Every CVE whose affected-product data names Apache Nutch, ordered by CVSS severity, with EPSS exploit prediction and CISA KEV status.
CVEs (5)
CVE-2016-6809 — CVSS 9.8 (critical): Apache Tika before 1.14 allows Java code execution for serialized objects embedded in MATLAB files. The issue exists because Tika invokes…
CVE-2026-41871 — CVSS 9.8 (critical): Missing Authorization, Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability in Apache Nutch…
CVE-2021-23901 — CVSS 9.1 (critical): An XML external entity (XXE) injection vulnerability was discovered in the Nutch DmozParser and is known to affect Nutch versions < 1.18…
CVE-2026-41869 — CVSS 9.1 (critical): Missing Authorization, Improper Resource Shutdown and Job Interruption vulnerability in Apache Nutch Server (Nutch REST API). This issue…
CVE-2026-41870 — CVSS 8.8 (high): Missing Authorization, Improper Control of Generation of Code ('Code Injection'), Improper Control of Dynamically-Managed Code Resources…