- Server
- SSH-2.0-OpenSSH_3.8.1p1 Debian-8.sarge.4
- Host key
- ssh-rsa a720df9b6c9d88c2…
Raw response
SSH-2.0-OpenSSH_3.8.1p1 Debian-8.sarge.4
Host
Tags: Hosting End-of-life software
As of our latest check on 2026-05-29, 91.109.28.60 (Leaseweb Deutschland GmbH, AS28753, Germany) had 2 open ports (22, 80) and 435 known CVEs, 1 known to be exploited.
Open ports and CVEs as of our latest check of this host, 2026-05-29.
CVEs by severity: CRITICAL 63 HIGH 165 MEDIUM 184 LOW 23
A match is an indication, not proof: it is based on the software version a service reported, and fixes are often backported without changing the version. See the list
Not counted: 52 on a distribution build — the fix may be backported (http_server 1.3.33, openssh 3.8.1p1). See them
Not counted: 1 only affects a particular platform; this host's is not known (openssh 3.8.1p1). See them
Not counted: 6 fixed by the distribution (openssh 3.8.1p1). See them
Not counted: 6 only affect another platform (php 4.3.10, http_server 1.3.33). See them
Not a Tor relay, not a VPN or privacy relay address, and not on a current public blocklist.
SSH-2.0-OpenSSH_3.8.1p1 Debian-8.sarge.4
HTTP/1.1 200 OK Date: Fri, 29 May 2026 08:46:59 GMT Server: Apache/1.3.33 (Debian GNU/Linux) X-Powered-By: PHP/4.3.10-15 Transfer-Encoding: chunked Content-Type: text/html; charset=utf-8 89 <html> <head> <title>s218</title> </head> <body> <smaii><font color=888888>s218</font></small><br> <b> <font color=red> IP: 72.11.149.151
These CVEs were matched on software built by an operating-system distribution whose package revision the service does not show. Distributions often fix a flaw without changing the upstream version number, so whether this build is affected cannot be told from its version. They are not counted. 1 of them is known to be exploited.
CVEs by severity: CRITICAL 11 HIGH 18 MEDIUM 23
| CVE | Software |
|---|---|
| CVE-2021-40438 CRITICAL 9.0 known exploited | http_server 1.3.33 · port 80 |
| CVE-2009-3555 CRITICAL 9.8 | http_server 1.3.33 · port 80 |
| CVE-2021-39275 CRITICAL 9.8 | http_server 1.3.33 · port 80 |
| CVE-2021-44790 CRITICAL 9.8 | http_server 1.3.33 · port 80 |
| CVE-2022-22720 CRITICAL 9.8 | http_server 1.3.33 · port 80 |
| CVE-2022-31813 CRITICAL 9.8 | http_server 1.3.33 · port 80 |
| CVE-2026-28780 CRITICAL 9.8 | http_server 1.3.33 · port 80 |
| CVE-2017-9788 CRITICAL 9.1 | http_server 1.3.33 · port 80 |
| CVE-2022-22721 CRITICAL 9.1 | http_server 1.3.33 · port 80 |
| CVE-2022-28615 CRITICAL 9.1 | http_server 1.3.33 · port 80 |
| CVE-2026-42535 CRITICAL 9.1 | http_server 1.3.33 · port 80 |
| CVE-2026-24072 HIGH 8.8 | http_server 1.3.33 · port 80 |
| CVE-2026-93546 HIGH 8.8 | http_server 1.3.33 · port 80 |
| CVE-2025-58098 HIGH 8.3 | http_server 1.3.33 · port 80 |
| CVE-2006-3747 HIGH 7.6 | http_server 1.3.33 · port 80 |
| CVE-2004-0174 HIGH 7.5 | http_server 1.3.33 · port 80 |
| CVE-2006-20001 HIGH 7.5 | http_server 1.3.33 · port 80 |
| CVE-2017-9798 HIGH 7.5 | http_server 1.3.33 · port 80 |
| CVE-2018-1303 HIGH 7.5 | http_server 1.3.33 · port 80 |
| CVE-2021-34798 HIGH 7.5 | http_server 1.3.33 · port 80 |
| CVE-2022-22719 HIGH 7.5 | http_server 1.3.33 · port 80 |
| CVE-2022-29404 HIGH 7.5 | http_server 1.3.33 · port 80 |
| CVE-2022-30556 HIGH 7.5 | http_server 1.3.33 · port 80 |
| CVE-2023-31122 HIGH 7.5 | http_server 1.3.33 · port 80 |
| CVE-2026-29169 HIGH 7.5 | http_server 1.3.33 · port 80 |
| CVE-2026-34059 HIGH 7.5 | http_server 1.3.33 · port 80 |
| CVE-2025-49812 HIGH 7.4 | http_server 1.3.33 · port 80 |
| CVE-2023-38709 HIGH 7.3 | http_server 1.3.33 · port 80 |
| CVE-2004-2343 HIGH 7.2 | http_server 1.3.33 · port 80 |
| CVE-2010-0010 MEDIUM 6.8 | http_server 1.3.33 · port 80 |
| CVE-2026-29170 MEDIUM 6.1 | http_server 1.3.33 · port 80 |
| CVE-2018-1301 MEDIUM 5.9 | http_server 1.3.33 · port 80 |
| CVE-2018-1302 MEDIUM 5.9 | http_server 1.3.33 · port 80 |
| CVE-2022-28614 MEDIUM 5.3 | http_server 1.3.33 · port 80 |
| CVE-2022-37436 MEDIUM 5.3 | http_server 1.3.33 · port 80 |
| CVE-2026-33857 MEDIUM 5.3 | http_server 1.3.33 · port 80 |
| CVE-2026-34032 MEDIUM 5.3 | http_server 1.3.33 · port 80 |
| CVE-2004-0942 MEDIUM 5.0 | http_server 1.3.33 · port 80 |
| CVE-2007-6750 MEDIUM 5.0 | http_server 1.3.33 · port 80 |
| CVE-2011-3368 MEDIUM 5.0 | http_server 1.3.33 · port 80 |
| CVE-2015-0228 MEDIUM 5.0 | http_server 1.3.33 · port 80 |
| CVE-2026-33006 MEDIUM 4.8 | http_server 1.3.33 · port 80 |
| CVE-2007-3304 MEDIUM 4.7 | http_server 1.3.33 · port 80 |
| CVE-2005-3352 MEDIUM 4.3 | http_server 1.3.33 · port 80 |
| CVE-2006-3918 MEDIUM 4.3 | http_server 1.3.33 · port 80 |
| CVE-2006-5752 MEDIUM 4.3 | http_server 1.3.33 · port 80 |
| CVE-2007-5000 MEDIUM 4.3 | http_server 1.3.33 · port 80 |
| CVE-2007-6388 MEDIUM 4.3 | http_server 1.3.33 · port 80 |
| CVE-2008-2939 MEDIUM 4.3 | http_server 1.3.33 · port 80 |
| CVE-2011-4317 MEDIUM 4.3 | http_server 1.3.33 · port 80 |
| CVE-2016-8612 MEDIUM 4.3 | http_server 1.3.33 · port 80 |
| CVE-2010-4755 MEDIUM 4.0 | openssh 3.8.1p1 · port 22 |
These CVEs only apply when the software runs on a particular platform (for example Windows), and this host's platform is not known. They are not counted.
CVEs by severity: MEDIUM 1
| CVE | Software |
|---|---|
| CVE-2008-4109 MEDIUM 5.0 | openssh 3.8.1p1 · port 22 |
The distribution's security data says the package revision this service shows already has the fix for these CVEs, or that its build is not affected. They are not counted.
CVEs by severity: CRITICAL 1 HIGH 1 MEDIUM 3 LOW 1
| CVE | Software |
|---|---|
| CVE-2010-4478 CRITICAL 9.8 | openssh 3.8.1p1 · port 22 |
| CVE-2014-1692 HIGH 7.3 | openssh 3.8.1p1 · port 22 |
| CVE-2004-1653 MEDIUM 6.4 | openssh 3.8.1p1 · port 22 |
| CVE-2011-4327 MEDIUM 5.5 | openssh 3.8.1p1 · port 22 |
| CVE-2006-0883 MEDIUM 5.0 | openssh 3.8.1p1 · port 22 |
| CVE-2008-3259 LOW 1.2 | openssh 3.8.1p1 · port 22 |
These CVEs need a platform this host visibly does not run (for example a flaw of the Windows build on a Linux host). They are not counted.
CVEs by severity: CRITICAL 2 HIGH 2 MEDIUM 2
| CVE | Software |
|---|---|
| CVE-2012-2376 HIGH 10.0 | php 4.3.10 · port 80 |
| CVE-2015-4642 CRITICAL 9.8 | php 4.3.10 · port 80 |
| CVE-2024-3566 CRITICAL 9.8 | php 4.3.10 · port 80 |
| CVE-2024-40898 HIGH 7.5 | http_server 1.3.33 · port 80 |
| CVE-2022-28330 MEDIUM 5.3 | http_server 1.3.33 · port 80 |
| CVE-2011-0754 MEDIUM 4.4 | php 4.3.10 · port 80 |
Every port that has answered a connection on this address, and when. A port is listed as open above only when a service was identified on it. Times are UTC.