CVE-2023-51767high · CVSS 7.0 — OpenSSH through 10.0, when common types of DRAM are used, might allow row hammer attacks (for authentication bypass) because the integer val
CVE-2025-26465medium · CVSS 6.8 — A vulnerability was found in OpenSSH when the VerifyHostKeyDNS option is enabled. A machine-in-the-middle attack can be performed by a malic
CVE-2025-26466medium · CVSS 5.9 — A flaw was found in the OpenSSH package. For each ping packet the SSH server receives, a pong packet is allocated in a memory buffer and sto
CVE-2025-32728medium · CVSS 4.3 — In sshd in OpenSSH before 10.0, the DisableForwarding directive does not adhere to the documentation stating that it disables X11 and agent
CVE-2026-35385high · CVSS 7.5 — In OpenSSH before 10.3, a file downloaded by scp may be installed setuid or setgid, an outcome contrary to some users' expectations, if the
CVE-2026-35387low · CVSS 3.1 — OpenSSH before 10.3 can use unintended ECDSA algorithms. Listing of any ECDSA algorithm in PubkeyAcceptedAlgorithms or HostbasedAcceptedAlgo
CVE-2026-35388low · CVSS 2.5 — OpenSSH before 10.3 omits connection multiplexing confirmation for proxy-mode multiplexing sessions.
CVE-2026-35414medium · CVSS 4.2 — OpenSSH before 10.3 mishandles the authorized_keys principals option in uncommon scenarios involving a principals list in conjunction with a
CVE-2026-59995medium · CVSS 4.2 — sftp in OpenSSH before 10.4 does not properly constrain the location of downloaded files when "sftp server:/path ." is used with an attacker
CVE-2026-59996medium · CVSS 4.2 — scp in OpenSSH before 10.4 may place a file in the parent directory of an intended directory when the copy occurs between two remote destina
CVE-2026-59997medium · CVSS 4.2 — internal-sftp in sshd in OpenSSH before 10.4 recognizes only the first 9 command-line arguments, which can be important if a later command-l
CVE-2026-59998medium · CVSS 4.8 — sshd in OpenSSH before 10.4 has an undocumented security-relevant behavior: GSSAPIStrictAcceptorCheck has no value if the server is in Windo
CVE-2026-59999medium · CVSS 5.9 — In sshd in OpenSSH before 10.4, DisableForwarding=yes was supposed to take precedence over PermitTunnel=yes, but did not.
CVE-2026-60000low · CVSS 3.7 — sshd in OpenSSH before 10.4 allows remote attackers to cause a denial of service (resource consumption from excessive authentication attempt
CVE-2026-60001medium · CVSS 6.5 — sshd in OpenSSH before 10.4 does not always honor the minimum authentication delay.
CVE-2026-60002high · CVSS 7.7 — ssh in OpenSSH before 10.4 can have a use-after-free when a server changes its host key during a key re-exchange. (This outcome occurs only
CVE-2024-42516high · CVSS 7.5 — HTTP response splitting in the core of Apache HTTP Server allows an attacker who can manipulate the Content-Type response headers of applica
CVE-2024-43204high · CVSS 7.5 — SSRF in Apache HTTP Server with mod_proxy loaded allows an attacker to send outbound proxy requests to a URL controlled by the attacker. Re
CVE-2024-43394high · CVSS 7.5 — Server-Side Request Forgery (SSRF) in Apache HTTP Server on Windows allows to potentially leak NTLM hashes to a malicious server via
mod_re
CVE-2024-47252high · CVSS 7.5 — Insufficient escaping of user-supplied data in mod_ssl in Apache HTTP Server 2.4.63 and earlier allows an untrusted SSL/TLS client to insert
CVE-2025-23048critical · CVSS 9.1 — In some mod_ssl configurations on Apache HTTP Server 2.4.35 through to 2.4.63, an access control bypass by trusted clients is possible using
CVE-2025-49630high · CVSS 7.5 — In certain proxy configurations, a denial of service attack against Apache HTTP Server versions 2.4.26 through to 2.4.63 can be triggered by
CVE-2025-49812high · CVSS 7.4 — In some mod_ssl configurations on Apache HTTP Server versions through to 2.4.63, an HTTP desynchronisation attack allows a man-in-the-middle
CVE-2025-53020high · CVSS 7.5 — Late Release of Memory after Effective Lifetime vulnerability in Apache HTTP Server.
This issue affects Apache HTTP Server: from 2.4.17 up
CVE-2025-55753high · CVSS 7.5 — An integer overflow in the case of failed ACME certificate renewal leads, after a number of failures (~30 days in default configurations), t
CVE-2025-59775high · CVSS 7.5 — Server-Side Request Forgery (SSRF) vulnerability
in Apache HTTP Server on Windows
with AllowEncodedSlashes On and MergeSlashes Off all
CVE-2025-65082medium · CVSS 6.5 — Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in Apache HTTP Server through environment variables set via the
CVE-2025-66200medium · CVSS 5.4 — mod_userdir+suexec bypass via AllowOverride FileInfo vulnerability in Apache HTTP Server. Users with access to use the RequestHeader directi
CVE-2025-58098high · CVSS 8.3 — Apache HTTP Server 2.4.65 and earlier with Server Side Includes (SSI) enabled and mod_cgid (but not mod_cgi) passes the shell-escaped query
CVE-2026-24072high · CVSS 8.8 — An escalation of privilege bug in various modules in Apache HTTP 2.4.66 and earlier allows local .htaccess authors to read files with the pr
CVE-2026-34059high · CVSS 7.5 — Buffer Over-read vulnerability in Apache HTTP Server.
This issue affects Apache HTTP Server: through 2.4.66.
Users are recommended to upgr
CVE-2026-33857medium · CVSS 5.3 — Out-of-bounds Read vulnerability in mod_proxy_ajp of
Apache HTTP Server.
This issue affects Apache HTTP Server: through 2.4.66.
Users ar
CVE-2026-34032medium · CVSS 5.3 — Improper Null Termination, Out-of-bounds Read vulnerability in Apache HTTP Server.
This issue affects Apache HTTP Server: through 2.4.66.
CVE-2026-29169high · CVSS 7.5 — A NULL pointer dereference in mod_dav_lock in Apache HTTP Server 2.4.66 and earlier may allow an attacker to crash the server with a malicio
CVE-2026-33006medium · CVSS 4.8 — A timing attack against mod_auth_digest in Apache HTTP Server 2.4.66 allows a bypass of Digest authentication by a remote attacker.
Users a
CVE-2026-33007medium · CVSS 5.3 — A NULL pointer dereference in the mod_authn_socache in Apache HTTP Server 2.4.66 and earlier allows an unauthenticated remote user to crash
CVE-2026-33523medium · CVSS 6.5 — HTTP response splitting vulnerability in multiple Apache HTTP Server modules with untrusted or compromised backend servers.
This issue affe
CVE-2026-29168high · CVSS 7.3 — Allocation of Resources Without Limits or Throttling vulnerability in Apache HTTP Server's mod_md via OCSP response data.
This issue affec
CVE-2026-28780critical · CVSS 9.8 — Heap-based Buffer Overflow vulnerability in mod_proxy_ajp of Apache HTTP Server.
If mod_proxy_ajp connects to a malicious AJP server this AJ
CVE-2026-29167critical · CVSS 9.8 — Use After Free vulnerability in Apache HTTP Server with mod_ldap in per-directory configuration
This issue affects Apache HTTP Server: from
CVE-2026-29170medium · CVSS 6.1 — A cross-site scripting vulnerability exists in mod_proxy_ftp's HTML directory list generation in Apache HTTP Server 2.4.67 and earlier when
CVE-2026-34355high · CVSS 7.5 — A buffer overflow in mod_proxy_html in Apache HTTP Server 2.4.67 and earlier allows an attack by an untrusted backend.
Users are recommended
CVE-2026-34356high · CVSS 7.5 — Heap-based Buffer Overflow vulnerability in Apache HTTP Server with malicious backend servers and ProxyPassReverseCookie*
This issue affect
CVE-2026-42535critical · CVSS 9.1 — A path handling issue in mod_dav_fs in Apache 2.4.67 and earlier allows a WebDAV content author to directly manipulate trusted DAV property
CVE-2026-42536high · CVSS 7.5 — Heap-based Buffer Overflow vulnerability in Apache HTTP Server with mod_xml2enc, xml2StartParse, and untrusted content
This issue affects A
CVE-2026-43951medium · CVSS 6.5 — Out-of-bounds Read vulnerability in Apache HTTP Server with mod_headers and mod_mime and multiple response languages.
This issue affects Ap
CVE-2026-44119medium · CVSS 5.5 — Improper Privilege Management vulnerability in Apache HTTP Server 2.4.67 and earlier allows local .htaccess authors to read files with the p
CVE-2026-44185high · CVSS 7.3 — Buffer Over-read vulnerability in Apache HTTP Server via outbound OCSP requests to an attacker controlled OCSP server
This issue affects Ap
CVE-2026-44186high · CVSS 7.3 — Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in the mod_proxy_ftp module in Apache HTTP Server with an attacker cont
CVE-2026-44631critical · CVSS 9.8 — Buffer Underwrite vulnerability in Apache HTTP Server on crafted regular expressions in the configuration.
This issue affects Apache HTTP S