Apache
3,495 known vulnerabilities
Top Products
In Apache Linkis <=1.3.0 when used with the MySQL Connector/J in the data source module, an authenticated attacker could
Improper Authentication vulnerability in Apache Software Foundation Apache IoTDB.This issue affects iotdb-web-workbench
Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Apache Software Fou
Prior to Apache HTTP Server 2.4.55, a malicious backend can cause the response headers to be truncated early, resulting
Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') vulnerability in mod_proxy_ajp of Apache HTTP Se
A carefully crafted If: request header can cause a memory read, or write of a single zero byte, in a pool (heap) memory
When explicitly enabling the feature flag DASHBOARD_CACHE (disabled by default), the system allowed for an unauthenticat
An authenticated attacker with update datasets permission could change a dataset link to an untrusted site, users could
An authenticated attacker with write CSS template permissions can create a record with specific HTML tags that will not
Two legacy REST API endpoints for approval and request access are vulnerable to cross site request forgery. This issue a
Upload data forms do not correctly render user input leading to possible XSS attack vectors that can be performed by aut
Dashboard rendering does not sufficiently sanitize the content of markdown components leading to possible XSS attack vec
A vulnerability in the SQL Alchemy connector of Apache Superset allows an authenticated user with read access to a speci
When using Apache Shiro before 1.11.0 together with Spring Boot 2.6+, a specially crafted HTTP request may cause an auth
An improper neutralization of input during web page generation ('Cross-site Scripting') [CWE-79] vulnerability in Sling
Usage of temporary files with insecure permissions by the Apache James server allows an attacker with local access to ac
Unproper laxist permissions on the temporary files used by MIME4J TempFileStorageProvider may lead to information disclo
Improper validation of script alert plugin parameters in Apache DolphinScheduler to avoid remote command execution vulne
The JsonErrorReportValve in Apache Tomcat 8.5.83, 9.0.40 to 9.0.68 and 10.1.0-M1 to 10.1.1 did not escape the type, mess
Apache Dubbo is a java based, open source RPC framework. Versions prior to 2.6.10 and 2.7.10 are vulnerable to pre-auth
Diagnosis Controller miss parameter validation, so user may attacked by command injection via HTTP Request.
In the fix for CVE-2022-24697, a blacklist is used to filter user input commands. But there is a risk of being bypassed.
Apache ShardingSphere-Proxy prior to 5.3.0 when using MySQL as database backend didn't cleanup the database session comp
This vulnerable is about a potential code injection when an attacker has control of the target LDAP server using in the
Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Apache Software Fou
Improper Input Validation vulnerability for the xdebug plugin in Apache Software Foundation Apache Traffic Server can le
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Apache Software Foundation Apache Helix UI componen
Improper Check for Unusual or Exceptional Conditions vulnerability in handling the requests to Apache Traffic Server. T
Improper Check for Unusual or Exceptional Conditions vulnerability handling requests in Apache Traffic Server allows an
An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache Zeppelin
The improper Input Validation vulnerability in "”Move folder to Trash” feature of Apache Zeppelin allows an attacker to
The Apache Bookkeeper Java Client (before 4.14.6 and also 4.15.0) does not close the connection to the bookkeeper server
A vulnerability in import module of Apache Atlas allows an authenticated user to write to web server filesystem. This i
A SSRF vulnerability in parsing the href attribute of XOP:Include in MTOM requests in versions of Apache CXF before 3.5.
A vulnerability in Apache CXF before versions 3.5.5 and 3.4.10 allows an attacker to perform a remote directory listing
Improper neutralization of special elements used in an LDAP query ('LDAP Injection') vulnerability in ActiveDirectory an
Prior to Apache Commons Net 3.9.0, Net's FTP client trusts the host from PASV response by default. A malicious server ca
Apache Tapestry 3.x allows deserialization of untrusted data, leading to remote code execution. This issue is similar to
Apache Fineract allowed an authenticated user to perform remote code execution due to a path traversal vulnerability in
When using tasks to read config files, there is a risk of database password disclosure. We recommend you upgrade to vers
Alarm instance management has command injection when there is a specific command configured. It is only for logged-in us
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Apache Airfl
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Apache Airfl
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Apache Airfl
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Apache Airfl
missing input validation in Apache Hama may cause information disclosure through path traversal and XSS. Since Apache Ha
Class org.apache.sshd.server.keyprovider.SimpleGeneratorHostKeyProvider in Apache MINA SSHD <= 2.9.1 uses Java deseriali
Users with write permissions to a repository can delete arbitrary directories.
If anonymous read enabled, it's possible to read the database file directly without logging in.
In Apache Airflow versions prior to 2.4.3, there was an open redirect in the webserver's `/login` endpoint.
Frequently Asked Questions
How many CVEs affect Apache?
Apache has 3,495 CVE records in our database, including 596 critical and 1319 high severity vulnerabilities. 37 of these are listed in CISA's Known Exploited Vulnerabilities catalog.
What are the most severe Apache vulnerabilities?
Apache has 596 critical severity (CVSS 9.0+) and 1319 high severity (CVSS 7.0-8.9) vulnerabilities. 37 vulnerabilities are confirmed as actively exploited in the wild.
How can I scan for Apache vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Apache products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Apache Vulnerabilities
CyberStrike scans your infrastructure for Apache vulnerabilities and provides real-time remediation guidance.
Get Started