Spain · L'Hospitalet de Llobregat · MBA DATACENTERS S.L.
Risk score: 98/100 · 7 open port(s) · 57 CVE(s)
First seen 2026-08-18 · last seen 2026-08-18
Open ports
Port
Service
Software
CVEs
21
ftp
vsftpd
0
22
ssh
0
80
http
Apache HTTP Server
57
111
rpcbind
0
3306
mysql
MySQL
0
5060
sip
0
8080
http
Apache HTTP Server
0
CVEs (57)
CVE-2006-4110medium · CVSS 4.3 — Apache 2.2.2, when running on Windows, allows remote attackers to read source code of CGI programs via a request that contains uppercase (or
CVE-2006-4154medium · CVSS 6.8 — Format string vulnerability in the mod_tcl module 1.0 for Apache 2.x allows context-dependent attackers to execute arbitrary code via format
CVE-2007-1741medium · CVSS 6.2 — Multiple race conditions in suexec in Apache HTTP Server (httpd) 2.2.3 between directory and file validation, and their usage, allow local u
CVE-2007-1742low · CVSS 3.7 — suexec in Apache HTTP Server (httpd) 2.2.3 uses a partial comparison for verifying whether the current directory is within the document root
CVE-2007-1743medium · CVSS 4.4 — suexec in Apache HTTP Server (httpd) 2.2.3 does not verify combinations of user and group IDs on the command line, which might allow local u
CVE-2007-6203medium · CVSS 4.3 — Apache HTTP Server 2.0.x and 2.2.x does not sanitize the HTTP Method specifier header from an HTTP request when it is reflected back in a "4
CVE-2007-6422medium · CVSS 4.0 — The balancer_handler function in mod_proxy_balancer in the Apache HTTP Server 2.2.0 through 2.2.6, when a threaded Multi-Processing Module i
CVE-2007-6421low · CVSS 3.5 — Cross-site scripting (XSS) vulnerability in balancer-manager in mod_proxy_balancer in the Apache HTTP Server 2.2.0 through 2.2.6 allows remo
CVE-2007-6420medium · CVSS 4.3 — Cross-site request forgery (CSRF) vulnerability in the balancer-manager in mod_proxy_balancer for Apache HTTP Server 2.2.x allows remote att
CVE-2007-6423high · CVSS 7.8 — Unspecified vulnerability in mod_proxy_balancer for Apache HTTP Server 2.2.x before 2.2.7-dev, when running on Windows, allows remote attack
CVE-2008-2168medium · CVSS 4.3 — Cross-site scripting (XSS) vulnerability in Apache 2.2.6 and earlier allows remote attackers to inject arbitrary web script or HTML via UTF-
CVE-2008-2384high · CVSS 7.5 — SQL injection vulnerability in mod_auth_mysql.c in the mod-auth-mysql (aka libapache2-mod-auth-mysql) module for the Apache HTTP Server 2.x,
CVE-2009-1195medium · CVSS 4.9 — The Apache HTTP Server 2.2.11 and earlier 2.2 versions does not properly handle Options=IncludesNOEXEC in the AllowOverride directive, which
CVE-2010-0408medium · CVSS 5.0 — The ap_proxy_ajp_request function in mod_proxy_ajp.c in mod_proxy_ajp in the Apache HTTP Server 2.2.x before 2.2.15 does not properly handle
CVE-2011-3368medium · CVSS 5.0 — The mod_proxy module in the Apache HTTP Server 1.3.x through 1.3.42, 2.0.x through 2.0.64, and 2.2.x through 2.2.21 does not properly intera
CVE-2011-3607medium · CVSS 4.4 — Integer overflow in the ap_pregsub function in server/util.c in the Apache HTTP Server 2.0.x through 2.0.64 and 2.2.x through 2.2.21, when t
CVE-2011-4415low · CVSS 1.2 — The ap_pregsub function in server/util.c in the Apache HTTP Server 2.0.x through 2.0.64 and 2.2.x through 2.2.21, when the mod_setenvif modu
CVE-2011-3639medium · CVSS 4.3 — The mod_proxy module in the Apache HTTP Server 2.0.x through 2.0.64 and 2.2.x before 2.2.18, when the Revision 1179239 patch is in place, do
CVE-2011-4317medium · CVSS 4.3 — The mod_proxy module in the Apache HTTP Server 1.3.x through 1.3.42, 2.0.x through 2.0.64, and 2.2.x through 2.2.21, when the Revision 11792
CVE-2007-6750medium · CVSS 5.0 — The Apache HTTP Server 1.x and 2.x allows remote attackers to cause a denial of service (daemon outage) via partial HTTP requests, as demons
CVE-2012-0883medium · CVSS 6.9 — envvars (aka envvars-std) in the Apache HTTP Server before 2.4.2 places a zero-length directory name in the LD_LIBRARY_PATH, which allows lo
CVE-2012-2687low · CVSS 2.6 — Multiple cross-site scripting (XSS) vulnerabilities in the make_variant_list function in mod_negotiation.c in the mod_negotiation module in
CVE-2012-3499medium · CVSS 4.3 — Multiple cross-site scripting (XSS) vulnerabilities in the Apache HTTP Server 2.2.x before 2.2.24-dev and 2.4.x before 2.4.4 allow remote at
CVE-2012-4558medium · CVSS 4.3 — Multiple cross-site scripting (XSS) vulnerabilities in the balancer_handler function in the manager interface in mod_proxy_balancer.c in the
CVE-2013-5704medium · CVSS 5.0 — The mod_headers module in the Apache HTTP Server 2.2.22 allows remote attackers to bypass "RequestHeader unset" directives by placing a head
CVE-2017-3169critical · CVSS 9.8 — In Apache httpd 2.2.x before 2.2.33 and 2.4.x before 2.4.26, mod_ssl may dereference a NULL pointer when third-party modules call ap_hook_pr
CVE-2017-9798high · CVSS 7.5 — Apache httpd allows remote attackers to read secret data from process memory if the Limit directive can be set in a user's .htaccess file, o
CVE-2016-4975medium · CVSS 6.1 — Possible CRLF injection allowing HTTP response splitting attacks for sites which use mod_userdir. This issue was mitigated by changes made i
CVE-2021-34798high · CVSS 7.5 — Malformed requests may cause the server to dereference a NULL pointer. This issue affects Apache HTTP Server 2.4.48 and earlier.
CVE-2021-39275critical · CVSS 9.8 — ap_escape_quotes() may write beyond the end of a buffer when given malicious input. No included modules pass untrusted data to these functio
CVE-2021-40438critical · CVSS 9.0 — A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user. This issue affects Apa
CVE-2021-44790critical · CVSS 9.8 — A carefully crafted request body can cause a buffer overflow in the mod_lua multipart parser (r:parsebody() called from Lua scripts). The Ap
CVE-2022-22719high · CVSS 7.5 — A carefully crafted request body can cause a read to a random memory area which could cause the process to crash. This issue affects Apache
CVE-2022-22720critical · CVSS 9.8 — Apache HTTP Server 2.4.52 and earlier fails to close inbound connection when errors are encountered discarding the request body, exposing th
CVE-2022-22721critical · CVSS 9.1 — If LimitXMLRequestBody is set to allow request bodies larger than 350MB (defaults to 1M) on 32 bit systems an integer overflow happens which
CVE-2022-28330medium · CVSS 5.3 — Apache HTTP Server 2.4.53 and earlier on Windows may read beyond bounds when configured to process requests with the mod_isapi module.
CVE-2022-28614medium · CVSS 5.3 — The ap_rwrite() function in Apache HTTP Server 2.4.53 and earlier may read unintended memory if an attacker can cause the server to reflect
CVE-2022-28615critical · CVSS 9.1 — Apache HTTP Server 2.4.53 and earlier may crash or disclose information due to a read beyond bounds in ap_strcmp_match() when provided with
CVE-2022-29404high · CVSS 7.5 — In Apache HTTP Server 2.4.53 and earlier, a malicious request to a lua script that calls r:parsebody(0) may cause a denial of service due to
CVE-2022-30556high · CVSS 7.5 — Apache HTTP Server 2.4.53 and earlier may return lengths to applications calling r:wsread() that point past the end of the storage allocated
CVE-2022-31813critical · CVSS 9.8 — Apache HTTP Server 2.4.53 and earlier may not send the X-Forwarded-* headers to the origin server based on client side Connection header hop
CVE-2006-20001high · CVSS 7.5 — A carefully crafted If: request header can cause a memory read, or write of a single zero byte, in a pool (heap) memory location beyond the
CVE-2022-37436medium · CVSS 5.3 — Prior to Apache HTTP Server 2.4.55, a malicious backend can cause the response headers to be truncated early, resulting in some headers bein
CVE-2023-31122high · CVSS 7.5 — Out-of-bounds Read vulnerability in mod_macro of Apache HTTP Server.This issue affects Apache HTTP Server: through 2.4.57.
CVE-2023-38709high · CVSS 7.3 — Faulty input validation in the core of Apache allows malicious or exploitable backend/content generators to split HTTP responses.
This issu
CVE-2024-40898high · CVSS 7.5 — SSRF in Apache HTTP Server on Windows with mod_rewrite in server/vhost context, allows to potentially leak NTML hashes to a malicious server
CVE-2025-49812high · CVSS 7.4 — In some mod_ssl configurations on Apache HTTP Server versions through to 2.4.63, an HTTP desynchronisation attack allows a man-in-the-middle
CVE-2025-58098high · CVSS 8.3 — Apache HTTP Server 2.4.65 and earlier with Server Side Includes (SSI) enabled and mod_cgid (but not mod_cgi) passes the shell-escaped query
CVE-2026-24072high · CVSS 8.8 — An escalation of privilege bug in various modules in Apache HTTP 2.4.66 and earlier allows local .htaccess authors to read files with the pr
CVE-2026-34059high · CVSS 7.5 — Buffer Over-read vulnerability in Apache HTTP Server.
This issue affects Apache HTTP Server: through 2.4.66.
Users are recommended to upgr