Http Server
Vendor:
First CVE: May 31, 2000 · Active for 26 years
22
Total CVEs
More Total CVEs than 94% of tracked products
2.2
Avg CVEs / Year
Higher CVE frequency than 73% of tracked products
7.5
Avg CVSS
Higher Avg CVSS than 49% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Http Server over time
Volume of CVEsAvg CVSS Base Score
First CVE
May 31, 2000
26 years ago
Most Recent CVE
May 26, 2026
60 days ago
CVE Severity & Scoring
Http Server22 CVEs
27%
64%
9%
All CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network8 (36.4%)
Unknown12 (54.5%)
Physical0 (0.0%)
Adjacent Network2 (9.1%)
Attack Complexity
Low9 (40.9%)
High1 (4.5%)
Unknown12 (54.5%)
User Interaction
None10 (45.5%)
Unknown12 (54.5%)
Required0 (0.0%)
Privileges Required
Low2 (9.1%)
High0 (0.0%)
None8 (36.4%)
Unknown12 (54.5%)
Top CVEs
Signals from CVEs in this product scope (22 CVEs).
22 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2010-0425HIGH modules/arch/win32/mod_isapi.c in mod_isapi in the Apache HTTP Server 2.0.37 through 2.0.63, 2.2.0 through 2.2.14, and 2.3.x before 2.3.7, when running on Windows, does not ensure | Mar 5, 2010 | 10.0 | 91 | NO | YES |
CVE-2004-0493MEDIUM The ap_get_mime_headers_core function in Apache httpd 2.0.49 allows remote attackers to cause a denial of service (memory exhaustion), and possibly an integer signedness error lead | Aug 6, 2004 | 6.4 | 72 | NO | YES |
CVE-2000-0505MEDIUM The Apache 1.3.x HTTP server for Windows platforms allows remote attackers to list directory contents by requesting a URL containing a large number of / characters. | May 31, 2000 | 5.0 | 45 | NO | YES |
CVE-2004-0492HIGH Heap-based buffer overflow in proxy_util.c for mod_proxy in Apache 1.3.25 to 1.3.31 allows remote attackers to cause a denial of service (process crash) and possibly execute arbitr | Aug 6, 2004 | 10.0 | 41 | NO | NO |
CVE-2026-8855CRITICAL IBM HTTP Server 8.5, and 9.0 is vulnerable to remote code execution and denial of service in configurations with TLS mutual authentication (client authentication). | May 26, 2026 | 9.8 | 39 | NO | NO |
CVE-2026-8856CRITICAL IBM HTTP Server 8.5, and 9.0 is vulnerable to denial of service in configurations where an attacker has write access to parts of the server configuration. | May 26, 2026 | 9.1 | 36 | NO | NO |
CVE-2026-9170HIGH IBM HTTP Server 8.5, and 9.0 is vulnerable to denial of service and a potential remote code execution due to improper input validation. | May 26, 2026 | 7.5 | 33 | NO | NO |
CVE-2012-5955HIGH Unspecified vulnerability in the IBM HTTP Server component 5.3 in IBM WebSphere Application Server (WAS) for z/OS allows remote attackers to execute arbitrary commands via unknown | Dec 20, 2012 | 10.0 | 33 | NO | NO |
CVE-2026-8854HIGH IBM HTTP Server 8.5, and 9.0 is vulnerable to denial of service via the optional module mod_mem_cache. | May 26, 2026 | 7.5 | 32 | NO | NO |
CVE-2026-8834HIGH IBM HTTP Server 8.5, and 9.0 contains a buffer overflow vulnerability. A privileged user, authenticated to the Administration Server, could exploit this vulnerability to execute re | May 26, 2026 | 8.0 | 31 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (22 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
4.5% of CVEs· 96th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
4 CVEs
18.2% of CVEs· 89th percentile
Social Chatter
Signals from CVEs in this product scope (22 CVEs).
Media Mentions
Signals from CVEs in this product scope (22 CVEs).
Top CNAs Publishing CVEs For Http Server
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 9.0.0.0 | 1 | 7.5 | 0.5% | 0 | 0 |
| 8.5.0.0 | 2 | 7.5 | 0.8% | 0 | 0 |
| 6.1.0.9 | 1 | 10.0 | 94.3% | 0 | 1 |
| 6.1.0.7 | 1 | 10.0 | 94.3% | 0 | 1 |
| 6.1.0.5 | 1 | 10.0 | 94.3% | 0 | 1 |
| 6.1.0.3 | 1 | 10.0 | 94.3% | 0 | 1 |
| 6.1.0.29 | 1 | 10.0 | 94.3% | 0 | 1 |
| 6.1.0.27 | 1 | 10.0 | 94.3% | 0 | 1 |
| 6.1.0.25 | 1 | 10.0 | 94.3% | 0 | 1 |
| 6.1.0.23 | 1 | 10.0 | 94.3% | 0 | 1 |
| 6.1.0.21 | 1 | 10.0 | 94.3% | 0 | 1 |
| 6.1.0.2 | 1 | 10.0 | 94.3% | 0 | 1 |
| 6.1.0.19 | 1 | 10.0 | 94.3% | 0 | 1 |
| 6.1.0.17 | 1 | 10.0 | 94.3% | 0 | 1 |
| 6.1.0.15 | 1 | 10.0 | 94.3% | 0 | 1 |
| 6.1.0.13 | 1 | 10.0 | 94.3% | 0 | 1 |
| 6.1.0.11 | 1 | 10.0 | 94.3% | 0 | 1 |
| 6.1 | 1 | 10.0 | 94.3% | 0 | 1 |
| 6.0.2.9 | 1 | 10.0 | 94.3% | 0 | 1 |
| 6.0.2.7 | 1 | 10.0 | 94.3% | 0 | 1 |