Risk score: 100/100 · 51 open port(s) · 180 CVE(s)
First seen 2026-08-15 · last seen 2026-08-15
Open ports
Port
Service
Software
CVEs
21
tls
EIG Embedded Web Server
0
22
ssh
OpenSSH
17
23
0
25
0
53
tls
0
80
http
Jetty(6.1.12.rc2)
0
102
tls
Linux UPnP
0
110
tls
WebLogic Server 10.3.6.0.0
0
111
tls
WebLogic Server 10.3.6.0.0
0
135
tls
GlassFish
0
139
tls
Boa
0
143
0
443
http
Apache HTTP Server
1
445
tls
0
502
modbus
0
587
http
Apache
0
789
tls
Boa
0
993
http
Apache HTTP Server
0
995
tls
0
1433
tls
0
CVEs (180)
CVE-2006-4924high · CVSS 7.8 — sshd in OpenSSH before 4.4, when using the version 1 SSH protocol, allows remote attackers to cause a denial of service (CPU consumption) vi
CVE-2006-5052medium · CVSS 5.0 — Unspecified vulnerability in portable OpenSSH before 4.4, when running on some platforms, allows remote attackers to determine the validity
CVE-2007-2243medium · CVSS 5.0 — OpenSSH 4.6 and earlier, when ChallengeResponseAuthentication is enabled, allows remote attackers to determine the existence of user account
CVE-2007-4752high · CVSS 7.5 — ssh in OpenSSH before 4.7 does not properly handle when an untrusted cookie cannot be created and uses a trusted X11 cookie instead, which a
CVE-2008-3259low · CVSS 1.2 — OpenSSH before 5.1 sets the SO_REUSEADDR socket option when the X11UseLocalhost configuration setting is disabled, which allows local users
CVE-2008-4109medium · CVSS 5.0 — A certain Debian patch for OpenSSH before 4.3p2-9etch3 on etch; before 4.6p1-1 on sid and lenny; and on other distributions such as SUSE use
CVE-2010-4478critical · CVSS 9.8 — OpenSSH 5.6 and earlier, when J-PAKE is enabled, does not properly validate the public parameters in the J-PAKE protocol, which allows remot
CVE-2010-4755medium · CVSS 4.0 — The (1) remote_glob function in sftp-glob.c and the (2) process_put function in sftp.c in OpenSSH 5.8 and earlier, as used in FreeBSD 7.3 an
CVE-2012-0814medium · CVSS 6.5 — The auth_parse_options function in auth-options.c in sshd in OpenSSH before 5.7 provides debug messages containing authorized_keys command o
CVE-2011-5000low · CVSS 3.5 — The ssh_gssapi_parse_ename function in gss-serv.c in OpenSSH 5.8 and earlier, when gssapi-with-mic authentication is enabled, allows remote
CVE-2010-5107high · CVSS 7.5 — The default configuration of OpenSSH through 6.1 enforces a fixed time limit between establishing a TCP connection and completing a login, w
CVE-2011-4327medium · CVSS 5.5 — ssh-keysign.c in ssh-keysign in OpenSSH before 5.8p2 on certain platforms executes ssh-rand-helper with unintended open file descriptors, wh
CVE-2014-2532medium · CVSS 4.2 — sshd in OpenSSH before 6.6 does not properly support wildcards on AcceptEnv lines in sshd_config, which allows remote attackers to bypass in
CVE-2014-2653medium · CVSS 6.5 — The verify_host_key function in sshconnect.c in the client in OpenSSH 6.6 and earlier allows remote servers to trigger the skipping of SSHFP
CVE-2020-15778high · CVSS 7.4 — scp in OpenSSH through 8.3p1 allows command injection in the scp.c toremote function, as demonstrated by backtick characters in the destinat
CVE-2023-38408critical · CVSS 9.8 — The PKCS#11 feature in ssh-agent in OpenSSH before 9.3p2 has an insufficiently trustworthy search path, leading to remote code execution if
CVE-2024-6387high · CVSS 8.1 — A security regression (CVE-2006-5051) was discovered in OpenSSH's server (sshd). There is a race condition which can lead sshd to handle som
CVE-2011-4969medium · CVSS 4.3 — Cross-site scripting (XSS) vulnerability in jQuery before 1.6.3, when using location.hash to select elements, allows remote attackers to inj
CVE-2005-4836high · CVSS 7.8 — The HTTP/1.1 connector in Apache Tomcat 4.1.15 through 4.1.40 does not reject NULL bytes in a URL when allowLinking is configured, which all
CVE-2006-7196medium · CVSS 4.3 — Cross-site scripting (XSS) vulnerability in the calendar application example in Apache Tomcat 4.0.0 through 4.0.6, 4.1.0 through 4.1.31, 5.0
CVE-2007-1358low · CVSS 2.6 — Cross-site scripting (XSS) vulnerability in certain applications using Apache Tomcat 4.0.0 through 4.0.6 and 4.1.0 through 4.1.34 allows rem
CVE-2007-2449medium · CVSS 4.3 — Multiple cross-site scripting (XSS) vulnerabilities in certain JSP files in the examples web application in Apache Tomcat 4.0.0 through 4.0.
CVE-2007-5461low · CVSS 3.5 — Absolute path traversal vulnerability in Apache Tomcat 4.0.0 through 4.0.6, 4.1.0, 5.0.0, 5.5.0 through 5.5.25, and 6.0.0 through 6.0.14, un
CVE-2008-2370medium · CVSS 5.0 — Apache Tomcat 4.1.0 through 4.1.37, 5.5.0 through 5.5.26, and 6.0.0 through 6.0.16, when a RequestDispatcher is used, performs path normaliz
CVE-2008-3271medium · CVSS 4.3 — Apache Tomcat 5.5.0 and 4.1.0 through 4.1.31 allows remote attackers to bypass an IP address restriction and obtain sensitive information vi
CVE-2009-0781medium · CVSS 4.3 — Cross-site scripting (XSS) vulnerability in jsp/cal/cal2.jsp in the calendar application in the examples web application in Apache Tomcat 4.
CVE-2008-5519low · CVSS 2.6 — The JK Connector (aka mod_jk) 1.2.0 through 1.2.26 in Apache Tomcat allows remote attackers to obtain sensitive information via an arbitrary
CVE-2009-0033medium · CVSS 5.0 — Apache Tomcat 4.1.0 through 4.1.39, 5.5.0 through 5.5.27, and 6.0.0 through 6.0.18, when the Java AJP connector and mod_jk load balancing ar
CVE-2009-0580medium · CVSS 4.3 — Apache Tomcat 4.1.0 through 4.1.39, 5.5.0 through 5.5.27, and 6.0.0 through 6.0.18, when FORM authentication is used, allows remote attacker
CVE-2008-5515medium · CVSS 5.0 — Apache Tomcat 4.1.0 through 4.1.39, 5.5.0 through 5.5.27, 6.0.0 through 6.0.18, and possibly earlier versions normalizes the target pathname
CVE-2009-3548high · CVSS 7.5 — The Windows installer for Apache Tomcat 6.0.0 through 6.0.20, 5.5.0 through 5.5.28, and possibly earlier versions uses a blank default passw
CVE-2013-6357medium · CVSS 6.8 — Cross-site request forgery (CSRF) vulnerability in the Manager application in Apache Tomcat 5.5.25 and earlier allows remote attackers to hi
CVE-2013-4286medium · CVSS 5.8 — Apache Tomcat before 6.0.39, 7.x before 7.0.47, and 8.x before 8.0.0-RC3, when an HTTP connector or AJP connector is used, does not properly
CVE-2013-4322medium · CVSS 4.3 — Apache Tomcat before 6.0.39, 7.x before 7.0.50, and 8.x before 8.0.0-RC10 processes chunked transfer coding without properly handling (1) a
CVE-2013-4590medium · CVSS 4.3 — Apache Tomcat before 6.0.39, 7.x before 7.0.50, and 8.x before 8.0.0-RC10 allows attackers to obtain "Tomcat internals" information by lever
CVE-2014-0075medium · CVSS 5.0 — Integer overflow in the parseChunkHeader function in java/org/apache/coyote/http11/filters/ChunkedInputFilter.java in Apache Tomcat before 6
CVE-2014-0096medium · CVSS 4.3 — java/org/apache/catalina/servlets/DefaultServlet.java in the default servlet in Apache Tomcat before 6.0.40, 7.x before 7.0.53, and 8.x befo
CVE-2014-0099medium · CVSS 4.3 — Integer overflow in java/org/apache/tomcat/util/buf/Ascii.java in Apache Tomcat before 6.0.40, 7.x before 7.0.53, and 8.x before 8.0.4, when
CVE-2014-0119medium · CVSS 4.3 — Apache Tomcat before 6.0.40, 7.x before 7.0.54, and 8.x before 8.0.6 does not properly constrain the class loader that accesses the XML pars
CVE-2013-4444medium · CVSS 6.8 — Unrestricted file upload vulnerability in Apache Tomcat 7.x before 7.0.40, in certain situations involving outdated java.io.File code and a
CVE-2016-8735critical · CVSS 9.8 — Remote code execution is possible with Apache Tomcat before 6.0.48, 7.x before 7.0.73, 8.x before 8.0.39, 8.5.x before 8.5.7, and 9.x before
CVE-2025-24813critical · CVSS 9.8 — Path Equivalence: 'file.Name' (Internal Dot) leading to Remote Code Execution and/or Information disclosure and/or malicious content added t
CVE-2006-1015medium · CVSS 6.4 — Argument injection vulnerability in certain PHP 3.x, 4.x, and 5.x applications, when used with sendmail and when accepting remote input for
CVE-2006-1017critical · CVSS 9.3 — The c-client library 2000, 2001, or 2004 for PHP before 4.4.4 and 5.x before 5.1.5 do not check the (1) safe_mode or (2) open_basedir functi
CVE-2006-1490medium · CVSS 5.0 — PHP before 5.1.3-RC1 might allow remote attackers to obtain portions of memory via crafted binary data sent to a script that processes user
CVE-2006-0996medium · CVSS 4.3 — Cross-site scripting (XSS) vulnerability in phpinfo (info.c) in PHP 5.1.2 and 4.4.2 allows remote attackers to inject arbitrary web script o
CVE-2006-1494low · CVSS 2.6 — Directory traversal vulnerability in file.c in PHP 4.4.2 and 5.1.2 allows local users to bypass open_basedir restrictions allows remote atta
CVE-2006-1608low · CVSS 2.1 — The copy function in file.c in PHP 4.4.2 and 5.1.2 allows local users to bypass safe mode and read arbitrary files via a source argument con
CVE-2006-1549low · CVSS 2.1 — PHP 4.4.2 and 5.1.2 allows local users to cause a crash (segmentation fault) by defining and executing a recursive function. NOTE: it has b
CVE-2006-1990medium · CVSS 5.0 — Integer overflow in the wordwrap function in string.c in PHP 4.4.2 and 5.1.2 might allow context-dependent attackers to execute arbitrary co