Apache
3,495 known vulnerabilities
Top Products
JWT tokens that were used by workers in Kubernetes Executors have been exposed to users who had read only access to Kube
Camel-CXF and Camel-Knative Message Header Injection via Missing Inbound Filtering The CXF and Knative HeaderFilterStra
Improper Control of Generation of Code ('Code Injection'), Improper Neutralization of Directives in Dynamically Evaluate
Improper Authentication vulnerability in Apache OFBiz via Password-Change Logic Flaw Leading to Remote Code Execution T
Improper Authorization vulnerability in Apache OFBiz Webtools. This issue affects Apache OFBiz: before 24.09.06. Users
Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection') vulnerability in Apache OFBiz. Thi
Improper Control of Generation of Code ('Code Injection') vulnerability in email services of Apache OFBiz. This issue a
Use of Hard-coded Cryptographic Key vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 24.09.06. U
Server-Side Request Forgery (SSRF) vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 24.09.06. Us
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache OFBiz. This issue affects Apache OFB
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache OFBiz. Thi
Improper Access Control vulnerability in Apache OFBiz in multi-tenant deployments. This issue affects Apache OFBiz: bef
Improper Authentication vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 24.09.06. Users are rec
Improper Neutralization of Special Elements used in an Expression Language Statement ('Expression Language Injection') v
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'), Improper Limitation of a Pathname
Improper Input Validation vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 24.09.06. Users are r
Server-Side Request Forgery (SSRF) vulnerability in Apache OFBiz via Content component operations. This issue affects A
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache OFBiz. This issu
Improper Neutralization of Special Elements Used in a Template Engine vulnerability in Apache OFBiz. This issue affects
Code injection in SQL code generation in Apache Flink 1.15.0 through 1.20.x and 2.0.0 through 2.x allows authenticated u
Uncontrolled Recursion vulnerability in Apache Commons. When processing an untrusted configuration file, Commons Config
Improper Authorization vulnerability when multiple method constraints define an HTTP method for the same extension in Ap
Observable Timing Discrepancy vulnerability when comparing AJP secret in Apache Tomcat. This issue affects Apache Tomca
Improper Handling of Case Sensitivity vulnerability in LockOutRealm in Apache Tomcat. This issue affects Apache Tomcat:
DEPRECATED: Authentication Bypass Issues vulnerability in digest authentication in Apache Tomcat. This issue affects Ap
Exposure of HTTP Authentication Header to unexpected hosts during WebSocket authentication vulnerability in Apache Tomca
Improper Input Validation vulnerability in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0
Allocation of Resources Without Limits or Throttling vulnerability in Apache Tomcat. This issue affects Apache Tomcat:
The OpenSearch logging provider, when configured with a `host` URL that embeds credentials (for example `https://user:pa
The Elasticsearch logging provider, when configured with a `host` URL that embeds credentials (for example `https://user
The optional extension component TinkerpopClientService is missing the Restricted annotation with the Execute Code Requi
Instances deployed via the Proxmox extension allow unauthorized access to instances belonging to other tenants. This
Account users are allowed by default to register templates to be downloaded directly to the primary storage for deployin
Due to multiple time-of-check time-of-use race conditions in the resource count check and increment logic, as well as mi
Missing MinIO policy cleanup on bucket deletion via Apache CloudStack allows users to retain access to buckets which the
The CloudStack Backup plugin has an improper access logic in versions 4.21.0.0 and 4.22.0.0. Anyone with authenticated u
The CloudStack Backup plugin has an improper access logic in versions 4.21.0.0 and 4.22.0.0. Anyone with authenticated u
The CloudStack Backup plugin has an improper authorization logic in versions 4.21.0.0 and 4.22.0.0. Anyone with authenti
FolderUploadsFileManager in Apache Wicket does not validate or sanitize the uploadFieldId parameter or the clientFileNam
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Wicket. This issue affects Apache Wi
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache Wicket. Th
Missing invocation of Servlet http web request method changeSessionId after session binding can be exploited for a sessi
Heap-based Buffer Overflow vulnerability in mod_proxy_ajp of Apache HTTP Server. If mod_proxy_ajp connects to a maliciou
Allocation of Resources Without Limits or Throttling vulnerability in Apache HTTP Server's mod_md via OCSP response dat
Origin Validation Error, Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Improper Neutra
Memory Allocation with Excessive Size Value vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0.
Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift. This issue affects Apache Thrift:
In Apache Iceberg, the table's metadata files are control files: they tell readers which data files belong to the table
In plain terms, Apache Polaris is supposed to issue short-lived GCS credentials that only work for one table's files, bu
Apache Polaris accepts literal `*` characters in namespace and table names. When it later builds temporary S3 access pol
Frequently Asked Questions
How many CVEs affect Apache?
Apache has 3,495 CVE records in our database, including 596 critical and 1319 high severity vulnerabilities. 37 of these are listed in CISA's Known Exploited Vulnerabilities catalog.
What are the most severe Apache vulnerabilities?
Apache has 596 critical severity (CVSS 9.0+) and 1319 high severity (CVSS 7.0-8.9) vulnerabilities. 37 vulnerabilities are confirmed as actively exploited in the wild.
How can I scan for Apache vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Apache products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Apache Vulnerabilities
CyberStrike scans your infrastructure for Apache vulnerabilities and provides real-time remediation guidance.
Get Started