Apache
3,495 known vulnerabilities
Top Products
Reflected cross-site scripting vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 24.09.03. Users
Unrestricted Upload of File with Dangerous Type vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before
An out-of-bounds Write vulnerability in Apache OpenOffice could allow an attacker to craft a document that would crash t
Apache OpenOffice documents can contain links. A missing Authorization vulnerability in Apache OpenOffice allowed an att
Apache OpenOffice documents can contain links to other files. A missing Authorization vulnerability in Apache OpenOffice
Apache OpenOffice Calc spreadsheet can contain links to other files, in the form of "external data sources". A missing A
Apache OpenOffice documents can contain links. A missing Authorization vulnerability in Apache OpenOffice allowed an att
Apache OpenOffice documents can contain links. A missing Authorization vulnerability in Apache OpenOffice allowed an att
An attacker with a valid read-only account can bypass Doris MCP Server’s read-only mode due to improper access control,
Sensitive data exposure via logging in basic-auth leads to plaintext usernames and passwords written to error logs and f
User with CREATE and no UPDATE privilege for Pools, Connections, Variables could update existing records via bulk create
API users via `/api/v2/dagReports` could perform Dag code execution in the context of the api-server if the api-server w
An example dag `example_dag_decorator` had non-validated parameter that allowed the UI user to redirect the example to a
Improper Resource Shutdown or Release vulnerability in Apache Tomcat. If an error occurred (including exceeding limits)
Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in Apache Tomcat. Tomcat did not escape ANS
Relative Path Traversal vulnerability in Apache Tomcat. The fix for bug 60013 introduced a regression where the r
Apache Syncope offers the ability to extend / customize the base behavior on every deployment by allowing to provide cus
Apache Geode is vulnerable to CSRF attacks through GET requests to the Management and Monitoring REST API that could all
** UNSUPPORTED WHEN ASSIGNED ** Inefficient Regular Expression Complexity vulnerability in Apache Traffic Control. This
A Deserialization of Untrusted Data vulnerability exists in the Apache ActiveMQ NMS AMQP Client. This issue affects all
This issue affects Apache Spark versions before 3.4.4, 3.5.2 and 4.0.0. Apache Spark versions before 4.0.0, 3.5.2 an
Malicious script injection ('Cross-site Scripting') vulnerability in Apache Geode web-api (REST). This vulnerability all
Incorrect Execution-Assigned Permissions vulnerability in Apache StreamPark. This issue affects Apache StreamPark: from
Apache Flink CDC version 3.4.0 was vulnerable to a SQL injection via maliciously crafted identifiers eg. crafted databas
Server-Side Request Forgery (SSRF) vulnerability in Apache Kylin. This issue affects Apache Kylin: from 4.0.0 through 5
Files or Directories Accessible to External Parties vulnerability in Apache Kylin. You are fine as long as the Kylin's
Authentication Bypass Using an Alternate Path or Channel vulnerability in Apache Kylin. This issue affects Apache Kylin
Deserialization of untrusted data in python in pyfory versions 0.12.0 through 0.12.2, or the legacy pyfury versions from
Apache Airflow 3 introduced a change to the handling of sensitive information in Connections. The intent was to restrict
Improper permission check in ZooKeeper AdminServer lets authorized clients to run snapshot and restore command with insu
Deserialization of Untrusted Data vulnerability in Apache IoTDB. This issue affects Apache IoTDB: from 1.0.0 before 2.0
A vulnerability in Apache IoTDB. This issue affects Apache IoTDB: from 1.3.3 through 1.3.4, from 2.0.1-beta through 2.0
A vulnerability in Apache Fory allows a remote attacker to cause a Denial of Service (DoS). The issue stems from the ins
Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection') vulnerability in Apache HertzBeat .
XML Injection RCE by parse http sitemap xml response vulnerability in Apache HertzBeat. The attacker needs t
Deserialization of Untrusted Data vulnerability in Apache Jackrabbit Core and Apache Jackrabbit JCR Commons. This issue
Incorrect Default Permissions vulnerability in Apache DolphinScheduler. This issue affects Apache DolphinScheduler: bef
Improper Input Validation vulnerability in Apache DolphinScheduler. An authenticated user can execute any shell script s
Privilege Defined With Unsafe Actions vulnerability in Apache Cassandra. An user with MODIFY permission ON ALL KEYSPACES
Improper Output Neutralization for Logs vulnerability in Apache Log4cxx. When using JSONLayout, not all payload bytes a
Improper Output Neutralization for Logs vulnerability in Apache Log4cxx. When using HTMLLayout, logger names are not p
SQL Injection vulnerability in Apache StreamPark. This issue affects Apache StreamPark: from 2.1.4 before 2.1.6. Users
Critical XXE in Apache Tika (tika-parser-pdf-module) in Apache Tika 1.13 through and including 3.2.1 on all platforms al
CWE-918 Server-Side Request Forgery (SSRF) in eventmesh-runtime module in WebhookUtil.java on windows\linux\mac os e.g.
** UNSUPPORTED WHEN ASSIGNED ** Improper Neutralization of Expression/Command Delimiters vulnerability in Apache Commons
Improper Control of Generation of Code ('Code Injection') vulnerability leading to a possible RCE in Apache OFBiz scrum
Apache Superset contains an improper access control vulnerability in its /explore endpoint. A missing authorization chec
A bypass of the DISALLOWED_SQL_FUNCTIONS security feature in Apache Superset allows for the execution of blocked SQL fun
When a guest user accesses a chart in Apache Superset, the API response from the /chart/data endpoint includes a query f
A stored Cross-Site Scripting (XSS) vulnerability exists in Apache Superset's chart visualization. An authenticated user
Frequently Asked Questions
How many CVEs affect Apache?
Apache has 3,495 CVE records in our database, including 596 critical and 1319 high severity vulnerabilities. 37 of these are listed in CISA's Known Exploited Vulnerabilities catalog.
What are the most severe Apache vulnerabilities?
Apache has 596 critical severity (CVSS 9.0+) and 1319 high severity (CVSS 7.0-8.9) vulnerabilities. 37 vulnerabilities are confirmed as actively exploited in the wild.
How can I scan for Apache vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Apache products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Apache Vulnerabilities
CyberStrike scans your infrastructure for Apache vulnerabilities and provides real-time remediation guidance.
Get Started