Apache
3,495 known vulnerabilities
Top Products
All versions of Apache Santuario - XML Security for Java prior to 2.2.3 and 2.1.7 are vulnerable to an issue where the "
Apache Shiro before 1.8.0, when using Apache Shiro with Spring Boot, a specially crafted HTTP request may cause an authe
Apache Tomcat 8.5.0 to 8.5.63, 9.0.0-M1 to 9.0.43 and 10.0.0-M1 to 10.0.2 did not properly validate incoming TLS packets
ap_escape_quotes() may write beyond the end of a buffer when given malicious input. No included modules pass untrusted d
A vulnerability in XML processing in Apache Jena, in versions up to 4.1.0, may allow an attacker to execute XML External
A carefully crafted request uri-path can cause mod_proxy_uwsgi to read above the allocated memory and crash (DoS). This
Malformed requests may cause the server to dereference a NULL pointer. This issue affects Apache HTTP Server 2.4.48 and
A Remote Code Execution (RCE) vulnerability was discovered in the Any23 YAMLExtractor.java file and is known to affect A
An XML external entity (XXE) injection vulnerability was discovered in the Any23 StreamUtils.java file and is known to a
The variable import endpoint was not protected by authentication in Airflow >=2.0.0, <2.1.3. This allowed unauthenticate
The Dubbo Provider will check the incoming request and the corresponding serialization type of this request meet the con
Some component in Dubbo will try to print the formated string of the input arguments, which will possibly cause RCE for
In Apache Dubbo, users may choose to use the Hessian protocol. The Hessian protocol is implemented on top of HTTP and pa
Apache Dubbo supports various rules to support configuration override or traffic routing (called routing in Dubbo). Thes
Cross Site Scripting vulnerability in markdown interpreter of Apache Zeppelin allows an attacker to inject malicious scr
Authentication bypass vulnerability in Apache Zeppelin allows an attacker to bypass Zeppelin authentication mechanism to
bash command injection vulnerability in Apache Zeppelin allows an attacker to inject system commands into Spark interpre
In Apache Ofbiz, versions v17.12.01 to v17.12.07 implement a try catch exception to handle errors at multiple locations
From Apache NiFi MiNiFi C++ version 0.5.0 the c2 protocol implements an "agent-update" command which was designed to pat
An out-of-bounds array read in the apr_time_exp*() functions was fixed in the Apache Portable Runtime 1.6.3 release (CVE
Unrestricted Upload of File with Dangerous Type vulnerability in Apache OFBiz allows an attacker to execute remote comma
User controlled `request.getHeader("Referer")`, `request.getRequestURL()` and `request.getQueryString()` are used to bui
If remote logging is not used, the worker (in the case of CeleryExecutor) or the scheduler (in the case of LocalExecutor
A crafted method sent through HTTP/2 will bypass validation and be forwarded by mod_proxy, which can lead to request spl
Improper configuration will cause ServiceComb ServiceCenter Directory Traversal problem in ServcieCenter 1.x.x versions
Apache jUDDI uses several classes related to Java's Remote Method Invocation (RMI) which (as an extension to UDDI) provi
mod_auth_openidc is an authentication/authorization module for the Apache 2.x HTTP server that functions as an OpenID Co
mod_auth_openidc is an authentication/authorization module for the Apache 2.x HTTP server that functions as an OpenID Co
While investigating DIRSTUDIO-1219 it was noticed that configured StartTLS encryption was not applied when any SASL auth
mod_auth_openidc is an authentication/authorization module for the Apache 2.x HTTP server that functions as an OpenID Co
mod_auth_openidc is an authentication/authorization module for the Apache 2.x HTTP server that functions as an OpenID Co
Impala sessions use a 16 byte secret to verify that the session is not being hijacked by another user. However, these se
In Apache Teaclave Rust SGX SDK 1.1.3, a side-channel vulnerability in base64 PEM file decoding allows system-level (adm
When reading a specially crafted ZIP archive, or a derived formats, an Apache Ant build can be made to allocate large am
When reading a specially crafted TAR archive an Apache Ant build can be made to allocate large amounts of memory that fi
When reading a specially crafted ZIP archive, Compress can be made to allocate large amounts of memory that finally lead
When reading a specially crafted TAR archive, Compress can be made to allocate large amounts of memory that finally lead
When reading a specially crafted 7Z archive, Compress can be made to allocate large amounts of memory that finally leads
When reading a specially crafted 7Z archive, the construction of the list of codecs that decompress an entry can result
Apache Tomcat 10.0.0-M1 to 10.0.6, 9.0.0.M1 to 9.0.46 and 8.5.0 to 8.5.66 did not correctly parse the HTTP transfer-enco
A vulnerability in the JNDI Realm of Apache Tomcat allows an attacker to authenticate using variations of a valid user n
A vulnerability in Apache Tomcat allows an attacker to remotely trigger a denial of service. An error introduced as part
A vulnerability in sshd-core of Apache Mina SSHD allows an attacker to overflow the server causing an OutOfMemory error.
A vulnerability in the HTML pages of Apache Jena Fuseki allows an attacker to execute arbitrary javascript on certain pa
In the Druid ingestion system, the InputSource is used for reading data from a certain data source. However, the HTTP In
Stack-based Buffer Overflow vulnerability in cachekey plugin of Apache Traffic Server. This issue affects Apache Traffic
Improper Input Validation vulnerability in HTTP/2 of Apache Traffic Server allows an attacker to DOS the server. This is
Improper Input Validation vulnerability in HTTP/2 of Apache Traffic Server allows an attacker to DOS the server. This is
Invalid values in the Content-Length header sent to Apache Traffic Server allows an attacker to smuggle requests. This i
Incorrect handling of url fragment vulnerability of Apache Traffic Server allows an attacker to poison the cache. This i
Frequently Asked Questions
How many CVEs affect Apache?
Apache has 3,495 CVE records in our database, including 596 critical and 1319 high severity vulnerabilities. 37 of these are listed in CISA's Known Exploited Vulnerabilities catalog.
What are the most severe Apache vulnerabilities?
Apache has 596 critical severity (CVSS 9.0+) and 1319 high severity (CVSS 7.0-8.9) vulnerabilities. 37 vulnerabilities are confirmed as actively exploited in the wild.
How can I scan for Apache vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Apache products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Apache Vulnerabilities
CyberStrike scans your infrastructure for Apache vulnerabilities and provides real-time remediation guidance.
Get Started