Http server
This hub aggregates every CVE we track for Http server, a product in the web cms plugins space. Use it to gauge the current risk picture and drill into individual advisories.
140
CVEs tracked
27
Critical
53
High
4
In CISA KEV
Severity distribution
MEDIUM54HIGH53CRITICAL27LOW6
Monthly trend
0
0
0
0
0
1
0
0
0
0
0
0
0
0
0
0
0
1
0
0
1
8
0
0
2024-082026-07
Latest CVEs
The 15 most recently published vulnerabilities affecting Http server.
- CVE-2026-9170IBM HTTP Server is affected by multiple vulnerabilities9.8
- CVE-2026-8835IBM HTTP Server is affected by multiple vulnerabilities7.3
- CVE-2026-8834IBM HTTP Server is affected by multiple vulnerabilities8.0
- CVE-2026-8855IBM HTTP Server is affected by multiple vulnerabilities8.1
- CVE-2026-8854IBM HTTP Server is affected by multiple vulnerabilities7.5
- CVE-2026-8856IBM HTTP Server is affected by multiple vulnerabilities7.7
- CVE-2026-8852IBM HTTP Server is affected by multiple vulnerabilities6.2
- CVE-2026-8850IBM HTTP Server is affected by multiple vulnerabilities7.5
- CVE-2026-34291Vulnerability in the Oracle HTTP Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Difficult to exploit vulnerabili...8.7
- CVE-2026-21962Vulnerability in the Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in product of Oracle Fusion Middleware (component: Weblogic Server Proxy Plug-in for Apache HTTP Server, Weblogic Server P...10.0
- CVE-2025-21498Vulnerability in the Oracle HTTP Server product of Oracle Fusion Middleware (component: Core). The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows unauth...5.3
- CVE-2024-20991Vulnerability in the Oracle HTTP Server product of Oracle Fusion Middleware (component: Web Listener). The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allow...5.3
- CVE-2023-22019Vulnerability in the Oracle HTTP Server product of Oracle Fusion Middleware (component: Web Listener). The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allow...7.5
- CVE-2023-44487The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.KEV7.5
- CVE-2023-32342IBM GSKit information disclosure7.5
Product normalization is registry-driven with AI assist and human review. How it works