217 exploited vulnerabilities in Apache Http Server
- Vendors
- Apache, Linux Mint, Red Os, Rocky Linux, Canonical, Alt Linux
- With known exploits
- 217
- Affected Apache Http Server versions
- < 2.4.67, 2.4.60, 2.4.61, 2.4.62, 2.4.55, 2.4.52, 2.4.49, 2.4.50, 2.4.43, 2.4.54, 2.2.33, 2.4.26, 2.2.0, 2.2.2, 2.2.3, 2.2.11, 2.2.12, 2.2.13, 2.2.14, 2.2.15, 2.2.16, 2.2.17, 2.2.18, 2.2.19, 2.2.20, 2.2.21, 2.2.22, 2.2.23, 2.2.24, 2.2.25, 2.2.26, 2.2.27, 2.2.29, 2.2.30, 2.2.31, 2.2.32, 2.4.1, 2.4.2, 2.4.10, 2.4.12, 2.4.16, 2.4.17, 2.4.18, 2.4.20, 2.4.23, 2.4.25, 2.4.64, 2.4.39, 2.4.66, 2.4.56
- Affected Gnu Bash versions
- ≤ 4.3
- Affected Ibm Websphere Application Server versions
- < 6.1.0.31
- Affected Openssl versions
- ≤ 0.9.8l, 0.9.1c, 0.9.2b, 0.9.3, 0.9.3a, 0.9.4, 0.9.5, 0.9.5a, 0.9.6, 0.9.6a, 0.9.6b, 0.9.6c, 0.9.6d, 0.9.6e, 0.9.6f, 0.9.6g, 0.9.6h, 0.9.6i, 0.9.6j, 0.9.6k, 0.9.6l, 0.9.6m, 0.9.7, 0.9.7a, 0.9.7b, 0.9.7c, 0.9.7d, 0.9.7e, 0.9.7f, 0.9.7g, 0.9.7h, 0.9.7i, 0.9.7j, 0.9.7k, 0.9.7l, 0.9.7m, 0.9.8, 0.9.8a, 0.9.8b, 0.9.8c, 0.9.8k, 1.0
- Affected Apache Apr-util versions
- = 0.9.1, 0.9.2, 0.9.2-dev, 0.9.3, 0.9.3-dev, 0.9.4, 0.9.5, 0.9.6, 0.9.7-dev, 0.9.8, 0.9.9, 0.9.16, 1.3.0, 1.3.1, 1.3.2, 1.3.3, 1.3.4, 1.3.4-dev, 1.3.5, 1.3.6, 1.3.6-dev, 1.3.7, 1.3.8
- Affected Apache Portable Runtime versions
- = 0.9.1, 0.9.2, 0.9.2-dev, 0.9.3, 0.9.3-dev, 0.9.4, 0.9.5, 0.9.6, 0.9.7, 0.9.7-dev, 0.9.8, 0.9.9, 0.9.16-dev, 1.3.0, 1.3.1, 1.3.2, 1.3.3
- Affected Sonicwall Sma 200 Firmware versions
- = 10.2.0.8-37sv, 10.2.1.1-19sv, 10.2.1.2-24sv
- Affected Vbulletin versions
- ≤ 5.3.3, 5.0.0
Vulnerabilities with exploits
Highest CVSS first — 27 of these already have exploit code on Sploitus
CVE-2026-29168
CVE-2026-28780
CVE-2024-38474
CVE-2024-40725 3 exploits
Exploit for Exposure of Resource to Wrong Sphere in Apache Http_ServerExploit for Exposure of Resource to Wrong Sphere in Apache Http_Server
CVE-2024-40898 5 exploits
Exploit for Exposure of Resource to Wrong Sphere in Apache Http_ServerExploit for Server-Side Request Forgery in Apache Http_Server
CVE-2024-38476
CVE-2023-25690 5 exploits
Exploit for HTTP Request Smuggling in Apache Http_ServerApache 2.4.55 mod_proxy HTTP Request Smuggling Exploit
CVE-2022-36760
CVE-2022-23943
CVE-2022-22721
CVE-2021-44790 3 exploits
CVE-2021-42013 62 exploits
CVE-2021-26691
CVE-2020-11984 1 exploit
CVE-2014-6271 144 exploits
CVE-2014-7169 31 exploits
CVE-2010-0425 12 exploits
CVE-2009-4355
CVE-2009-2412 1 exploit
CVE-2022-31813 1 exploit
CVE-2022-22720
CVE-2021-39275
CVE-2021-20038 6 exploits
Exploit for Out-of-bounds Write in Sonicwall Sma_200_FirmwareExploit for Out-of-bounds Write in Sonicwall Sma_200_Firmware
CVE-2021-41773 156 exploits
CVE-2017-17671 1 exploit
CVE-2017-7679 2 exploits
Exploit for Improper Restriction of Operations within the Bounds of a Memory Buffer in Apache Http_ServerExploit for Cross-site Scripting in Jquery
CVE-2017-3167
CVE-2017-3169
CVE-2009-3555 15 exploits
metasploitable-vulnerability-mapping-with-nmapExploit for Improper Certificate Validation in Apache Http_Server
CVE-2018-18864 1 exploit
CVE-2025-23048 1 exploit
CVE-2024-38475 1 exploit
CVE-2006-6869 1 exploit
CVE-2022-28615
CVE-2019-10082
CVE-2026-23918 16 exploits
📄 Apache 2.4.66 HTTP/2 mod_http2 Double-Free Denial of Service📄 Apache HTTP Server 2.4.66 Denial of Service
CVE-2024-38472 1 exploit
CVE-2023-27522
CVE-2021-40438 5 exploits
Exploit for Server-Side Request Forgery in Resf Rocky_LinuxExploit for Server-Side Request Forgery in Resf Rocky_Linux
CVE-2009-3250 1 exploit
CVE-2022-46157
CVE-2021-29641 2 exploits
Monospace Directus Headless CMS File Upload / Rule Bypass VulnerabilitiesMonospace Directus Headless CMS File Upload / Rule Bypass
CVE-2019-13980
CVE-2025-58098
CVE-2024-10395
CVE-2024-38473 1 exploit
CVE-2019-0215
CVE-2019-10097
CVE-2013-3239 6 exploits
phpMyAdmin 3.5.8 and 4.0.0-RC2 - Multiple VulnerabilitiesphpMyAdmin 'filename_template' 远程代码执行(CVE-2013-3239)
CVE-2021-44224