Apache
3,495 known vulnerabilities
Top Products
Improper Authorization vulnerability in Apache Superset when FAB_ADD_SECURITY_API is enabled (disabled by default). Allo
Generation of Error Message Containing analytics metadata Information in Apache Superset. This issue affects Apache Sup
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Superset. S
Insufficient validation of filenames against control characters in Apache Subversion repositories served via mod_dav_svn
Apache Hive Metastore (HMS) uses SerializationUtilities#deserializeObjectWithTypeInformation method when filtering and f
Improper authentication of an HTTP endpoint in the S3 Gateway of Apache Ozone 1.4.0 allows any authenticated Kerberos us
Deserialization of untrusted data in IPC and Parquet readers in the Apache Arrow R package versions 4.0.0 through 16.1.0
Out-of-bounds Read vulnerability in Apache NimBLE. Missing proper validation of HCI Number Of Completed Packets could l
Out-of-bounds Read vulnerability in Apache NimBLE. Missing proper validation of HCI advertising report could lead to ou
Improper Validation of Array Index vulnerability in Apache NimBLE. Lack of input validation for HCI events from control
Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in Apache NimBLE. Specially crafte
Inadequate Encryption Strength vulnerability in Apache Answer. This issue affects Apache Answer: through 1.4.0. The id
Apache NiFi 1.16.0 through 1.28.0 and 2.0.0-M1 through 2.0.0-M4 include optional debug logging of Parameter Context valu
In bta_hd_set_report_act of bta_hd_act.cc, there is a possible out-of-bounds read due to an integer overflow. This could
Files or Directories Accessible to External Parties, Improper Privilege Management vulnerability in Apache Kafka Clients
Incorrect object recycling and reuse vulnerability in Apache Tomcat. This issue affects Apache Tomcat: 11.0.0, 10.1.31,
Incorrect object re-cycling and re-use vulnerability in Apache Tomcat. Incorrect recycling of the request and response u
Unchecked Error Condition vulnerability in Apache Tomcat. If Tomcat is configured to use a custom Jakarta Authentication
Improper Control of Generation of Code ('Code Injection'), Cross-Site Request Forgery (CSRF), : Improper Neutralization
Server-Side Request Forgery (SSRF), Improper Control of Generation of Code ('Code Injection') vulnerability in Apache OF
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache HertzBeat. This issue affects Apache
Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Apache HertzBeat (i
Deserialization of Untrusted Data vulnerability in Apache HertzBeat. This vulnerability can only be exploited by author
Apache Airflow versions before 2.10.3 contain a vulnerability that could expose sensitive configuration variables in tas
Unchecked return value can allow Apache Traffic Server to retain privileges on startup. This issue affects Apache Traff
Valid Host header field can cause Apache Traffic Server to crash on some platforms. This issue affects Apache Traffic S
Improper Input Validation vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 8.0.0
Account users in Apache CloudStack by default are allowed to register templates to be downloaded directly to the primary
Airflow versions before 2.10.3 have a vulnerability that allows authenticated users with audit log access to see sensiti
When using IPAuthenticationProvider in ZooKeeper Admin Server there is a possibility of Authentication Bypass by Spoofin
Allocation of Resources Without Limits or Throttling vulnerability in Apache Tomcat. This issue affects Apache Tomcat:
Session Fixation vulnerability in Apache Kylin. This issue affects Apache Kylin: from 2.0.0 through 4.x. Users are rec
Deserialization of Untrusted Data vulnerability in Apache Lucene.Net.Replicator. This issue affects Apache Lucene.NET's
Apache NiFi 1.10.0 through 1.27.0 and 2.0.0-M1 through 2.0.0-M3 support a description field for Parameters in a Paramete
When editing objects in the Syncope Console, incomplete HTML tags could be used to bypass HTML sanitization. This made i
Users logged into the Apache CloudStack's web interface can be tricked to submit malicious CSRF requests due to missing
The logout operation in the CloudStack web interface does not expire the user session completely which is valid until ex
The CloudStack Quota feature allows cloud administrators to implement a quota or usage limit system for cloud resources,
Account users in Apache CloudStack by default are allowed to upload and register templates for deploying instances and v
Insecure Default Initialization of Resource vulnerability in Apache Solr. New ConfigSets that are created via a Restore
Improper Authentication vulnerability in Apache Solr. Solr instances using the PKIAuthenticationPlugin, which is enable
Apache ActiveMQ Artemis allows access to diagnostic information and controls through MBeans, which are also exposed thro
Cross-site Resource Forgery (CSRF), Privilege escalation vulnerability in Apache Roller. On multi-blog/user Roller websi
On Windows platforms, a "best fit" character encoding conversion of command line arguments to Subversion's executables (
Improper Restriction of XML External Entity Reference ('XXE') vulnerability in Apache XML Graphics FOP. This issue affe
Uncontrolled Resource Consumption vulnerability in Apache Commons IO. The org.apache.commons.io.input.XmlStreamReader c
Schema parsing in the Java SDK of Apache Avro 1.11.3 and previous versions allows bad actors to execute arbitrary code.
Deserialization of Untrusted Data vulnerability in Apache Lucene Replicator. This issue affects Apache Lucene's replica
Exposure of Sensitive Information to an Unauthorized Actor, Insecure Storage of Sensitive Information vulnerability in M
Inadequate Encryption Strength vulnerability in Apache Answer. This issue affects Apache Answer: through 1.3.5. Using
Frequently Asked Questions
How many CVEs affect Apache?
Apache has 3,495 CVE records in our database, including 596 critical and 1319 high severity vulnerabilities. 37 of these are listed in CISA's Known Exploited Vulnerabilities catalog.
What are the most severe Apache vulnerabilities?
Apache has 596 critical severity (CVSS 9.0+) and 1319 high severity (CVSS 7.0-8.9) vulnerabilities. 37 vulnerabilities are confirmed as actively exploited in the wild.
How can I scan for Apache vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Apache products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Apache Vulnerabilities
CyberStrike scans your infrastructure for Apache vulnerabilities and provides real-time remediation guidance.
Get Started