Apache
3,495 known vulnerabilities
Top Products
Airflow versions 2.7.0 through 2.8.4 have a vulnerability that allows an authenticated user to see sensitive provider co
Insertion of Sensitive Information into Log File vulnerability in the Apache Solr Operator. This issue affects all vers
While an Apache Kafka cluster is being migrated from ZooKeeper mode to KRaft mode, in some cases ACLs will not be correc
HTTP/2 CONTINUATION DoS attack can cause Apache Traffic Server to consume more resources on the server. Version from 8.
Improper Input Validation vulnerability in Apache Zeppelin. The attackers can execute malicious queries by setting impr
Improper Encoding or Escaping of Output vulnerability in Apache Zeppelin. The attackers can modify helium.json and expo
Improper Encoding or Escaping of Output vulnerability in Apache Zeppelin. The attackers can execute shell scripts or ma
Improper Input Validation vulnerability in Apache Zeppelin. The attackers can call updating cron API with invalid or im
Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Zeppelin. The attacker can inject sen
Authentication Bypass by Spoofing vulnerability by replacing to exsiting notes in Apache Zeppelin.This issue affects Apa
Improper Input Validation vulnerability in Apache Zeppelin when creating a new note from Zeppelin's UI.This issue affect
Improper Input Validation vulnerability in Apache Zeppelin SAP.This issue affects Apache Zeppelin SAP: from 0.8.0 before
Cross-Site Request Forgery (CSRF) vulnerability in Credential page of Apache Zeppelin allows an attacker to submit malic
Improper Input Validation vulnerability in Apache Zeppelin. By adding relative path indicators(E.g ..), attackers can s
Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in Apache NimBLE. Specially crafted GATT operatio
HTTP/2 incoming headers exceeding the limit are temporarily buffered in nghttp2 in order to generate an informative HTTP
HTTP Response splitting in multiple modules in Apache HTTP Server allows an attacker that can inject malicious response
Faulty input validation in the core of Apache allows malicious or exploitable backend/content generators to split HTTP r
A problem has been identified in the CloudStack additional VM configuration (extraconfig) feature which can be misused b
The CloudStack management server and secondary storage VM could be tricked into making requests to restricted or random
By default the CloudStack management server honours the x-forwarded-for HTTP header and logs it as the source IP of an A
This vulnerability allows authenticated users with produce or consume permissions to perform unauthorized operations on
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Fineract.Th
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Fineract.Th
Improper Privilege Management vulnerability in Apache Fineract.This issue affects Apache Fineract: <1.8.5. Users are re
Improper Preservation of Permissions vulnerability in Apache Airflow.This issue affects Apache Airflow from 2.8.2 throug
Download of Code Without Integrity Check vulnerability in Apache Doris. The jdbc driver files used for JDBC catalog is n
Possible race condition vulnerability in Apache Doris. Some of code using `chmod()` method. This method run the risk of
Out-of-bounds Write vulnerability in Apache Commons Configuration.This issue affects Apache Commons Configuration: from
Out-of-bounds Write vulnerability in Apache Commons Configuration.This issue affects Apache Commons Configuration: from
An error in the evaluation of the fetch metadata headers could allow a bypass of the CSRF protection in Apache Wicket. T
Improper Input Validation vulnerability in Apache Hop Engine.This issue affects Apache Hop Engine: before 2.8.0. Users
A SSRF vulnerability using the Aegis DataBinding in versions of Apache CXF before 4.0.4, 3.6.3 and 3.5.8 allows an attac
Information disclosure in persistent watchers handling in Apache ZooKeeper due to missing ACL check. It allows an attack
Apache Airflow, versions 2.8.0 through 2.8.2, has a vulnerability that allows an authenticated user with limited permiss
Denial of Service due to improper input validation vulnerability for HTTP/2 requests in Apache Tomcat. When processing a
Denial of Service via incomplete cleanup vulnerability in Apache Tomcat. It was possible for WebSocket clients to keep W
The vulnerability allows authenticated users with only produce or consume permissions to modify topic-level policies, su
The Pulsar Functions Worker includes a capability that permits authenticated users to create functions where the functio
In Pulsar Functions Worker, authenticated users can upload functions in jar or nar files. These files, essentially zip f
Improper input validation in the Pulsar Function Worker allows a malicious authenticated user to execute arbitrary Java
Improper Authentication vulnerability in Apache Pulsar Proxy allows an attacker to connect to the /proxy-stats endpoint
The authentication method in Apache Doris versions before 2.0.0 was vulnerable to timing attacks. Users are recommended
In Apache Linkis <=1.4.0, The password is printed to the log when using the Oracle data source of the Linkis data source
Deserialization of Untrusted Data vulnerability in Apache InLong.This issue affects Apache InLong: from 1.8.0 through 1.
** UNSUPPORTED WHEN ASSIGNED ** Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vu
** UNSUPPORTED WHEN ASSIGNED ** Incorrect Authorization vulnerability in Apache Archiva: a vulnerability in Apache Arch
** UNSUPPORTED WHEN ASSIGNED ** Incorrect Authorization vulnerability in Apache Archiva. Apache Archiva has a setting t
Lack of proper input validation and constraint enforcement in Apache Ambari prior to 2.7.8 Impact : As it will be st
Apache Airflow, versions before 2.8.2, has a vulnerability that allows authenticated Ops and Viewers users to view all i
Frequently Asked Questions
How many CVEs affect Apache?
Apache has 3,495 CVE records in our database, including 596 critical and 1319 high severity vulnerabilities. 37 of these are listed in CISA's Known Exploited Vulnerabilities catalog.
What are the most severe Apache vulnerabilities?
Apache has 596 critical severity (CVSS 9.0+) and 1319 high severity (CVSS 7.0-8.9) vulnerabilities. 37 vulnerabilities are confirmed as actively exploited in the wild.
How can I scan for Apache vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Apache products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Apache Vulnerabilities
CyberStrike scans your infrastructure for Apache vulnerabilities and provides real-time remediation guidance.
Get Started