Apache
3,495 known vulnerabilities
Top Products
Apache Airflow, versions before 2.8.2, has a vulnerability that allows authenticated users to view DAG code and import e
Possible path traversal in Apache OFBiz allowing authentication bypass. Users are recommended to upgrade to version 18.1
Possible path traversal in Apache OFBiz allowing file inclusion. Users are recommended to upgrade to version 18.12.12, t
The Apache Xerces C++ XML parser on versions 3.0.0 before 3.2.5 contains a use-after-free error triggered during the sca
A low privilege authenticated user could import an existing dashboard or chart that they do not have access to and then
Apache Superset with custom roles that include `can write on dataset` and without all data access permissions, allows fo
Improper parsing of nested SQL statements on SQLLab would allow authenticated users to surpass their data authorization
A guest user could exploit a chart data REST API and send arbitrary SQL statements that on error could leak information
An authenticated user with privileges to create Alerts on Alerts & Reports has the capability to generate a specially cr
Improper input validation allows for header injection in MIME4J library when using MIME4J DOM for composing message. Thi
XML External Entity injection in apache ambari versions <= 2.7.7, Users are recommended to upgrade to version 2.7.8, whi
** UNSUPPORTED WHEN ASSIGNED ** Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Auror
Apache James prior to versions 3.8.1 and 3.7.5 is vulnerable to SMTP smuggling. A lenient behaviour in line delimiter h
Apache James prior to version 3.7.5 and 3.8.0 exposes a JMX endpoint on localhost subject to pre-authentication deserial
Malicious code injection in Apache Ambari in prior to 2.7.8. Users are recommended to upgrade to version 2.7.8, which fi
Exposure of sensitive data by by crafting a malicious EventFactory and providing a custom ExchangeCreatedEvent that expo
Improper Input Validation vulnerability in Apache DolphinScheduler. An authenticated user can cause arbitrary, unsandbox
Hertzbeat is a real-time monitoring system. In the implementation of `JmxCollectImpl.java`, `JMXConnectorFactory.connect
Hertzbeat is a real-time monitoring system. At the interface of `/define/yml`, SnakeYAML is used as a parser to parse ym
Hertzbeat is a real-time monitoring system. In `CalculateAlarm.java`, `AviatorEvaluator` is used to directly execute the
Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability in Apache Answ
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache Answer.This
Unrestricted Upload of File with Dangerous Type vulnerability in Apache Answer.This issue affects Apache Answer: through
When ssl was enabled for Mongo Hook, default settings included "allow_insecure" which caused that certificates were not
Deserialization of Untrusted Data vulnerability in Apache Camel CassandraQL Component AggregationRepository which is vul
Deserialization of Untrusted Data vulnerability in Apache Camel SQL ComponentThis issue affects Apache Camel: from 3.0.0
Arbitrary File Read Vulnerability in Apache Dolphinscheduler. This issue affects Apache DolphinScheduler: before 3.2.1.
Session Fixation Apache DolphinScheduler before version 3.2.0, which session is still valid after the password change.
Because the HttpUtils class did not verify certificates, an attacker that could perform a Man-in-the-Middle (MITM) attac
Exposure of Remote Code Execution in Apache Dolphinscheduler. This issue affects Apache DolphinScheduler: before 3.2.1.
Allocation of Resources Without Limits or Throttling vulnerability in Apache Commons Compress.This issue affects Apache
Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in Apache Commons Compress.This issue affects Apach
This is a duplicate for CVE-2023-46104. With correct CVE version ranges for affected Apache Superset. Uncontrolled res
Improper Control of Dynamically-Managed Code Resources, Unrestricted Upload of File with Dangerous Type, Inclusion of Fu
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Solr.This issue affects Apache Solr:
Incorrect Permission Assignment for Critical Resource, Improper Control of Dynamically-Managed Code Resources vulnerabil
Insufficiently Protected Credentials vulnerability in Apache Solr. This issue affects Apache Solr: from 6.0.0 through 8
Request smuggling vulnerability in HTTP server in Apache bRPC 0.9.5~1.7.0 on all platforms allows attacker to smuggle re
Improper Authentication vulnerability in Apache Ozone. The vulnerability allows an attacker to download metadata intern
Observable timing discrepancy vulnerability in Apache Pulsar SASL Authentication Provider can allow an attacker to forge
Malicious code execution via path traversal in Apache Software Foundation Apache Sling Servlets Resolver.This issue affe
Server-Side Request Forgery (SSRF) vulnerability in Apache ServiceComb Service-Center. Attackers can obtain sensitive se
Exposure of Sensitive Information to an Unauthorized Actor in Apache ServiceComb Service-Center.This issue affects Apa
In Apache Kylin version 2.0.0 to 4.0.3, there is a Server Config web interface that displays the content of file 'kylin.
Since version 5.2.0, when using deferrable mode with the path of a Kubernetes configuration file for authentication, the
Apache Airflow, versions before 2.8.1, have a vulnerability that allows an authenticated user to access the source code
Apache Airflow, versions before 2.8.1, have a vulnerability that allows a potential attacker to poison the XCom data by
A stored cross-site scripting (XSS) vulnerability exists in Apache Superset before 3.0.3. An authenticated attacker with
Generation of Error Message Containing Sensitive Information vulnerability in Apache Tomcat.This issue affects Apache To
Remote Code Execution vulnerability in Apache IoTDB.This issue affects Apache IoTDB: from 1.0.0 through 1.2.2. Users ar
Frequently Asked Questions
How many CVEs affect Apache?
Apache has 3,495 CVE records in our database, including 596 critical and 1319 high severity vulnerabilities. 37 of these are listed in CISA's Known Exploited Vulnerabilities catalog.
What are the most severe Apache vulnerabilities?
Apache has 596 critical severity (CVSS 9.0+) and 1319 high severity (CVSS 7.0-8.9) vulnerabilities. 37 vulnerabilities are confirmed as actively exploited in the wild.
How can I scan for Apache vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Apache products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Apache Vulnerabilities
CyberStrike scans your infrastructure for Apache vulnerabilities and provides real-time remediation guidance.
Get Started