Apache
3,495 known vulnerabilities
Top Products
Improper Authentication vulnerability in Apache Software Foundation Apache Accumulo. This issue affects Apache Accumulo:
In Apache Airflow, some potentially sensitive values were being shown to the user in certain situations. This vulnerabi
Allocation of Resources Without Limits or Throttling vulnerability in Apache Software Foundation Apache Struts.This issu
Allocation of Resources Without Limits or Throttling vulnerability in Apache Software Foundation Apache Struts.This issu
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Software Foundation Apache Traffic Se
Improper Input Validation vulnerability in Apache Software Foundation Apache Traffic Server. The configuration option p
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Software Foundation Apache Traffic Se
The DBCPConnectionPool and HikariCPConnectionPool Controller Services in Apache NiFi 0.0.2 through 1.21.0 allow an authe
The JndiJmsConnectionFactoryProvider Controller Service, along with the ConsumeJMS and PublishJMS Processors, in Apache
Apache Guacamole 0.9.10 through 1.5.1 may continue to reference a freed RDP audio input buffer. Depending on timing, thi
Apache Guacamole 1.5.1 and older may incorrectly calculate the lengths of instruction elements sent during the Guacamole
Arbitrary code execution in Apache Airflow CNCF Kubernetes provider version 5.0.0 allows user to change xcom sidecar ima
Privilege escalation when enabling FQL/Audit logs allows user with JMX access to run arbitrary commands as the user runn
A carefully crafted request on several JSPWiki plugins could trigger an XSS vulnerability on Apache JSPWiki, which could
For RocketMQ versions 5.1.0 and below, under certain conditions, there is a risk of remote command execution. Several
Exposure of Resource to Wrong Sphere Vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache
Insecure Default Initialization of Resource Vulnerability in Apache Software Foundation Apache InLong.This issue affects
Weak Password Requirements vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: f
Files or Directories Accessible to External Parties vulnerability in Apache Software Foundation Apache InLong.This issue
Insufficient Session Expiration vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLo
Files or Directories Accessible to External Parties vulnerability in Apache Software Foundation Apache InLong.This issue
Improper Privilege Management Vulnerabilities in Apache Software Foundation Apache InLong.This issue affects Apache InLo
Incorrect Permission Assignment for Critical Resource Vulnerability in Apache Software Foundation Apache InLong.This iss
Incorrect Permission Assignment for Critical Resource Vulnerability in Apache Software Foundation Apache InLong.This iss
Exposure of Resource to Wrong Sphere Vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache
Deserialization of Untrusted Data Vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache In
The fix for CVE-2023-24998 was incomplete for Apache Tomcat 11.0.0-M2 to 11.0.0-M4, 10.1.5 to 10.1.7, 9.0.71 to 9.0.73 a
Improper input validation in the Apache Sling Commons JSON bundle allows an attacker to trigger unexpected errors by sup
An attacker who has gained access to an admin account can perform RCE via null-byte injection Vendor: The Apache Softwa
An attacker that has gained access to certain private information can use this to act as other user. Vendor: The Apache
Attacker can access arbitrary recording/room Vendor: The Apache Software Foundation Versions Affected: Apache OpenMeet
Privilege Context Switching Error vulnerability in Apache Software Foundation Apache Airflow.This issue affects Apache A
Task instance details page in the UI is vulnerable to a stored XSS.This issue affects Apache Airflow: before 2.6.0.
Security vulnerability in Apache bRPC <1.5.0 on all platforms allows attackers to execute arbitrary code via ServerOptio
SQL injection in Log4cxx when using the ODBC appender to send log messages to a database. No fields sent to the databas
Authenticated users with appropriate privileges can create policies having expressions that can exploit code execution v
An Incorrect Permission Assignment for Critical Resource vulnerability was found in the Apache Ranger Hive Plugin. Any u
Design documents with matching document IDs, from databases on the same cluster, may share a mutable Javascript environm
** UNSUPPORTED WHEN ASSIGNED ** The Apache Spark UI offers the possibility to enable ACLs via the configuration option s
Apache StreamPark 1.0.0 before 2.0.0 When the user successfully logs in, to modify his profile, the username will be pas
Streampark allows any users to upload a jar as application, but there is no mandatory verification of the uploaded file
Apache StreamPark 1.0.0 to 2.0.0 have a LDAP injection vulnerability. LDAP Injection is an attack used to exploit web ba
There is insufficient checking of user queries in Apache Jena versions 4.7.0 and earlier, when invoking custom scripts.
An authenticated user with specific data permissions could access database connections stored passwords by requesting a
Session Validation attacks in Apache Superset versions up to and including 2.0.1. Installations that have not altered th
On version 3.0.0 through 3.1.1, Apache DolphinScheduler's python gateway suffered from improper authentication: an attac
An authenticated user with Gamma role authorization could have access to metadata information using non trivial methods
A malicious actor who has been authenticated and granted specific permissions in Apache Superset may use the import data
Incorrect Authorization vulnerability in Apache Software Foundation Apache IoTDB.This issue affects the iotdb-web-workbe
In Apache Spark versions prior to 3.4.0, applications using spark-submit can specify a 'proxy-user' to run as, limiting
Frequently Asked Questions
How many CVEs affect Apache?
Apache has 3,495 CVE records in our database, including 596 critical and 1319 high severity vulnerabilities. 37 of these are listed in CISA's Known Exploited Vulnerabilities catalog.
What are the most severe Apache vulnerabilities?
Apache has 596 critical severity (CVSS 9.0+) and 1319 high severity (CVSS 7.0-8.9) vulnerabilities. 37 vulnerabilities are confirmed as actively exploited in the wild.
How can I scan for Apache vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Apache products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Apache Vulnerabilities
CyberStrike scans your infrastructure for Apache vulnerabilities and provides real-time remediation guidance.
Get Started