An issue was discovered in Embedthis GoAhead before 4.0.1 and Appweb before 7.0.2. The server mishandles some HTTP request fields associated with time, which results in a NULL pointer dereference, as demonstrated by If-Modified-Since or If-Unmodified-Since with a month greater than 11.
Conclusion & alert: CVE-2018-15504 is rated High Exploit Risk (72/100): CVSS High severity, with medium exploitation likelihood (EPSS 0.98%). Core evidence: 2 public exploit reference(s) are indexed (Exploit-DB). Mandatory action: Public exploits are available—assess exposure, apply mitigations, and prioritize patching.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
| EDB-ID | Source | Kind | Published | Link |
|---|---|---|---|---|
| — | nvd_ref | exploit_tag | Exploit-DB ↗ | |
| — | nvd_ref | exploit_tag | Exploit-DB ↗ |
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-05-12 | 0.84% | 0.98% | +0.14% |
| 2 | 2026-05-10 | 0.47% | 0.84% | +0.37% |
| 3 | 2026-03-13 | — | 0.47% | — |
Full EPSS history (17 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 7.5 | 3.1 | HIGH |
|
3.9 | 3.6 | [email protected] |
| 5.0 | 2.0 | MEDIUM |
|
10.0 | 2.9 | [email protected] |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| embedthis | appweb | < 7.0.2 | cpe:2.3:a:embedthis:appweb:*:*:*:*:*:*:*:* |
| embedthis | goahead | < 4.0.1 | cpe:2.3:a:embedthis:goahead:*:*:*:*:*:*:*:* |
| juniper | junos | 12.1x46 | cpe:2.3:o:juniper:junos:12.1x46:-:*:*:*:*:*:* |
| juniper | junos | 12.1x46 | cpe:2.3:o:juniper:junos:12.1x46:d10:*:*:*:*:*:* |
| juniper | junos | 12.1x46 | cpe:2.3:o:juniper:junos:12.1x46:d15:*:*:*:*:*:* |
| juniper | junos | 12.1x46 | cpe:2.3:o:juniper:junos:12.1x46:d20:*:*:*:*:*:* |
| juniper | junos | 12.1x46 | cpe:2.3:o:juniper:junos:12.1x46:d25:*:*:*:*:*:* |
| juniper | junos | 12.1x46 | cpe:2.3:o:juniper:junos:12.1x46:d30:*:*:*:*:*:* |
| juniper | junos | 12.1x46 | cpe:2.3:o:juniper:junos:12.1x46:d35:*:*:*:*:*:* |
| juniper | junos | 12.1x46 | cpe:2.3:o:juniper:junos:12.1x46:d40:*:*:*:*:*:* |
| juniper | junos | 12.1x46 | cpe:2.3:o:juniper:junos:12.1x46:d45:*:*:*:*:*:* |
| juniper | junos | 12.1x46 | cpe:2.3:o:juniper:junos:12.1x46:d50:*:*:*:*:*:* |
| juniper | junos | 12.1x46 | cpe:2.3:o:juniper:junos:12.1x46:d55:*:*:*:*:*:* |
| juniper | junos | 12.1x46 | cpe:2.3:o:juniper:junos:12.1x46:d60:*:*:*:*:*:* |
| juniper | junos | 12.1x46 | cpe:2.3:o:juniper:junos:12.1x46:d65:*:*:*:*:*:* |
| juniper | junos | 12.1x46 | cpe:2.3:o:juniper:junos:12.1x46:d66:*:*:*:*:*:* |
| juniper | junos | 12.1x46 | cpe:2.3:o:juniper:junos:12.1x46:d67:*:*:*:*:*:* |
| juniper | junos | 12.1x46 | cpe:2.3:o:juniper:junos:12.1x46:d70:*:*:*:*:*:* |
| juniper | junos | 12.1x46 | cpe:2.3:o:juniper:junos:12.1x46:d71:*:*:*:*:*:* |
| juniper | junos | 12.1x46 | cpe:2.3:o:juniper:junos:12.1x46:d72:*:*:*:*:*:* |
| juniper | junos | 12.1x46 | cpe:2.3:o:juniper:junos:12.1x46:d73:*:*:*:*:*:* |
| juniper | junos | 12.1x46 | cpe:2.3:o:juniper:junos:12.1x46:d76:*:*:*:*:*:* |
| juniper | junos | 12.1x46 | cpe:2.3:o:juniper:junos:12.1x46:d77:*:*:*:*:*:* |
| juniper | junos | 12.3x48 | cpe:2.3:o:juniper:junos:12.3x48:-:*:*:*:*:*:* |
| juniper | junos | 12.3x48 | cpe:2.3:o:juniper:junos:12.3x48:d10:*:*:*:*:*:* |
| juniper | junos | 12.3x48 | cpe:2.3:o:juniper:junos:12.3x48:d15:*:*:*:*:*:* |
| juniper | junos | 12.3x48 | cpe:2.3:o:juniper:junos:12.3x48:d20:*:*:*:*:*:* |
| juniper | junos | 12.3x48 | cpe:2.3:o:juniper:junos:12.3x48:d25:*:*:*:*:*:* |
| juniper | junos | 12.3x48 | cpe:2.3:o:juniper:junos:12.3x48:d30:*:*:*:*:*:* |
| juniper | junos | 12.3x48 | cpe:2.3:o:juniper:junos:12.3x48:d35:*:*:*:*:*:* |
| juniper | junos | 12.3x48 | cpe:2.3:o:juniper:junos:12.3x48:d40:*:*:*:*:*:* |
| juniper | junos | 12.3x48 | cpe:2.3:o:juniper:junos:12.3x48:d45:*:*:*:*:*:* |
| juniper | junos | 12.3x48 | cpe:2.3:o:juniper:junos:12.3x48:d50:*:*:*:*:*:* |
| juniper | junos | 12.3x48 | cpe:2.3:o:juniper:junos:12.3x48:d51:*:*:*:*:*:* |
| juniper | junos | 12.3x48 | cpe:2.3:o:juniper:junos:12.3x48:d55:*:*:*:*:*:* |
| juniper | junos | 12.3x48 | cpe:2.3:o:juniper:junos:12.3x48:d60:*:*:*:*:*:* |
| juniper | junos | 12.3x48 | cpe:2.3:o:juniper:junos:12.3x48:d65:*:*:*:*:*:* |
| juniper | junos | 12.3x48 | cpe:2.3:o:juniper:junos:12.3x48:d66:*:*:*:*:*:* |
| juniper | junos | 12.3x48 | cpe:2.3:o:juniper:junos:12.3x48:d70:*:*:*:*:*:* |
| juniper | junos | 12.3x48 | cpe:2.3:o:juniper:junos:12.3x48:d75:*:*:*:*:*:* |
| juniper | junos | 15.1x49 | cpe:2.3:o:juniper:junos:15.1x49:-:*:*:*:*:*:* |
| juniper | junos | 15.1x49 | cpe:2.3:o:juniper:junos:15.1x49:d10:*:*:*:*:*:* |
| juniper | junos | 15.1x49 | cpe:2.3:o:juniper:junos:15.1x49:d100:*:*:*:*:*:* |
| juniper | junos | 15.1x49 | cpe:2.3:o:juniper:junos:15.1x49:d110:*:*:*:*:*:* |
| juniper | junos | 15.1x49 | cpe:2.3:o:juniper:junos:15.1x49:d120:*:*:*:*:*:* |
| juniper | junos | 15.1x49 | cpe:2.3:o:juniper:junos:15.1x49:d130:*:*:*:*:*:* |
| juniper | junos | 15.1x49 | cpe:2.3:o:juniper:junos:15.1x49:d131:*:*:*:*:*:* |
| juniper | junos | 15.1x49 | cpe:2.3:o:juniper:junos:15.1x49:d140:*:*:*:*:*:* |
| juniper | junos | 15.1x49 | cpe:2.3:o:juniper:junos:15.1x49:d15:*:*:*:*:*:* |
| juniper | junos | 15.1x49 | cpe:2.3:o:juniper:junos:15.1x49:d150:*:*:*:*:*:* |
| juniper | junos | 15.1x49 | cpe:2.3:o:juniper:junos:15.1x49:d160:*:*:*:*:*:* |
| juniper | junos | 15.1x49 | cpe:2.3:o:juniper:junos:15.1x49:d170:*:*:*:*:*:* |
| juniper | junos | 15.1x49 | cpe:2.3:o:juniper:junos:15.1x49:d20:*:*:*:*:*:* |
| juniper | junos | 15.1x49 | cpe:2.3:o:juniper:junos:15.1x49:d25:*:*:*:*:*:* |
| juniper | junos | 15.1x49 | cpe:2.3:o:juniper:junos:15.1x49:d30:*:*:*:*:*:* |
| juniper | junos | 15.1x49 | cpe:2.3:o:juniper:junos:15.1x49:d35:*:*:*:*:*:* |
| juniper | junos | 15.1x49 | cpe:2.3:o:juniper:junos:15.1x49:d40:*:*:*:*:*:* |
| juniper | junos | 15.1x49 | cpe:2.3:o:juniper:junos:15.1x49:d45:*:*:*:*:*:* |
| juniper | junos | 15.1x49 | cpe:2.3:o:juniper:junos:15.1x49:d50:*:*:*:*:*:* |
| juniper | junos | 15.1x49 | cpe:2.3:o:juniper:junos:15.1x49:d55:*:*:*:*:*:* |
| juniper | junos | 15.1x49 | cpe:2.3:o:juniper:junos:15.1x49:d60:*:*:*:*:*:* |
| juniper | junos | 15.1x49 | cpe:2.3:o:juniper:junos:15.1x49:d65:*:*:*:*:*:* |
| juniper | junos | 15.1x49 | cpe:2.3:o:juniper:junos:15.1x49:d70:*:*:*:*:*:* |
| juniper | junos | 15.1x49 | cpe:2.3:o:juniper:junos:15.1x49:d75:*:*:*:*:*:* |
| juniper | junos | 15.1x49 | cpe:2.3:o:juniper:junos:15.1x49:d80:*:*:*:*:*:* |
| juniper | junos | 15.1x49 | cpe:2.3:o:juniper:junos:15.1x49:d90:*:*:*:*:*:* |
| juniper | junos | 12.3 | cpe:2.3:o:juniper:junos:12.3:-:*:*:*:*:*:* |
| juniper | junos | 12.3 | cpe:2.3:o:juniper:junos:12.3:r1:*:*:*:*:*:* |
| juniper | junos | 12.3 | cpe:2.3:o:juniper:junos:12.3:r10:*:*:*:*:*:* |
| juniper | junos | 12.3 | cpe:2.3:o:juniper:junos:12.3:r10-s1:*:*:*:*:*:* |
| juniper | junos | 12.3 | cpe:2.3:o:juniper:junos:12.3:r10-s2:*:*:*:*:*:* |
| juniper | junos | 12.3 | cpe:2.3:o:juniper:junos:12.3:r11:*:*:*:*:*:* |
| juniper | junos | 12.3 | cpe:2.3:o:juniper:junos:12.3:r12:*:*:*:*:*:* |
| juniper | junos | 12.3 | cpe:2.3:o:juniper:junos:12.3:r12-s1:*:*:*:*:*:* |
| juniper | junos | 12.3 | cpe:2.3:o:juniper:junos:12.3:r12-s10:*:*:*:*:*:* |
| juniper | junos | 12.3 | cpe:2.3:o:juniper:junos:12.3:r12-s11:*:*:*:*:*:* |
| juniper | junos | 12.3 | cpe:2.3:o:juniper:junos:12.3:r12-s12:*:*:*:*:*:* |
| juniper | junos | 12.3 | cpe:2.3:o:juniper:junos:12.3:r12-s3:*:*:*:*:*:* |
| juniper | junos | 12.3 | cpe:2.3:o:juniper:junos:12.3:r12-s4:*:*:*:*:*:* |
| juniper | junos | 12.3 | cpe:2.3:o:juniper:junos:12.3:r12-s6:*:*:*:*:*:* |
| URL | Tags |
|---|---|
| https://github.com/embedthis/appweb/commit/66067ae6d1fa08b37a270e7dc1821df52ed2daef | Patch Third Party Advisory |
| https://github.com/embedthis/appweb/issues/605 | Exploit Patch Third Party Advisory |
| https://github.com/embedthis/goahead/issues/264 | Exploit Patch Third Party Advisory |
| https://supportportal.juniper.net/s/article/2019-07-Security-Bulletin-Junos-OS-J-Web-Denial-of-Service-due-to-multiple-vulnerabilities-in-Embedthis-Appweb-Server | Third Party Advisory |
| https://supportportal.juniper.net/s/article/2021-07-Security-Bulletin-Junos-OS-Multiple-J-Web-vulnerabilities-resolved | Third Party Advisory |