Apache
3,495 known vulnerabilities
Top Products
Apache Software Foundation Apache Submarine has a bug when serializing against yaml. The bug is caused by snakeyaml htt
A cleverly devised username might bypass LDAP authentication checks. In LDAP-authenticated Derby installations, this co
Relative library resolution in linux container-executor binary in Apache Hadoop 3.3.1-3.3.4 on Linux allows local user t
We failed to apply CVE-2023-40611 in 2.7.1 and this vulnerability was marked as fixed then. Apache Airflow, versions b
Apache Airflow, versions before 2.7.3, has a vulnerability that allows an authorized user who has access to read specifi
Deserialization of untrusted data in IPC and Parquet readers in PyArrow versions 0.14.0 to 14.0.0 allows arbitrary code
Deserialization of Untrusted Data, Improper Input Validation vulnerability in Apache UIMA Java SDK, Apache UIMA Java SDK
Missing Authentication in Apache Software Foundation Apache OFBiz when using the Solr plugin. This issue affects Apache
Allura Discussion and Allura Forum importing does not restrict URL values specified in attachments. Project administrato
Insertion of Sensitive Information into Log File vulnerability in Apache Airflow Celery provider, Apache Airflow. Sensi
The Java OpenWire protocol marshaller is vulnerable to Remote Code Execution. This vulnerability may allow a remote att
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Airflow.This issue affects Apache Air
When a HTTP/2 stream was reset (RST frame) by a client, there was a time window were the request's memory resources were
An attacker, opening a HTTP/2 connection with an initial window size of 0, was able to block handling of that connection
Out-of-bounds Read vulnerability in mod_macro of Apache HTTP Server.This issue affects Apache HTTP Server: through 2.4.5
All versions of Apache Santuario - XML Security for Java prior to 2.2.6, 2.3.4, and 3.0.3, when using the JSR 105 API, a
Deserialization of Untrusted Data Vulnerability in Apache Software Foundation Apache InLong. This issue affects Apache
There exists an SSRF (Server-Side Request Forgery) vulnerability located at the /sandbox/proxyGateway endpoint. This vu
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Traffic Server.This issue affects Apa
Improper Input Validation vulnerability in Apache Traffic Server with malformed HTTP/2 frames.This issue affects Apache
Security vulnerability in Apache bRPC <=1.6.0 on all platforms allows attackers to inject XSS code to the builtin rpcz p
Authorization Bypass Through User-Controlled Key vulnerability in Apache InLong.This issue affects Apache InLong: from 1
Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerability in Apac
Insufficient Verification of Data Authenticity vulnerability in Apache InLong.This issue affects Apache InLong: from 1.4
Apache Airflow, versions 2.7.0 and 2.7.1, is affected by a vulnerability that allows an authenticated user to retrieve s
Apache Airflow, in versions prior to 2.7.2, contains a security vulnerability that allows an authenticated user with lim
Apache Airflow, versions prior to 2.7.2, contains a security vulnerability that allows authenticated users of Airflow to
Apache Airflow, versions before 2.7.2, has a vulnerability that allows an authorized user who has access to read specifi
Authorization Bypass Through User-Controlled Key vulnerability in Apache ZooKeeper. If SASL Quorum Peer authentication i
An integer overflow in xerces-c++ 3.2.3 in BigFix Platform allows remote attackers to cause out-of-bound access via HTTP
Improper Input Validation vulnerability in Apache Tomcat.Tomcat from 11.0.0-M1 through 11.0.0-M11, from 10.1.0-M1 throug
Incomplete Cleanup vulnerability in Apache Tomcat.When recycling various internal objects in Apache Tomcat from 11.0.0-M
Incomplete Cleanup vulnerability in Apache Tomcat. The internal fork of Commons FileUpload packaged with Apache Tomcat
When deserializing untrusted or corrupted data, it is possible for a reader to consume memory beyond the allowed constra
Improper Neutralization of CRLF Sequences in HTTP Headers in Apache Flink Stateful Functions 3.1.0, 3.1.1 and 3.2.0 allo
Improper Input Validation, Uncontrolled Resource Consumption vulnerability in Apache Commons Compress in TAR parsing.Thi
In the Apache Airflow HDFS Provider, versions prior to 4.1.1, a documentation info pointed users to an install incorrect
Important: Authentication Bypass CVE-2023-41081 The mod_jk component of Apache Tomcat Connectors in some circumstances,
Apache Airflow, versions before 2.7.1, is affected by a vulnerability that allows authenticated users who have access to
Apache Airflow, versions before 2.7.1, is affected by a vulnerability that allows authenticated and DAG-view authorized
Apache Superset would allow for SQLite database connections to be incorrectly registered when an attacker uses alternati
If an attacker gains write access to the Apache Superset metadata database, they could persist a specifically crafted Py
An Incorrect authorisation check in SQLLab in Apache Superset versions up to and including 2.1.0. This vulnerability all
By default, stack traces for errors were enabled, which resulted in the exposure of internal traces on REST API endpoint
Improper REST API permission in Apache Superset up to and including 2.1.0 allows for an authenticated Gamma users to tes
An improper default REST API permission for Gamma users in Apache Superset up to and including 2.1.0 allows for an authe
A non Admin authenticated user could incorrectly create resources using the import charts feature, on Apache Superset up
Improper data authorization check on Jinja templated queries in Apache Superset up to and including 2.1.0 allows for an
** UNSUPPORTED WHEN ASSIGNED ** When integrating Apache Axis 1.x in an application, it may not have been obvious that lo
Incorrect certificate validation in InvokeHTTP on Apache NiFi MiNiFi C++ versions 0.13 to 0.14 allows an intermediary to
Frequently Asked Questions
How many CVEs affect Apache?
Apache has 3,495 CVE records in our database, including 596 critical and 1319 high severity vulnerabilities. 37 of these are listed in CISA's Known Exploited Vulnerabilities catalog.
What are the most severe Apache vulnerabilities?
Apache has 596 critical severity (CVSS 9.0+) and 1319 high severity (CVSS 7.0-8.9) vulnerabilities. 37 vulnerabilities are confirmed as actively exploited in the wild.
How can I scan for Apache vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Apache products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Apache Vulnerabilities
CyberStrike scans your infrastructure for Apache vulnerabilities and provides real-time remediation guidance.
Get Started