Apache
3,495 known vulnerabilities
Top Products
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Solr. The Solr Metrics API publishes
Apache Shiro before 1.13.0 or 2.0.0-alpha-4, may be susceptible to a path traversal attack that results in an authentica
Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability in Apache Answ
** UNSUPPORTED WHEN ASSIGNED ** Improper Input Validation vulnerability in Apache Axis allowed users with access to the
Deserialization of Untrusted Data vulnerability in Apache InLong.This issue affects Apache InLong: from 1.7.0 through 1.
Improper Control of Generation of Code ('Code Injection') vulnerability in Apache InLong.This issue affects Apache InLon
Improper Input Validation vulnerability in Apache DolphinScheduler. An authenticated user can cause arbitrary, unsandbox
Apache OpenOffice documents can contain links that call internal macros with arbitrary arguments. Several URI Schemes ar
The vulnerability permits attackers to circumvent authentication processes, enabling them to remotely execute arbitrary
Arbitrary file properties reading vulnerability in Apache Software Foundation Apache OFBiz when user operates an uri cal
Hertzbeat is an open source, real-time monitoring system. Prior to version 1.4.1, Spring Boot permission configuration i
Hertzbeat is an open source, real-time monitoring system. Hertzbeat uses aviatorscript to evaluate alert expressions. Th
Hertzbeat is an open source, real-time monitoring system with custom-monitoring, high performance cluster, prometheus-li
Deserialization of Untrusted Data vulnerability in Apache IoTDB.This issue affects Apache IoTDB: from 0.13.0 through 0.1
Apache Airflow, versions before 2.8.0, is affected by a vulnerability that allows an authenticated user without the vari
Apache Airflow, version 2.7.0 through 2.7.3, has a vulnerability that allows an attacker to trigger a DAG in a GET reque
Apache Airflow, in versions prior to 2.8.0, contains a security vulnerability that allows an authenticated user with lim
Apache Airflow, versions 2.6.0 through 2.7.3 has a stored XSS vulnerability that allows a DAG author to add an unbounded
Improper Authentication vulnerability in Apache Pulsar WebSocket Proxy allows an attacker to connect to the /pingpong en
Apache Guacamole 1.5.3 and older do not consistently ensure that values received from a VNC server will not result in in
A where_in JINJA macro allows users to specify a quote, which combined with a carefully crafted statement would allow fo
An authenticated Gamma user has the ability to create a dashboard and add charts to it, this user would automatically be
Uncontrolled resource consumption can be triggered by authenticated attacker that uploads a malicious ZIP to import data
The api /api/snapshot and /api/get_log_file would allow unauthenticated access. It could allow a DoS attack or get arbit
In streampark, there is a project module that integrates Maven's compilation capability. However, there is no check on t
In the Streampark platform, when users log in to the system and use certain features, some pages provide a name-based fu
Deserialization of Untrusted Data vulnerability in Apache Dubbo.This issue only affects Apache Dubbo 3.1.5. Users are r
A deserialization vulnerability existed when decode a malicious package.This issue affects Apache Dubbo: from 3.1.0 thro
URL Redirection to Untrusted Site ('Open Redirect') vulnerability when "form" authentication is used in Apache Shiro. Mi
Design document functions which receive a user http request object may expose authorization or session cookie headers of
An attacker can manipulate file upload params to enable paths traversal and under some circumstances this can lead to up
When a Multipart request is performed but some of the fields exceed the maxStringLength limit, the upload files will re
Pre-auth RCE in Apache Ofbiz 18.12.09. It's due to XML-RPC no longer maintained still present. This issue affects Apach
** UNSUPPORTED WHEN ASSIGNED ** The value set as the DefaultLocaleResolver.LOCALE_KEY attribute on the session was not
Improper Restriction of XML External Entity Reference vulnerability in Apache Cocoon.This issue affects Apache Cocoon: f
Before DolphinScheduler version 3.1.0, the login user could delete UDF function in the resource center unauthorized (whi
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Cocoon.This
An authenticated malicious user could initiate multiple concurrent requests, each requesting multiple dashboard exports,
An authenticated user with read permissions on database connections metadata could potentially access sensitive informat
An authenticated attacker with update datasets permission could change a dataset link to an untrusted site by spoofing t
Improper Input Validation vulnerability in Apache Tomcat.Tomcat from 11.0.0-M1 through 11.0.0-M10, from 10.1.0-M1 throug
Once an user is authenticated on Jolokia, he can potentially trigger arbitrary code execution. In details, in ActiveMQ
Apache NiFi 0.7.0 through 1.23.2 include the JoltTransformJSON Processor, which provides an advanced configuration user
Improper payload validation and an improper REST API response type, made it possible for an authenticated malicious acto
Unnecessary read permissions within the Gamma role would allow authenticated users to read configured CSS templates and
Improper authorization check and possible privilege escalation on Apache Superset up to but excluding 2.1.2. Using the d
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache DolphinScheduler.This issue affects A
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache DolphinScheduler. The information ex
On unix-like systems, the temporary directory is shared between all user. As such, writing to this directory using APIs
Apache Software Foundation Apache Submarine has an SQL injection vulnerability when a user logs in. This issue can resul
Frequently Asked Questions
How many CVEs affect Apache?
Apache has 3,495 CVE records in our database, including 596 critical and 1319 high severity vulnerabilities. 37 of these are listed in CISA's Known Exploited Vulnerabilities catalog.
What are the most severe Apache vulnerabilities?
Apache has 596 critical severity (CVSS 9.0+) and 1319 high severity (CVSS 7.0-8.9) vulnerabilities. 37 vulnerabilities are confirmed as actively exploited in the wild.
How can I scan for Apache vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Apache products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Apache Vulnerabilities
CyberStrike scans your infrastructure for Apache vulnerabilities and provides real-time remediation guidance.
Get Started