Apache
3,495 known vulnerabilities
Top Products
Improper Authentication vulnerability in Apache Software Foundation Apache IoTDB.This issue affects Apache IoTDB Grafana
Arbitrary file reading vulnerability in Apache Software Foundation Apache OFBiz when using the Solr plugin. This is a p
The SlingRequestDispatcher doesn't correctly implement the RequestDispatcher API resulting in a generic type of include-
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Software Fo
In Apache Linkis <=1.3.1, because the parameters are not effectively filtered, the attacker uses the MySQL data source a
In Apache Linkis <=1.3.1, due to the lack of effective filtering of parameters, an attacker configuring malicious Mysql
In Apache Linkis <=1.3.1, due to the default token generated by Linkis Gateway deployment being too simple, it is easy
In Apache Linkis <=1.3.1, due to the Manager module engineConn material upload does not check the zip path, This is a
In Apache Linkis <=1.3.1, The PublicService module uploads files without restrictions on the path to the uploaded files,
Improper Input Validation vulnerability in Apache Software Foundation Apache Airflow Spark Provider.This issue affects A
Improper Input Validation vulnerability in Apache Software Foundation Apache Airflow Drill Provider.This issue affects A
Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Software Foundation Apache Airflow Hiv
Apache James server version 3.7.3 and earlier provides a JMX management service without authentication by default. This
** UNSUPPORTED WHEN ASSIGNED ** Improper Neutralization of Special Elements used in a Command ('Command Injection') vuln
Privilege escalation via stored XSS using the file upload service to upload malicious content. The issue can be exploite
Vendor: The Apache Software Foundation Versions Affected: Apache OpenMeetings from 2.0.0 before 7.0.0 Description: Att
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Software Fo
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Software Fo
Server-Side Request Forgery (SSRF) vulnerability in Apache Software Foundation Apache Fineract. Authorized users with li
Deserialization of Untrusted Data vulnerability in Apache Software Foundation Apache InLong. It could be triggered by a
Apache OpenOffice documents can contain links that call internal macros with arbitrary arguments. Several URI Schemes ar
Apache OpenOffice versions before 4.1.14 may be configured to add an empty entry to the Java class path. This may lead t
When using the RemoteIpFilter with requests received from a reverse proxy via HTTP that include the X-Forwarded-Proto
Excessive Iteration vulnerability in Apache Software Foundation Apache Sling Resource Merger.This issue affects Apache S
Generation of Error Message Containing Sensitive Information vulnerability in Apache Software Foundation Apache Airflow.
** UNSUPPORTED WHEN ASSIGNED ** When using the Chainsaw or SocketAppender components with Log4j 1.x on JRE less than 1.
A deserialization vulnerability existed when dubbo generic invoke, which could lead to malicious code execution. This
HTTP Response Smuggling vulnerability in Apache HTTP Server via mod_proxy_uwsgi. This issue affects Apache HTTP Server:
Some mod_proxy configurations on Apache HTTP Server versions 2.4.0 through 2.4.55 allow a HTTP Request Smuggling attack.
Generation of Error Message Containing Sensitive Information vulnerability in the Apache Airflow AWS Provider. This iss
Improper Input Validation vulnerability in the Apache Airflow Hive Provider. This issue affects Apache Airflow Hive Pro
Improper Input Validation vulnerability in the Apache Airflow Sqoop Provider. This issue affects Apache Airflow Sqoop P
Improper Input Validation vulnerability in the Apache Airflow Google Provider. This issue affects Apache Airflow Google
Improper Input Validation vulnerability in the Apache Airflow Google Provider. This issue affects Apache Airflow Google
Privilege Escalation vulnerability in Apache Software Foundation Apache Sling. Any content author is able to create i18n
An LDAP Injection vulnerability exists in the LdapIdentityBackend of Apache Kerby before 2.0.3.
Apache Commons FileUpload before 1.5 does not limit the number of request parts to be processed resulting in the possibi
Improper Privilege Management vulnerability in Apache Software Foundation Apache ShenYu. ShenYu Admin allows low-privi
Apache Sling JCR Base < 3.1.12 has a critical injection vulnerability when running on old JDK versions (JDK 1.8.191 or e
The ExtractCCDAAttributes Processor in Apache NiFi 1.2.0 through 1.19.1 does not restrict XML External Entity references
A possible security vulnerability has been identified in Apache Kafka Connect API. This requires access to a Kafka Conne
An improper neutralization of input during web page generation ('Cross-site Scripting') [CWE-79] vulnerability in Sling
There are issues with the AGE drivers for Golang and Python that enable SQL injections to occur. This impacts AGE for Po
Deserialization of Untrusted Data vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache In
Out-of-bounds Read vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.1.
On Windows, Apache Portable Runtime 1.7.0 and earlier may write beyond the end of a stack based buffer in apr_socket_sen
Integer Overflow or Wraparound vulnerability in apr_base64 functions of Apache Portable Runtime Utility (APR-util) allow
Integer Overflow or Wraparound vulnerability in apr_encode functions of Apache Portable Runtime (APR) allows an attacker
Incorrect Authorization vulnerability in Apache Software Foundation Apache IoTDB.This issue affects the iotdb-web-workbe
In Apache Linkis <=1.3.0 when used with the MySQL Connector/J, a deserialization vulnerability with possible remote code
Frequently Asked Questions
How many CVEs affect Apache?
Apache has 3,495 CVE records in our database, including 596 critical and 1319 high severity vulnerabilities. 37 of these are listed in CISA's Known Exploited Vulnerabilities catalog.
What are the most severe Apache vulnerabilities?
Apache has 596 critical severity (CVSS 9.0+) and 1319 high severity (CVSS 7.0-8.9) vulnerabilities. 37 vulnerabilities are confirmed as actively exploited in the wild.
How can I scan for Apache vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Apache products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Apache Vulnerabilities
CyberStrike scans your infrastructure for Apache vulnerabilities and provides real-time remediation guidance.
Get Started