | 0 |
| 8.2.0 | 1 | 9.8 | 21.9% | 0 | 0 |
| 8.1.1 | 1 | 9.8 | 21.9% | 0 | 0 |
| 6.6.0 | 1 | 7.5 | 2.2% | 0 | 0 |
| 6.5.1 | 2 | 7.5 | 3.9% | 0 | 0 |
| 6.5.0 | 2 | 7.5 | 3.9% | 0 | 0 |
| 6.4.2 | 2 | 7.5 | 3.9% | 0 | 0 |
| 6.4.1 | 2 | 7.5 | 3.9% | 0 | 0 |
| 6.4.0 | 3 | 7.5 | 4.8% | 0 | 0 |
| 6.3.0 | 3 | 7.5 | 4.8% | 0 | 0 |
| 6.2.1 | 3 | 7.5 | 4.8% | 0 | 0 |
| 6.2.0 | 3 | 7.5 | 4.8% | 0 | 0 |
| 6.1.0 | 2 | 7.5 | 6.0% | 0 | 0 |
| 6.0.1 | 2 | 7.5 | 6.0% | 0 | 0 |
| 6.0.0 | 2 | 7.5 | 6.0% | 0 | 0 |
| 5.5.4 | 1 | 7.5 | 5.5% | 0 | 0 |