Spain · Las Rozas de Madrid · Universidad Nacional de Educacion a Distancia - UNED
Risk score: 98/100 · 3 open port(s) · 28 CVE(s)
First seen 2026-08-18 · last seen 2026-08-18
Open ports
Port
Service
Software
CVEs
80
http
Apache HTTP Server
28
443
http
0
8080
http
0
CVEs (28)
CVE-2026-24072high · CVSS 8.8 — An escalation of privilege bug in various modules in Apache HTTP 2.4.66 and earlier allows local .htaccess authors to read files with the pr
CVE-2026-34059high · CVSS 7.5 — Buffer Over-read vulnerability in Apache HTTP Server.
This issue affects Apache HTTP Server: through 2.4.66.
Users are recommended to upgr
CVE-2026-33857medium · CVSS 5.3 — Out-of-bounds Read vulnerability in mod_proxy_ajp of
Apache HTTP Server.
This issue affects Apache HTTP Server: through 2.4.66.
Users ar
CVE-2026-34032medium · CVSS 5.3 — Improper Null Termination, Out-of-bounds Read vulnerability in Apache HTTP Server.
This issue affects Apache HTTP Server: through 2.4.66.
CVE-2026-23918high · CVSS 8.8 — Double Free and possible RCE vulnerability in Apache HTTP Server with the HTTP/2 protocol.
This issue affects Apache HTTP Server: 2.4.66.
CVE-2026-29169high · CVSS 7.5 — A NULL pointer dereference in mod_dav_lock in Apache HTTP Server 2.4.66 and earlier may allow an attacker to crash the server with a malicio
CVE-2026-33006medium · CVSS 4.8 — A timing attack against mod_auth_digest in Apache HTTP Server 2.4.66 allows a bypass of Digest authentication by a remote attacker.
Users a
CVE-2026-33007medium · CVSS 5.3 — A NULL pointer dereference in the mod_authn_socache in Apache HTTP Server 2.4.66 and earlier allows an unauthenticated remote user to crash
CVE-2026-33523medium · CVSS 6.5 — HTTP response splitting vulnerability in multiple Apache HTTP Server modules with untrusted or compromised backend servers.
This issue affe
CVE-2026-29168high · CVSS 7.3 — Allocation of Resources Without Limits or Throttling vulnerability in Apache HTTP Server's mod_md via OCSP response data.
This issue affec
CVE-2026-28780critical · CVSS 9.8 — Heap-based Buffer Overflow vulnerability in mod_proxy_ajp of Apache HTTP Server.
If mod_proxy_ajp connects to a malicious AJP server this AJ
CVE-2026-29167critical · CVSS 9.8 — Use After Free vulnerability in Apache HTTP Server with mod_ldap in per-directory configuration
This issue affects Apache HTTP Server: from
CVE-2026-29170medium · CVSS 6.1 — A cross-site scripting vulnerability exists in mod_proxy_ftp's HTML directory list generation in Apache HTTP Server 2.4.67 and earlier when
CVE-2026-34355high · CVSS 7.5 — A buffer overflow in mod_proxy_html in Apache HTTP Server 2.4.67 and earlier allows an attack by an untrusted backend.
Users are recommended
CVE-2026-34356high · CVSS 7.5 — Heap-based Buffer Overflow vulnerability in Apache HTTP Server with malicious backend servers and ProxyPassReverseCookie*
This issue affect
CVE-2026-42535critical · CVSS 9.1 — A path handling issue in mod_dav_fs in Apache 2.4.67 and earlier allows a WebDAV content author to directly manipulate trusted DAV property
CVE-2026-42536high · CVSS 7.5 — Heap-based Buffer Overflow vulnerability in Apache HTTP Server with mod_xml2enc, xml2StartParse, and untrusted content
This issue affects A
CVE-2026-43951medium · CVSS 6.5 — Out-of-bounds Read vulnerability in Apache HTTP Server with mod_headers and mod_mime and multiple response languages.
This issue affects Ap
CVE-2026-44119medium · CVSS 5.5 — Improper Privilege Management vulnerability in Apache HTTP Server 2.4.67 and earlier allows local .htaccess authors to read files with the p
CVE-2026-44185high · CVSS 7.3 — Buffer Over-read vulnerability in Apache HTTP Server via outbound OCSP requests to an attacker controlled OCSP server
This issue affects Ap
CVE-2026-44186high · CVSS 7.3 — Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in the mod_proxy_ftp module in Apache HTTP Server with an attacker cont
CVE-2026-44631critical · CVSS 9.8 — Buffer Underwrite vulnerability in Apache HTTP Server on crafted regular expressions in the configuration.
This issue affects Apache HTTP S
CVE-2026-48913high · CVSS 7.3 — Use After Free vulnerability in Apache HTTP Server module mod_http2 when file handles are already exhausted.
This issue affects Apache HTTP
CVE-2026-49975high · CVSS 7.5 — Memory Allocation with Excessive Size Value vulnerability in Apache HTTP Server's mod_http leads to denial of service via malicious HTTP req
CVE-2019-11358medium · CVSS 6.1 — jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) because of Object.prototyp
CVE-2020-11023medium · CVSS 6.9 — In jQuery versions greater than or equal to 1.0.3 and before 3.5.0, passing HTML containing <option> elements from untrusted sources - even
CVE-2020-11022medium · CVSS 6.9 — In jQuery starting with 1.12.0 and before 3.5.0, passing HTML from untrusted sources - even after sanitizing it - to one of jQuery's DOM man
CVE-2020-7656medium · CVSS 6.1 — jquery prior to 1.9.0 allows Cross-site Scripting attacks via the load method. The load method fails to recognize and remove "<script>" HTML