56.775 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync
Search: http
2708 CVE
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2022-43872 | MED 5.3 | ibm financial_transaction_manager IBM Financial Transaction Manager 3.2.4 authorization checks are done incorrectly for some HTTP requests which allows getting unauthorized technical information (e.g. event log entries) about the FTM SWIFT system. IBM X-Force ID: 239708. | 0.5% | — |
| CVE-2026-40564 | MED 6.5 | apache flink_kubernetes_operator Files or Directories Accessible to External Parties, Server-Side Request Forgery (SSRF) vulnerability in Apache Flink Kubernetes Operator. The FlinkSessionJob jarURI is currently not validated so that it points to user-owned files or addresses. This lets a u | 0.5% | — |
| CVE-2026-49298 | HIGH 8.8 | apache airflow A bug in Apache Airflow's KubernetesExecutor caused JWT tokens used by worker pods to authenticate against the Execution API to be passed to the worker container as command-line arguments visible in the pod spec. An authenticated UI/API user with Kubernetes re | 0.5% | — |
| CVE-2023-42503 | MED 5.5 | apache commons_compress Improper Input Validation, Uncontrolled Resource Consumption vulnerability in Apache Commons Compress in TAR parsing.This issue affects Apache Commons Compress: from 1.22 before 1.24.0. Users are recommended to upgrade to version 1.24.0, which fixes the issue | 0.5% | — |
| CVE-2026-74848 | HIGH 7.5 | apache apisix Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in Apache APISIX. An attacker could make other clients receive attacker-chosen or other users' responses on serverless-plugin routes. This issue affects Apache | 0.5% | — |
| CVE-2026-34032 | MED 5.3 | apache http_server Improper Null Termination, Out-of-bounds Read vulnerability in Apache HTTP Server. This issue affects Apache HTTP Server: through 2.4.66. Users are recommended to upgrade to version 2.4.67, which fixes the issue. | 0.5% | — |
| CVE-2024-33505 | MED 5.6 | fortinet fortianalyzer A heap-based buffer overflow in Fortinet FortiAnalyzer version 7.4.0 through 7.4.2, 7.2.0 through 7.2.5, 7.0.0 through 7.0.12, 6.4.0 through 6.4.14, FortiManager version 7.4.0 through 7.4.2, 7.2.0 through 7.2.5, 7.0.0 through 7.0.12, 6.4.0 through 6.4.14 allow | 0.5% | — |
| CVE-2023-20263 | MED 4.7 | cisco hyperflex_hx_data_platform A vulnerability in the web-based management interface of Cisco HyperFlex HX Data Platform could allow an unauthenticated, remote attacker to redirect a user to a malicious web page. This vulnerability is due to improper input validation of the parameters | 0.5% | — |
| CVE-2022-34165 | MED 5.4 | ibm websphere_application_server IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 and IBM WebSphere Application Server Liberty 17.0.0.3 through 22.0.0.9 are vulnerable to HTTP header injection, caused by improper validation. This could allow an attacker to conduct various attacks again | 0.5% | — |
| CVE-2023-48789 | MED 4.3 | fortinet fortiportal A client-side enforcement of server-side security in Fortinet FortiPortal version 6.0.0 through 6.0.14 allows attacker to improper access control via crafted HTTP requests. | 0.5% | — |
| CVE-2022-22386 | MED 5.3 | ibm security_verify_privilege_on-premises IBM Security Verify Privilege On-Premises 11.5 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information | 0.5% | — |
| CVE-2022-22377 | MED 5.3 | ibm security_verify_privilege_on-premises IBM Security Verify Privilege On-Premises 11.5 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information | 0.5% | — |
| CVE-2023-41680 | HIGH 7.5 | fortinet fortisandbox A improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.1, FortiSandbox 4.2.1 through 4.2.5, FortiSandbox 4.0.0 through 4.0.3, FortiSandbox 3.2 all versions, FortiSandbox 3 | 0.5% | — |
| CVE-2026-22732 | CRIT 9.1 | vmware spring_security When applications specify HTTP response headers for servlet applications using Spring Security, there is the possibility that the HTTP Headers will not be written. This issue affects Spring Security Servlet applications using lazy (default) writing of HTTP He | 0.5% | — |
| CVE-2026-48913 | HIGH 7.3 | apache http_server Use After Free vulnerability in Apache HTTP Server module mod_http2 when file handles are already exhausted. This issue affects Apache HTTP Server: from 2.4.55 through 2.4.67. | 0.5% | — |
| CVE-2024-45030 | CRIT 9.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: igb: cope with large MAX_SKB_FRAGS Sabrina reports that the igb driver does not cope well with large MAX_SKB_FRAG values: setting MAX_SKB_FRAG to 45 causes payload corruption on TX. An easy | 0.5% | — |
| CVE-2026-62735 | HIGH 7.8 | microsoft windows_10_1607 Heap-based buffer overflow in Windows HTTP.sys allows an authorized attacker to elevate privileges locally. | 0.5% | — |
| CVE-2024-20524 | MED 6.8 | cisco rv042_firmware A vulnerability in the web-based management interface of Cisco Small Business RV042, RV042G, RV320, and RV325 Routers could allow an authenticated, Administrator-level, remote attacker to cause an unexpected reload of an affected device, resulting in a denial | 0.5% | — |
| CVE-2024-20523 | MED 6.8 | cisco rv042_firmware A vulnerability in the web-based management interface of Cisco Small Business RV042, RV042G, RV320, and RV325 Routers could allow an authenticated, Administrator-level, remote attacker to cause an unexpected reload of an affected device, resulting in a denial | 0.5% | — |
| CVE-2025-54500 | MED 5.3 | f5 big-ip_access_policy_manager An HTTP/2 implementation flaw allows a denial-of-service (DoS) that uses malformed HTTP/2 control frames in order to break the max concurrent streams limit (HTTP/2 MadeYouReset Attack). Note: Software versions which have reached End of Technical Support (EoT | 0.5% | — |
| CVE-2023-34036 | MED 5.3 | vmware spring_hateoas Reactive web applications that use Spring HATEOAS to produce hypermedia-based responses might be exposed to malicious forwarded headers if they are not behind a trusted proxy that ensures correctness of such headers, or if they don't have anything else in pla | 0.5% | — |
| CVE-2026-57021 | MED 5.3 | juniper junos An Out-of-bounds Write vulnerability in the http-gatekeeper (http-gk) of Juniper Networks Junos OS on SRX Series allows an unauthenticated, network-based attacker to cause a Denial-of-Service (DoS). If an SRX Series device is configured for remote-access VPN | 0.5% | — |
| CVE-2025-15558 | HIGH 8.0 | docker command_line_interface Docker CLI for Windows searches for plugin binaries in C:\ProgramData\Docker\cli-plugins, a directory that does not exist by default. A low-privileged attacker can create this directory and place malicious CLI plugin binaries (docker-compose.exe, docker-buildx | 0.5% | — |
| CVE-2022-27484 | MED 5.4 | fortinet fortiadc A unverified password change in Fortinet FortiADC version 6.2.0 through 6.2.3, 6.1.x, 6.0.x, 5.x.x allows an authenticated attacker to bypass the Old Password check in the password change form via a crafted HTTP request. | 0.5% | — |
| CVE-2023-36633 | MED 5.4 | fortinet fortimail An improper authorization vulnerability [CWE-285] in FortiMail webmail version 7.2.0 through 7.2.2 and before 7.0.5 allows an authenticated attacker to see and modify the title of address book folders of other users via crafted HTTP or HTTPs requests. | 0.5% | — |