Apache
3,495 known vulnerabilities
Top Products
It was discovered that the "Trigger DAG with config" screen was susceptible to XSS attacks via the `origin` query argume
Hessian serialization is a network protocol that supports object-based transmission. Apache Cayenne's optional Remote Ob
An attacker can abuse the batch-requests plugin to send requests to bypass the IP restriction of Admin API. A default co
When running Apache Cassandra with the following configuration: enable_user_defined_functions: true enable_scripted_user
Fix of CVE-2021-40525 do not prepend delimiters upon valid directory validations. Affected implementations include: - ma
In Apache Traffic Control Traffic Ops prior to 6.1.0 or 5.1.6, an unprivileged user who can reach Traffic Ops over HTTPS
In Apache ActiveMQ Artemis prior to 2.20.0 or 2.19.1, an attacker could partially disrupt availability (DoS) through unc
Apache Gobblin trusts all certificates used for LDAP connections in Gobblin-as-a-Service. This affects versions <= 0.15.
In Apache Gobblin, the Hadoop token is written to a temp file that is visible to all local users on Unix-like systems. T
Apache Superset up to and including 1.3.2 allowed for registered database connections password leak for authenticated us
In Apache Pulsar it is possible to access data from BookKeeper that does not belong to the topics accessible by the auth
The fix for bug CVE-2020-9484 introduced a time of check, time of use vulnerability into Apache Tomcat 10.1.0-M1 to 10.1
Apache Karaf obr:* commands and run goal on the karaf-maven-plugin have partial path traversal which allows to break out
Apache Karaf allows monitoring of applications and the Java runtime by using the Java Management Extensions (JMX). JMX i
Missing authentication on ShenYu Admin when register by HTTP. This issue affected Apache ShenYu 2.4.0 and 2.4.1.
User can access /plugin api without authentication. This issue affected Apache ShenYu 2.4.0 and 2.4.1.
On Apache ShenYu versions 2.4.0 and 2.4.1, and endpoint existed that disclosed the passwords of all users. Users are rec
Groovy Code Injection & SpEL Injection which lead to Remote Code Execution. This issue affected Apache ShenYu 2.4.0 and
There's a vulnerability within the Apache Xerces Java (XercesJ) XML parser when handling specially crafted XML document
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache ShardingSphere ElasticJob-UI allows a
In Apache Airflow prior to 2.2.0. This CVE applies to a specific case where a User who has "can_create" permissions on D
CVE-2020-9493 identified a deserialization issue that was present in Apache Chainsaw. Prior to Chainsaw V2.0 Chainsaw wa
By design, the JDBCAppender in Log4j 1.2.x accepts an SQL statement as a configuration parameter where the values to be
JMSSink in all versions of Log4j 1.x is vulnerable to deserialization of untrusted data when the attacker has write acce
When using Apache Knox SSO prior to 1.6.1, a request could be crafted to redirect a user to a malicious page due to impr
Apache Guacamole 1.2.0 and 1.3.0 do not properly validate responses received from a SAML identity provider. If SAML supp
Apache Guacamole 1.3.0 and older may incorrectly include a private tunnel identifier in the non-private details of some
A deserialization vulnerability existed in dubbo hessian-lite 3.2.11 and its earlier versions, which could lead to malic
A vulnerability in the .NET SDK of Apache Avro allows an attacker to allocate excessive resources, potentially causing a
Apache Kylin provides encryption classes PasswordPlaceholderConfigurer to help users encrypt their passwords. In the enc
In Apache Kylin, Cross-origin requests with credentials are allowed to be sent from any origin. This issue affects Apach
Apache kylin checks the legitimacy of the project before executing some commands with the project name passed in by the
Apache Kylin allows users to read data from other database systems using JDBC. The MySQL JDBC driver supports certain pr
Kylin can receive user input and load any class through Class.forName(...). This issue affects Apache Kylin 2 version 2.
All request mappings in `StreamingCoordinatorController.java` handling `/kylin/api/streaming_coordinator/*` REST API end
The "first name" and "last name" fields of the Apache Pluto 3.1.0 MVCBean JSP portlet maven archetype are vulnerable to
The input fields in the JSP version of the Apache Pluto Applicant MVCBean CDI portlet are vulnerable to Cross-Site Scrip
The input fields of the Apache Pluto UrlTestPortlet are vulnerable to Cross-Site Scripting (XSS) attacks. Users should m
Apache James ManagedSieve implementation alongside with the file storage for sieve scripts is vulnerable to path travers
In Apache James, while fuzzing with Jazzer the IMAP parsing stack, we discover that crafted APPEND and STATUS IMAP comma
In Apache James, using Jazzer fuzzer, we identified that an IMAP user can craft IMAP LIST commands to orchestrate a Deni
Apache James prior to release 3.6.1 is vulnerable to a buffering attack relying on the use of the STARTTLS command. This
Apache Geode versions up to 1.12.4 and 1.13.4 are vulnerable to a log file redaction of sensitive information flaw when
Apache Log4j2 versions 2.0-beta7 through 2.17.0 (excluding security fix releases 2.3.2 and 2.12.4) are vulnerable to a r
In Apache APISIX Dashboard before 2.10.1, the Manager API uses two frameworks and introduces framework `droplet` on the
An Improper Input Validation vulnerability in DataImportHandler of Apache Solr allows an attacker to provide a Windows U
A carefully crafted request body can cause a buffer overflow in the mod_lua multipart parser (r:parsebody() called from
A crafted URI sent to httpd configured as a forward proxy (ProxyRequests on) can cause a crash (NULL pointer dereference
Improper Input Validation vulnerability in Parquet-MR of Apache Parquet allows an attacker to DoS by malicious Parquet f
Apache PLC4X - PLC4C (Only the C language implementation was effected) was vulnerable to an unsigned integer underflow f
Frequently Asked Questions
How many CVEs affect Apache?
Apache has 3,495 CVE records in our database, including 596 critical and 1319 high severity vulnerabilities. 37 of these are listed in CISA's Known Exploited Vulnerabilities catalog.
What are the most severe Apache vulnerabilities?
Apache has 596 critical severity (CVSS 9.0+) and 1319 high severity (CVSS 7.0-8.9) vulnerabilities. 37 vulnerabilities are confirmed as actively exploited in the wild.
How can I scan for Apache vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Apache products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Apache Vulnerabilities
CyberStrike scans your infrastructure for Apache vulnerabilities and provides real-time remediation guidance.
Get Started