Apache
3,495 known vulnerabilities
Top Products
In Apache Airflow prior to 2.3.4, an insecure umask was configured for numerous Airflow components when running with the
In Apache Airflow versions 2.2.4 through 2.3.3, the `database` webserver session backend was susceptible to session fixa
Apache OFBiz up to version 18.12.05 is vulnerable to Regular Expression Denial of Service (ReDoS) in the way it handles
The Solr plugin of Apache OFBiz is configured by default to automatically make a RMI request on localhost, port 1099. In
In Apache OFBiz, versions 18.12.05 and earlier, an attacker acting as an anonymous user of the ecommerce plugin, can ins
Apache OFBiz uses the Birt project plugin (https://eclipse.github.io/birt-website/) to create data visualizations and re
Apache OFBiz uses the Birt plugin (https://eclipse.github.io/birt-website/) to create data visualizations and reports. I
Apache ShenYu Admin has insecure permissions, which may allow low-privilege administrators to modify high-privilege admi
Apache Geode versions prior to 1.15.0 are vulnerable to a deserialization of untrusted data flaw when using REST API on
Apache Geode versions up to 1.12.2 and 1.13.2 are vulnerable to a deserialization of untrusted data flaw when using JMX
Apache Geode versions up to 1.12.5, 1.13.4 and 1.14.0 are vulnerable to a deserialization of untrusted data flaw when us
A flaw in Apache libapreq2 versions 2.16 and earlier could cause a buffer overflow while processing multipart form uploa
ZKConfigurationStore which is optionally used by CapacityScheduler of Apache Hadoop YARN deserializes data obtained from
A flaw was found in AMQ Broker. This issue can cause a partial interruption to the availability of AMQ Broker via an Out
In Apache ActiveMQ Artemis prior to 2.24.0, an attacker could show malicious content and/or redirect users to a maliciou
Apache Flume versions 1.4.0 through 1.10.0 are vulnerable to a remote code execution (RCE) attack when a configuration u
Apache Airflow Docker's Provider prior to 3.0.0 shipped with an example DAG that was vulnerable to (authenticated) remot
Apache OpenOffice supports the storage of passwords for web connections in the user's configuration database. The stored
Apache OpenOffice supports the storage of passwords for web connections in the user's configuration database. The stored
Improper Input Validation vulnerability in HTTP/2 frame handling of Apache Traffic Server allows an attacker to smuggle
Improper Input Validation vulnerability in HTTP/2 header parsing of Apache Traffic Server allows an attacker to smuggle
Improper Input Validation vulnerability in handling the Transfer-Encoding header of Apache Traffic Server allows an atta
Improper Input Validation vulnerability in HTTP/1.1 header parsing of Apache Traffic Server allows an attacker to send i
Improper Input Validation vulnerability in HTTP/2 request validation of Apache Traffic Server allows an attacker to crea
Improper Input Validation vulnerability in header parsing of Apache Traffic Server allows an attacker to request secure
It is possible to crash (panic) an application by providing a corrupted data to be read. This issue affects Rust applica
It is possible for a Reader to consume memory beyond the allowed constraints and thus lead to out of memory on the syste
It is possible to provide data to be read that leads the reader to loop in cycles endlessly, consuming CPU. This issue a
Apache Hadoop's FileUtil.unTar(File, File) API does not escape the input file name before being passed to the shell. An
A carefully crafted invocation on the Image plugin could trigger an CSRF vulnerability on Apache JSPWiki before 2.11.3,
A carefully crafted request on WeblogPlugin could trigger an XSS vulnerability on Apache JSPWiki, which could allow the
A carefully crafted request on UserPreferences.jsp could trigger an CSRF vulnerability on Apache JSPWiki before 2.11.3,
A carefully crafted request on AJAXPreview.jsp could trigger an XSS vulnerability on Apache JSPWiki, which could allow t
A carefully crafted request on XHRHtml2Markup.jsp could trigger an XSS vulnerability on Apache JSPWiki up to and includi
Apache Calcite Avatica JDBC driver creates HTTP client instances based on class names provided via `httpclient_impl` con
A regular expression used in Apache MXNet (incubating) is vulnerable to a potential denial-of-service by excessive resou
The Apache Xalan Java XSLT library is vulnerable to an integer truncation issue when processing malicious XSLT styleshee
Apache CloudStack version 4.5.0 and later has a SAML 2.0 authentication Service Provider plugin which is found to be vul
A vulnerability in Apache SkyWalking NodeJS Agent prior to 0.5.1. The vulnerability will cause NodeJS services that has
The Apache Spark UI offers the possibility to enable ACLs via the configuration option spark.acls.enable. With an authen
Apache Hive before 3.1.3 "CREATE" and "DROP" function operations does not check for necessary authorization of involved
Apache Tapestry up to version 5.8.1 is vulnerable to Regular Expression Denial of Service (ReDoS) in the way it handles
In Apache Druid 0.22.1 and earlier, the server did not set appropriate headers to prevent clickjacking. Druid 0.23.0 and
In Apache Druid 0.22.1 and earlier, certain specially-crafted links result in unescaped URL parameters being sent back i
Apache Commons Configuration performs variable interpolation, allowing properties to be dynamically evaluated and expand
Apache Superset up to 1.5.1 allowed for authenticated users to access metadata information related to datasets they have
Apache Jetspeed-2 does not sufficiently filter untrusted user input by default leading to a number of issues including X
Apache Shiro before 1.9.1, A RegexRequestMatcher can be misconfigured to be bypassed on some servlet containers. Applica
The initial fixes in CVE-2022-30126 and CVE-2022-30973 for regexes in the StandardsExtractingContentHandler were insuffi
The Security Team noticed that the termination condition of the for loop in the readExternal method is a controllable va
Frequently Asked Questions
How many CVEs affect Apache?
Apache has 3,495 CVE records in our database, including 596 critical and 1319 high severity vulnerabilities. 37 of these are listed in CISA's Known Exploited Vulnerabilities catalog.
What are the most severe Apache vulnerabilities?
Apache has 596 critical severity (CVSS 9.0+) and 1319 high severity (CVSS 7.0-8.9) vulnerabilities. 37 vulnerabilities are confirmed as actively exploited in the wild.
How can I scan for Apache vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Apache products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Apache Vulnerabilities
CyberStrike scans your infrastructure for Apache vulnerabilities and provides real-time remediation guidance.
Get Started