Known vulnerabilities in Apache HTTP Server - page 2

Software CPE: cpe:2.3:a:apache_foundation:apache_http_server:*:*:*:*:*:*:*:*
Total vulnerabilities: 155
Public exploits: 31
Known exploited (KEV): 4
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting Apache HTTP Server Apache HTTP Server is affected by 155 known vulnerabilities: 4 critical, 15 high, 101 medium, 35 low Critical High Medium Low

Vulnerabilities (155)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU129547 - Allocation of Resources Without Limits or Throttling
CVE-2026-29168
CWE-770 Medium
No
No
2.4.67 04.05.2026 SB2026050479
SB2026050772
SB2026051103
and 12 more
#VU129548 - Heap-based Buffer Overflow
CVE-2026-28780
CWE-122 High
No
No
2.4.67 04.05.2026 SB2026050479
SB2026050772
SB2026051101
and 24 more
#VU129549 - Improper Access Control
CVE-2026-24072
CWE-284 Low
No
No
2.4.67 04.05.2026 SB2026050479
SB2026050772
SB2026051240
and 18 more
#VU129550 - Double Free
CVE-2026-23918
CWE-415 High
Available
No
2.4.67 04.05.2026 SB2026050479
SB2026050772
SB20260513119
and 7 more
#VU119150 - Integer overflow
CVE-2025-55753
CWE-190 Low
No
No
2.4.66 04.12.2025 SB2025120441
SB2025121923
SB2025121940
and 31 more
#VU119149 - Improper Neutralization of Server-Side Includes (SSI) Within a Web Page
CVE-2025-58098
CWE-97 Low
Available
No
2.4.66 04.12.2025 SB2025120441
SB2025121923
SB2025121940
and 46 more
#VU119148 - Server-Side Request Forgery (SSRF)
CVE-2025-59775
CWE-918 Medium
No
No
2.4.66 04.12.2025 SB2025120441
SB2026010820
SB20260114117
and 10 more
#VU119147 - Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
CVE-2025-65082
CWE-74 Low
No
No
2.4.66 04.12.2025 SB2025120441
SB2025121923
SB2025122202
and 32 more
#VU119146 - Improper input validation
CVE-2025-66200
CWE-20 Low
No
No
2.4.66 04.12.2025 SB2025120441
SB2025121923
SB2025122202
and 30 more
#VU113185 - Expected Behavior Violation
CVE-2025-54090
CWE-440 Medium
No
No
2.4.65 23.07.2025 SB2025072350
SB2025080808
SB2025081113
and 9 more
#VU112734 - Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting')
CVE-2024-42516
CWE-113 Low
No
No
2.4.64 10.07.2025 SB2025071040
SB2025071710
SB2025071764
and 33 more
#VU112733 - Server-Side Request Forgery (SSRF)
CVE-2024-43204
CWE-918 Low
No
No
2.4.64 10.07.2025 SB2025071040
SB2025071710
SB2025071764
and 27 more
#VU112732 - Server-Side Request Forgery (SSRF)
CVE-2024-43394
CWE-918 Medium
No
No
2.4.64 10.07.2025 SB2025071040
SB2025071710
SB2025072111
and 7 more
#VU112731 - Improper Encoding or Escaping of Output
CVE-2024-47252
CWE-116 High
No
No
2.4.64 10.07.2025 SB2025071040
SB2025071764
SB2025072111
and 34 more
#VU112730 - Security Features
CVE-2025-23048
CWE-254 Medium
Available
No
2.4.64 10.07.2025 SB2025071040
SB2025071764
SB2025072111
and 29 more
#VU112729 - Resource Management Errors
CVE-2025-49630
CWE-399 Medium
No
No
2.4.64 10.07.2025 SB2025071040
SB2025071764
SB2025072111
and 26 more
#VU112728 - Cryptographic Issues
CVE-2025-49812
CWE-310 Medium
No
No
2.4.64 10.07.2025 SB2025071040
SB2025071764
SB2025072111
and 34 more
#VU112727 - Resource Management Errors
CVE-2025-53020
CWE-399 Medium
No
No
2.4.64 10.07.2025 SB2025071040
SB2025071201
SB2025071202
and 17 more
#VU94504 - Exposure of sensitive information to an unauthorized actor
CVE-2024-40725
CWE-200 Medium
Available
No
2.4.62 17.07.2024 SB20240717136
SB2024071854
SB2024071896
and 22 more
#VU94503 - Server-Side Request Forgery (SSRF)
CVE-2024-40898
CWE-918 High
Available
No
2.4.62 17.07.2024 SB20240717136
SB2024071896
SB2024081362
and 13 more


Showing elements 21 - 40 out of 155