Apache
3,495 known vulnerabilities
Top Products
Unlimited memory allocation in redis protocol parser in Apache bRPC (all versions < 1.14.1) on all platforms allows atta
Session Fixation vulnerability in Apache Tomcat via rewrite valve. This issue affects Apache Tomcat: from 11.0.0-M1 thr
Improper Resource Shutdown or Release vulnerability in Apache Tomcat made Tomcat vulnerable to the made you reset attack
Deserialization of Untrusted Data vulnerability in Apache Seata (incubating). This issue affects Apache Seata (incubati
If untrusted users are allowed to configure JMS for Apache CXF, previously they could use RMI or LDAP URLs, potentially
Missing Origin Validation in WebSockets vulnerability in Apache Zeppelin. The attacker could access the Zeppelin server
Improper Input Validation vulnerability in Apache Zeppelin. The fix for JDBC URL validation in CVE-2024-31864 did not ac
Incomplete Blacklist to Cross-Site Scripting vulnerability in Apache Zeppelin. This issue affects Apache Zeppelin: befo
A carefully crafted request using the Image plugin could trigger an XSS vulnerability on Apache JSPWiki, which could al
A carefully crafted request when creating a header link using the wiki markup syntax, which could allow the attacker to
** UNSUPPORTED WHEN ASSIGNED ** Improper Output Neutralization for Logs vulnerability in Apache Struts. This issue affe
A bug in Apache HTTP Server 2.4.64 results in all "RewriteCond expr ..." tests evaluating as "true". Users are recomm
File access paths in configuration files uploaded by users with administrator access are not validated. This issue affe
Users with administrator access can create databases files outside the files area of the Fuseki server. This issue affe
Apache CXF stores large stream based messages as temporary files on the local filesystem. A bug was introduced which mea
Blind XXE Vulnerabilities in jackrabbit-spi-commons and jackrabbit-core in Apache Jackrabbit < 2.23.2 due to usage of an
The attacker can use the raft server protocol in an unauthenticated way. The attacker can see the server's resources, in
Uncontrolled Recursion vulnerability in Apache Commons Lang. This issue affects Apache Commons Lang: Starting with comm
Uncontrolled Resource Consumption vulnerability in Apache Tomcat if an HTTP/2 client did not acknowledge the initial set
For some unlikely configurations of multipart upload, an Integer Overflow vulnerability in Apache Tomcat could lead to a
Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability in Apache Tomc
Late Release of Memory after Effective Lifetime vulnerability in Apache HTTP Server. This issue affects Apache HTTP Ser
In some mod_ssl configurations on Apache HTTP Server versions through to 2.4.63, an HTTP desynchronisation attack allows
In certain proxy configurations, a denial of service attack against Apache HTTP Server versions 2.4.26 through to 2.4.63
In some mod_ssl configurations on Apache HTTP Server 2.4.35 through to 2.4.63, an access control bypass by trusted clien
Insufficient escaping of user-supplied data in mod_ssl in Apache HTTP Server 2.4.63 and earlier allows an untrusted SSL/
Server-Side Request Forgery (SSRF) in Apache HTTP Server on Windows allows to potentially leak NTLM hashes to a maliciou
SSRF in Apache HTTP Server with mod_proxy loaded allows an attacker to send outbound proxy requests to a URL controlled
HTTP response splitting in the core of Apache HTTP Server allows an attacker who can manipulate the Content-Type respons
Incorrect Permission Assignment for Critical Resource vulnerability in Apache APISIX(java-plugin-runner). Local listeni
A vulnerability of plugin openid-connect in Apache APISIX. This vulnerability will only have an impact if all of the fo
The terminal emulator of Apache Guacamole 1.5.5 and older does not properly validate console codes received from servers
Deserialization of Untrusted Data vulnerability in Apache Seata (incubating). This security vulnerability is the same a
Failure to Sanitize Special Elements into a Different Plane (Special Element Injection) vulnerability in Apache Airflow
# Summary Unauthorized users can perform Arbitrary File Read and Deserialization attack by submit job using restful api
ESI plugin does not have the limit for maximum inclusion depth, and that allows excessive memory consumption if maliciou
ACL configured in ip_allow.config or remap.config does not use IP addresses that are provided by PROXY protocol. Users
Authentication Bypass Using an Alternate Path or Channel vulnerability in Apache Tomcat. When using PreResources or Pos
Untrusted Search Path vulnerability in Apache Tomcat installer for Windows. During installation, the Tomcat installer fo
Allocation of Resources Without Limits or Throttling vulnerability in Apache Tomcat. This issue affects Apache Tomcat:
Allocation of resources for multipart headers with insufficient limits enabled a DoS vulnerability in Apache Commons Fil
Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability was discovered in Apache NuttX RTO
Out-of-bounds Write resulting in possible Heap-based Buffer Overflow vulnerability was discovered in tools/bdf-converter
In Apache CloudStack, a flaw in access control affects the listTemplates and listIsos APIs. A malicious Domain Admin or
A privilege escalation vulnerability exists in Apache CloudStack versions 4.10.0.0 through 4.20.0.0 where a malicious Do
A privilege escalation vulnerability exists in Apache CloudStack versions 4.10.0.0 through 4.20.0.0 where a malicious Do
When an Apache CloudStack user-account creates a CKS-based Kubernetes cluster in a project, the API key and the secret k
The CloudStack Quota plugin has an improper privilege management logic in version 4.20.0.0. Anyone with authenticated us
In CVE-2023-25194, we announced the RCE/Denial of service attack via SASL JAAS JndiLoginModule configuration in Kafka Co
A possible security vulnerability has been identified in Apache Kafka. This requires access to a alterConfig to the clus
Frequently Asked Questions
How many CVEs affect Apache?
Apache has 3,495 CVE records in our database, including 596 critical and 1319 high severity vulnerabilities. 37 of these are listed in CISA's Known Exploited Vulnerabilities catalog.
What are the most severe Apache vulnerabilities?
Apache has 596 critical severity (CVSS 9.0+) and 1319 high severity (CVSS 7.0-8.9) vulnerabilities. 37 vulnerabilities are confirmed as actively exploited in the wild.
How can I scan for Apache vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Apache products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Apache Vulnerabilities
CyberStrike scans your infrastructure for Apache vulnerabilities and provides real-time remediation guidance.
Get Started