Http Server

Vendor:

First CVE: Jul 23, 1997 · Active for 29 years

105
Total CVEs
More Total CVEs than 99% of tracked products
5.0
Avg CVEs / Year
Higher CVE frequency than 87% of tracked products
7.3
Avg CVSS
Higher Avg CVSS than 45% of tracked products
2.9%
KEV Rate
Higher KEV Rate than 96% of tracked products

Trends Over Time

The number and severity of CVEs published that impact Http Server over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jul 23, 1997
29 years ago
Most Recent CVE
Apr 21, 2026
94 days ago

CVE Severity & Scoring

Http Server105 CVEs
All CVEs352,294 CVEs
LowMediumHighCritical
Attack Vector
Local8 (7.6%)
Network71 (67.6%)
Unknown26 (24.8%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low65 (61.9%)
High14 (13.3%)
Unknown26 (24.8%)
User Interaction
None71 (67.6%)
Unknown26 (24.8%)
Required8 (7.6%)
Privileges Required
Low8 (7.6%)
High1 (1.0%)
None70 (66.7%)
Unknown26 (24.8%)

Top CVEs

Signals from CVEs in this product scope (105 CVEs).

105 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool designed to allow unprivileged users to run commands as pri
Jan 28, 20227.898YESYES
A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user. This issue affects Apache HTTP Server 2.4.48 and earlier.
Sep 16, 20219.097YESYES
In Apache HTTP Server 2.4 releases 2.4.17 to 2.4.38, with MPM event, worker or prefork, code executing in less-privileged child processes or threads (including scripts executed by
Apr 8, 20197.893YESYES
modules/arch/win32/mod_isapi.c in mod_isapi in the Apache HTTP Server 2.0.37 through 2.0.63, 2.2.0 through 2.2.14, and 2.3.x before 2.3.7, when running on Windows, does not ensure
Mar 5, 201010.091NOYES
A carefully crafted request body can cause a buffer overflow in the mod_lua multipart parser (r:parsebody() called from Lua scripts). The Apache httpd team is not aware of an explo
Dec 20, 20219.888NOYES
Buffer overflows in OpenSSL 0.9.6d and earlier, and 0.9.7-beta2 and earlier, allow remote attackers to execute arbitrary code via (1) a large client master key in SSL2 or (2) a lar
Aug 12, 20027.581NOYES
The RC4 algorithm, as used in the TLS protocol and SSL protocol, has many single-byte biases, which makes it easier for remote attackers to conduct plaintext-recovery attacks via s
Mar 15, 20135.980NOYES
Race condition in the mod_status module in the Apache HTTP Server before 2.4.10 allows remote attackers to cause a denial of service (heap-based buffer overflow), or possibly obtai
Jul 20, 20146.875NOYES
A crafted URI sent to httpd configured as a forward proxy (ProxyRequests on) can cause a crash (NULL pointer dereference) or, for configurations mixing forward and reverse proxy de
Dec 20, 20218.272NONO
A carefully crafted request body can cause a read to a random memory area which could cause the process to crash. This issue affects Apache HTTP Server 2.4.52 and earlier.
Mar 14, 20227.565NONO

Exploit Exposure

Signals from CVEs in this product scope (105 CVEs).

CISA KEV
3 CVEs
2.9% of CVEs· 96th percentile
Metasploit
3 CVEs
2.9% of CVEs· 96th percentile
Nuclei
1 CVE
1.0% of CVEs· 96th percentile
ExploitDB
9 CVEs
8.6% of CVEs· 89th percentile

Social Chatter

Signals from CVEs in this product scope (105 CVEs).

Media Mentions

Signals from CVEs in this product scope (105 CVEs).

Top CNAs Publishing CVEs For Http Server

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
9.2.0.817.52.4%00
9.2.0.769.12.4%00
9.2.066.233.7%03
9.117.56.8%00
9.0.3.117.56.8%00
9.0.2.317.56.8%00
9.0.217.56.8%00
9.0.1.535.21.7%00
9.0.166.233.7%03
8.1.735.622.7%01
2.115.02.1%00
14.1.2.0.029.321.5%00
14.1.1.0.0110.042.7%00
12.2.1.4.0587.918.1%23
12.2.1.3.0597.817.0%34
12.2.1.2.045.540.7%01
12.2.1.215.92.1%00
12.2.1.1.024.879.1%01
12.1.3.0.065.427.4%01
12.1.3.085.729.4%01