Http Server
Vendor:
First CVE: Jul 23, 1997 · Active for 29 years
105
Total CVEs
More Total CVEs than 99% of tracked products
5.0
Avg CVEs / Year
Higher CVE frequency than 87% of tracked products
7.3
Avg CVSS
Higher Avg CVSS than 45% of tracked products
2.9%
KEV Rate
Higher KEV Rate than 96% of tracked products
Trends Over Time
The number and severity of CVEs published that impact Http Server over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jul 23, 1997
29 years ago
Most Recent CVE
Apr 21, 2026
94 days ago
CVE Severity & Scoring
Http Server105 CVEs
30%
44%
20%
All CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local8 (7.6%)
Network71 (67.6%)
Unknown26 (24.8%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low65 (61.9%)
High14 (13.3%)
Unknown26 (24.8%)
User Interaction
None71 (67.6%)
Unknown26 (24.8%)
Required8 (7.6%)
Privileges Required
Low8 (7.6%)
High1 (1.0%)
None70 (66.7%)
Unknown26 (24.8%)
Top CVEs
Signals from CVEs in this product scope (105 CVEs).
105 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-4034HIGH A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool designed to allow unprivileged users to run commands as pri | Jan 28, 2022 | 7.8 | 98 | YES | YES |
CVE-2021-40438CRITICAL A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user. This issue affects Apache HTTP Server 2.4.48 and earlier. | Sep 16, 2021 | 9.0 | 97 | YES | YES |
CVE-2019-0211HIGH In Apache HTTP Server 2.4 releases 2.4.17 to 2.4.38, with MPM event, worker or prefork, code executing in less-privileged child processes or threads (including scripts executed by | Apr 8, 2019 | 7.8 | 93 | YES | YES |
CVE-2010-0425HIGH modules/arch/win32/mod_isapi.c in mod_isapi in the Apache HTTP Server 2.0.37 through 2.0.63, 2.2.0 through 2.2.14, and 2.3.x before 2.3.7, when running on Windows, does not ensure | Mar 5, 2010 | 10.0 | 91 | NO | YES |
CVE-2021-44790CRITICAL A carefully crafted request body can cause a buffer overflow in the mod_lua multipart parser (r:parsebody() called from Lua scripts). The Apache httpd team is not aware of an explo | Dec 20, 2021 | 9.8 | 88 | NO | YES |
CVE-2002-0656HIGH Buffer overflows in OpenSSL 0.9.6d and earlier, and 0.9.7-beta2 and earlier, allow remote attackers to execute arbitrary code via (1) a large client master key in SSL2 or (2) a lar | Aug 12, 2002 | 7.5 | 81 | NO | YES |
CVE-2013-2566MEDIUM The RC4 algorithm, as used in the TLS protocol and SSL protocol, has many single-byte biases, which makes it easier for remote attackers to conduct plaintext-recovery attacks via s | Mar 15, 2013 | 5.9 | 80 | NO | YES |
CVE-2014-0226MEDIUM Race condition in the mod_status module in the Apache HTTP Server before 2.4.10 allows remote attackers to cause a denial of service (heap-based buffer overflow), or possibly obtai | Jul 20, 2014 | 6.8 | 75 | NO | YES |
CVE-2021-44224HIGH A crafted URI sent to httpd configured as a forward proxy (ProxyRequests on) can cause a crash (NULL pointer dereference) or, for configurations mixing forward and reverse proxy de | Dec 20, 2021 | 8.2 | 72 | NO | NO |
CVE-2022-22719HIGH A carefully crafted request body can cause a read to a random memory area which could cause the process to crash. This issue affects Apache HTTP Server 2.4.52 and earlier. | Mar 14, 2022 | 7.5 | 65 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (105 CVEs).
CISA KEV
3 CVEs
2.9% of CVEs· 96th percentile
Metasploit
3 CVEs
2.9% of CVEs· 96th percentile
Nuclei
1 CVE
1.0% of CVEs· 96th percentile
ExploitDB
9 CVEs
8.6% of CVEs· 89th percentile
Social Chatter
Signals from CVEs in this product scope (105 CVEs).
Media Mentions
Signals from CVEs in this product scope (105 CVEs).
Top CNAs Publishing CVEs For Http Server
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 9.2.0.8 | 1 | 7.5 | 2.4% | 0 | 0 |
| 9.2.0.7 | 6 | 9.1 | 2.4% | 0 | 0 |
| 9.2.0 | 6 | 6.2 | 33.7% | 0 | 3 |
| 9.1 | 1 | 7.5 | 6.8% | 0 | 0 |
| 9.0.3.1 | 1 | 7.5 | 6.8% | 0 | 0 |
| 9.0.2.3 | 1 | 7.5 | 6.8% | 0 | 0 |
| 9.0.2 | 1 | 7.5 | 6.8% | 0 | 0 |
| 9.0.1.5 | 3 | 5.2 | 1.7% | 0 | 0 |
| 9.0.1 | 6 | 6.2 | 33.7% | 0 | 3 |
| 8.1.7 | 3 | 5.6 | 22.7% | 0 | 1 |
| 2.1 | 1 | 5.0 | 2.1% | 0 | 0 |
| 14.1.2.0.0 | 2 | 9.3 | 21.5% | 0 | 0 |
| 14.1.1.0.0 | 1 | 10.0 | 42.7% | 0 | 0 |
| 12.2.1.4.0 | 58 | 7.9 | 18.1% | 2 | 3 |
| 12.2.1.3.0 | 59 | 7.8 | 17.0% | 3 | 4 |
| 12.2.1.2.0 | 4 | 5.5 | 40.7% | 0 | 1 |
| 12.2.1.2 | 1 | 5.9 | 2.1% | 0 | 0 |
| 12.2.1.1.0 | 2 | 4.8 | 79.1% | 0 | 1 |
| 12.1.3.0.0 | 6 | 5.4 | 27.4% | 0 | 1 |
| 12.1.3.0 | 8 | 5.7 | 29.4% | 0 | 1 |