All vulnerabilities
61 / 61
Sort
9.0
CVE-2021-40438AST KEV
A crafted request uri-path can cause mod_proxy to forward the request to an origin server choos…
2021-01-01KEV
EPSS100.0%
pct 100
9.1
CVE-2024-38475ANC KEV
Improper escaping of output in mod_rewrite in Apache HTTP Server 2.4.59 and earlier allows an a…
2024-01-01KEV
EPSS100.0%
pct 99
7.5
CVE-2024-27316ANC
HTTP/2 incoming headers exceeding the limit are temporarily buffered in nghttp2 in order to gen…
2024-01-01Pre-auth
EPSS91.3%
pct 99
9.8
CVE-2020-11984AST
Apache HTTP server 2.4.32 to 2.4.44 mod_proxy_uwsgi info disclosure and possible RCE
2020-01-01Pre-auth
EPSS90.5%
pct 99
5.3
CVE-2024-28182ANC
nghttp2 is an implementation of the Hypertext Transfer Protocol version 2 in C. The nghttp2 lib…
2024-01-01Pre-auth
EPSS85.0%
pct 99
7.5
CVE-2022-0778AST
The BN_mod_sqrt() function, which computes a modular square root, contains a bug that can cause…
2022-01-01Pre-auth
EPSS70.6%
pct 99
8.1
CVE-2021-26691AST
In Apache HTTP Server versions 2.4.0 to 2.4.46 a specially crafted SessionHeader sent by an ori…
2021-01-01Pre-auth
EPSS68.1%
pct 99
7.5
CVE-2021-26690AST
Apache HTTP Server versions 2.4.0 to 2.4.46 A specially crafted Cookie header handled by mod_se…
2021-01-01Pre-auth
EPSS65.1%
pct 99
5.9
CVE-2021-3449DEB
An OpenSSL TLS server may crash if sent a maliciously crafted renegotiation ClientHello message…
2021-01-01Pre-auth
EPSS63.5%
pct 99
7.5
CVE-2021-34798AST
Malformed requests may cause the server to dereference a NULL pointer. This issue affects Apach…
2021-01-01Pre-auth
EPSS62.8%
pct 99
4.8
CVE-2019-17567AST
Apache HTTP Server versions 2.4.6 to 2.4.46 mod_proxy_wstunnel configured on an URL that is not…
2019-01-01Pre-auth
EPSS60.3%
pct 99
8.1
CVE-2021-22901ANC
curl 7.75.0 through 7.76.1 suffers from a use-after-free vulnerability resulting in already fre…
2021-01-01Pre-auth
EPSS60.1%
pct 99
7.5
CVE-2020-11993AST
Apache HTTP Server versions 2.4.20 to 2.4.43 When trace/debug was enabled for the HTTP/2 module…
2020-01-01Pre-auth
EPSS58.7%
pct 98
7.3
CVE-2020-35452AST
Apache HTTP Server versions 2.4.0 to 2.4.46 A specially crafted Digest nonce can cause a stack …
2020-01-01Pre-auth
EPSS53.2%
pct 98
3.7
CVE-2020-1934AST
In Apache HTTP Server 2.4.0 to 2.4.41, mod_proxy_ftp may use uninitialized memory when proxying…
2020-01-01Pre-auth
EPSS52.0%
pct 98
5.9
CVE-2021-30641AST
Apache HTTP Server versions 2.4.39 to 2.4.46 Unexpected matching behavior with 'MergeSlashes OF…
2021-01-01Pre-auth
EPSS51.8%
pct 98
7.5
CVE-2021-23840AST
Calls to EVP_CipherUpdate, EVP_EncryptUpdate and EVP_DecryptUpdate may overflow the output leng…
2021-01-01Pre-auth
EPSS50.7%
pct 98
7.4
CVE-2021-3712AST
ASN.1 strings are represented internally within OpenSSL as an ASN1_STRING structure which conta…
2021-01-01Pre-auth
EPSS50.4%
pct 98
7.5
CVE-2020-13950AST
Apache HTTP Server versions 2.4.41 to 2.4.46 mod_proxy_http can be made to crash (NULL pointer …
2020-01-01Pre-auth
EPSS49.1%
pct 98
9.1
CVE-2024-38476ANC
Vulnerability in core of Apache HTTP Server 2.4.59 and earlier are vulnerably to information di…
2024-01-01Pre-auth
EPSS41.6%
pct 98
7.5
CVE-2024-2398ANC
When an application tells libcurl it wants to allow HTTP/2 server push, and the amount of recei…
2024-01-01Pre-auth
EPSS36.1%
pct 98
7.4
CVE-2024-39573ANC
Potential SSRF in mod_rewrite in Apache HTTP Server 2.4.59 and earlier allows an attacker to ca…
2024-01-01Pre-auth
EPSS35.4%
pct 98
8.3
CVE-2022-22720ANC
Apache HTTP Server 2.4.52 and earlier fails to close inbound connection when errors are encount…
2022-01-01Pre-auth
EPSS28.2%
pct 97
5.3
CVE-2024-38473ANC
Encoding problem in mod_proxy in Apache HTTP Server 2.4.59 and earlier allows request URLs with…
2024-01-01Pre-auth
EPSS25.9%
pct 97
5.3
CVE-2019-0196AST
A vulnerability was found in Apache HTTP Server 2.4.17 to 2.4.38. Using fuzzed network input, t…
2019-01-01Pre-auth
EPSS19.3%
pct 96
7.4
CVE-2021-3450DEB
The X509_V_FLAG_X509_STRICT flag enables additional security checks of the certificates present…
2021-01-01Pre-auth
EPSS18.3%
pct 96
6.3
CVE-2019-5482AST
Heap buffer overflow in the TFTP protocol handler in cURL 7.19.4 to 7.65.3.
2019-01-01
EPSS17.9%
pct 96
3.3
CVE-2019-0220AST
A vulnerability was found in Apache HTTP Server 2.4.0 to 2.4.38. When the path component of a r…
2019-01-01
EPSS17.9%
pct 96
4.8
CVE-2019-1551AST
There is an overflow bug in the x64_64 Montgomery squaring procedure used in exponentiation wit…
2019-01-01Pre-auth
EPSS14.3%
pct 96
6.5
CVE-2020-8285AST
curl 7.21.0 to and including 7.73.0 is vulnerable to uncontrolled recursion due to a stack over…
2020-01-01Pre-auth
EPSS9.9%
pct 94
4.2
CVE-2019-0197AST
A vulnerability was found in Apache HTTP Server 2.4.34 to 2.4.38. When HTTP/2 was enabled for a…
2019-01-01
EPSS8.4%
pct 94
8.6
CVE-2021-3517AST
There is a flaw in the xml entity encoding functionality of libxml2 in versions before 2.9.11. …
2021-01-01Pre-auth
EPSS8.3%
pct 94
7.5
CVE-2020-7595AST
xmlStringLenDecodeEntities in parser.c in libxml2 2.9.10 has an infinite loop in a certain end-…
2020-01-01Pre-auth
EPSS7.8%
pct 93
5.9
CVE-2021-23841AST
The OpenSSL public API function X509_issuer_and_serial_hash() attempts to create a unique hash …
2021-01-01Pre-auth
EPSS7.5%
pct 93
5.7
CVE-2019-5481AST
Double-free vulnerability in the FTP-kerberos code in cURL 7.52.0 to 7.65.3.
2019-01-01
EPSS7.3%
pct 93
5.9
CVE-2020-1971AST
The X.509 GeneralName type is a generic type for representing different types of names. One of …
2020-01-01Pre-auth
EPSS7.2%
pct 93
7.5
CVE-2018-20843AST
In libexpat in Expat before 2.2.7, XML input including XML names that contain a large number of…
2018-01-01Pre-auth
EPSS7.1%
pct 93
7.5
CVE-2019-15903AST
In libexpat before 2.2.8, crafted XML input could fool the parser into changing from DTD parsin…
2019-01-01Pre-auth
EPSS6.6%
pct 93
8.1
CVE-2022-23308AST
valid.c in libxml2 before 2.9.13 has a use-after-free of ID and IDREF attributes.
2022-01-01Pre-auth
EPSS6.0%
pct 92
7.5
CVE-2019-19956AST
xmlParseBalancedChunkMemoryRecover in parser.c in libxml2 before 2.9.10 has a memory leak relat…
2019-01-01Pre-auth
EPSS5.7%
pct 91
Select a vulnerability on the left to open the preview.