56.705 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync
Search: proxy
385 CVE
| Identifier | Severity, sorted descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2007-1644 | HIGH 10.0 | microsoft all_windows The dynamic DNS update mechanism in the DNS Server service on Microsoft Windows does not properly authenticate clients in certain deployments or configurations, which allows remote attackers to change DNS records for a web proxy server and conduct man-in-the-m | 32.6% | — |
| CVE-2004-0492 | HIGH 10.0 | apache http_server Heap-based buffer overflow in proxy_util.c for mod_proxy in Apache 1.3.25 to 1.3.31 allows remote attackers to cause a denial of service (process crash) and possibly execute arbitrary code via a negative Content-Length HTTP header field, which causes a large a | 33.6% | — |
| CVE-1999-1293 | HIGH 10.0 | apache http_server mod_proxy in Apache 1.2.5 and earlier allows remote attackers to cause a denial of service via malformed FTP commands, which causes Apache to dump core. | 4.0% | — |
| CVE-1999-0407 | HIGH 10.0 | microsoft internet_information_server By default, IIS 4.0 has a virtual directory /IISADMPWD which contains files that can be used as proxies for brute force password attacks, or to identify valid users on the system. | 5.1% | — |
| CVE-2026-8655 | CRIT 9.8 | citrix netscaler_application_delivery_controller Multiple Memory overflow vulnerabilities in NetScaler ADC and NetScaler Gateway leading to unpredictable or erroneous behavior and Denial of Service if NetScaler ADC is configured as an LB of type Oracle OR NetScaler ADC is configured as a DNS Proxy OR NetScal | 0.6% | — |
| CVE-2026-8452 | CRIT 9.8 | citrix netscaler_application_delivery_controller Memory overflow vulnerability NetScaler ADC and NetScaler Gateway leading to unpredictable or erroneous behavior and Denial of Service if the appliance is configured as a Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server | 1.6% | |
| CVE-2026-47065 | CRIT 9.8 | apache mina ZDRES-232: resolveProxyClass Not Overridden - acceptMatchers Filter Bypass via java.lang.reflect.Proxy Assessment: Fully addressed. When the serialised stream contains a TC_PROXYCLASSDESC (the marker for a java.lang.reflect.Proxy ), JDK’s ObjectInputStrea | 0.5% | — |
| CVE-2026-28780 | CRIT 9.8 | apache http_server Heap-based Buffer Overflow vulnerability in mod_proxy_ajp of Apache HTTP Server. If mod_proxy_ajp connects to a malicious AJP server this AJP server can send a malicious AJP message back to mod_proxy_ajp and cause it to write 4 attacker controlled bytes after | 1.4% | — |
| CVE-2026-0264 | CRIT 9.8 | paloaltonetworks pan-os A buffer overflow vulnerability in the DNS proxy and DNS Server features of Palo Alto Networks PAN-OS® Software allows an unauthenticated attacker with network access to cause a denial of service (DoS) condition (all PAN-OS platforms except Cloud NGFW and Pris | 0.5% | — |
| CVE-2025-7776 | CRIT 9.8 | citrix netscaler_application_delivery_controller Memory overflow vulnerability leading to unpredictable or erroneous behavior and Denial of Service in NetScaler ADC and NetScaler Gateway when NetScaler is configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) with PCoIP Profile bounded to i | 6.9% | — |
| CVE-2025-7775 | CRIT 9.8 | citrix netscaler_application_delivery_controller Memory overflow vulnerability leading to Remote Code Execution and/or Denial of Service in NetScaler ADC and NetScaler Gateway when NetScaler is configured as Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server (OR) NetScaler ADC a | 19.6% | |
| CVE-2025-6543 | CRIT 9.8 | citrix netscaler_application_delivery_controller Memory overflow vulnerability leading to unintended control flow and Denial of Service in NetScaler ADC and NetScaler Gateway when configured as Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) OR AAA virtual server | 10.1% | |
| CVE-2024-43639 | CRIT 9.8 | microsoft windows_server_2012 Windows KDC Proxy Remote Code Execution Vulnerability | 8.9% | — |
| CVE-2023-38545 | CRIT 9.8 | fedoraproject fedora This flaw makes curl overflow a heap based buffer in the SOCKS5 proxy handshake. When curl is asked to pass along the host name to the SOCKS5 proxy to allow that to resolve the address instead of it getting done by curl itself, the maximum length that host na | 78.5% | — |
| CVE-2023-33308 | CRIT 9.8 | fortinet fortios A stack-based overflow vulnerability [CWE-124] in Fortinet FortiOS version 7.0.0 through 7.0.10 and 7.2.0 through 7.2.3 and FortiProxy version 7.0.0 through 7.0.9 and 7.2.0 through 7.2.2 allows a remote unauthenticated attacker to execute arbitrary code or com | 2.1% | — |
| CVE-2023-25690 | CRIT 9.8 | apache http_server Some mod_proxy configurations on Apache HTTP Server versions 2.4.0 through 2.4.55 allow a HTTP Request Smuggling attack. Configurations are affected when mod_proxy is enabled along with some form of RewriteRule or ProxyPassMatch in which a non-specific pa | 84.5% | — |
| CVE-2022-45347 | CRIT 9.8 | apache shardingsphere Apache ShardingSphere-Proxy prior to 5.3.0 when using MySQL as database backend didn't cleanup the database session completely after client authentication failed, which allowed an attacker to execute normal commands by constructing a special MySQL client. This | 1.4% | — |
| CVE-2021-42756 | CRIT 9.8 | fortinet fortiweb Multiple stack-based buffer overflow vulnerabilities [CWE-121] in the proxy daemon of FortiWeb 5.x all versions, 6.0.7 and below, 6.1.2 and below, 6.2.6 and below, 6.3.16 and below, 6.4 all versions may allow an unauthenticated remote attacker to achieve arbit | 35.0% | — |
| CVE-2020-11984 | CRIT 9.8 | apache http_server Apache HTTP server 2.4.32 to 2.4.44 mod_proxy_uwsgi info disclosure and possible RCE | 90.0% | — |
| CVE-2018-17191 | CRIT 9.8 | apache netbeans Apache NetBeans (incubating) 9.0 NetBeans Proxy Auto-Configuration (PAC) interpretation is vulnerable for remote command execution (RCE). Using the nashorn script engine the environment of the javascript execution for the Proxy Auto-Configuration leaks privile | 7.8% | — |
| CVE-2018-0007 | CRIT 9.8 | juniper junos An unauthenticated network-based attacker able to send a maliciously crafted LLDP packet to the local segment, through a local segment broadcast, may be able to cause a Junos device to enter an improper boundary check condition allowing a memory corruption to | 2.2% | — |
| CVE-2017-9800 | CRIT 9.8 | apache subversion A maliciously constructed svn+ssh:// URL would cause Subversion clients before 1.8.19, 1.9.x before 1.9.7, and 1.10.0.x through 1.10.0-alpha3 to run an arbitrary shell command. Such a URL could be generated by a malicious server, by a malicious user committing | 18.9% | — |
| CVE-2017-8390 | CRIT 9.8 | paloaltonetworks pan-os The DNS Proxy in Palo Alto Networks PAN-OS before 6.1.18, 7.x before 7.0.16, 7.1.x before 7.1.11, and 8.x before 8.0.3 allows remote attackers to execute arbitrary code via a crafted domain name. | 6.1% | — |
| CVE-2017-5636 | CRIT 9.8 | apache nifi In Apache NiFi before 0.7.2 and 1.x before 1.1.2 in a cluster environment, the proxy chain serialization/deserialization is vulnerable to an injection attack where a carefully crafted username could impersonate another user and gain their permissions on a repl | 3.6% | — |
| CVE-2017-0305 | CRIT 9.8 | f5 ssl_intercept_iapp F5 SSL Intercept iApp version 1.5.0 - 1.5.7 is vulnerable to an unauthenticated, remote attack that may allow modification of the BIG-IP system configuration, extraction of sensitive system files, and possible remote command execution on the system when deploy | 3.8% | — |