Apache
3,495 known vulnerabilities
Top Products
Apache Nuttx Versions prior to 10.1.0 are vulnerable to integer wrap-around in functions malloc, realloc and memalign. T
An XXE issue in SAXBuilder in JDOM through 2.0.6 allows attackers to cause a denial of service via a crafted HTTP reques
A vulnerability in the JsonMapObjectReaderWriter of Apache CXF allows an attacker to submit malformed JSON to a web serv
A deserialization flaw was found in Apache Chainsaw versions prior to 2.1.0 which could lead to malicious code execution
Apache HTTP Server protocol handler for the HTTP/2 protocol checks received request headers against the size limitations
In Apache PDFBox, a carefully crafted PDF file can trigger an infinite loop while loading the file. This issue affects A
In Apache PDFBox, a carefully crafted PDF file can trigger an OutOfMemory-Exception while loading the file. This issue a
Apache HTTP Server versions 2.4.39 to 2.4.46 Unexpected matching behavior with 'MergeSlashes OFF'
In Apache HTTP Server versions 2.4.0 to 2.4.46 a specially crafted SessionHeader sent by an origin server could cause a
Apache HTTP Server versions 2.4.0 to 2.4.46 A specially crafted Cookie header handled by mod_session can cause a NULL po
Apache HTTP Server versions 2.4.0 to 2.4.46 A specially crafted Digest nonce can cause a stack overflow in mod_auth_dige
Apache HTTP Server versions 2.4.41 to 2.4.46 mod_proxy_http can be made to crash (NULL pointer dereference) with special
Apache HTTP Server versions 2.4.0 to 2.4.46 Unprivileged local users can stop httpd on Windows
Apache HTTP Server versions 2.4.6 to 2.4.46 mod_proxy_wstunnel configured on an URL that is not necessarily Upgraded by
In Apache APISIX Dashboard version 2.6, we changed the default value of listen host to 0.0.0.0 in order to facilitate us
Flask-AppBuilder is a development framework, built on top of Flask. User enumeration in database authentication in Flask
Apache Dubbo prior to 2.6.9 and 2.7.9 supports Script routing which will enable a customer to route the request to the r
Apache Dubbo prior to 2.7.9 support Tag routing which will enable a customer to route the request to the right server. T
Apache Dubbo prior to 2.6.9 and 2.7.9 by default supports generic calls to arbitrary methods exposed by provider interfa
Each Apache Dubbo server will set a serialization id to tell the clients which serialization protocol it is working on.
In Apache Dubbo prior to 2.6.9 and 2.7.9, the usage of parseURL method will lead to the bypass of white host check which
Apache Fineract prior to 1.5.0 disables HTTPS hostname verification in ProcessorHelper in the configureClient method. Un
If Apache Pulsar is configured to authenticate clients using tokens based on JSON Web Tokens (JWT), the signature of the
A DNS proxy and possible amplification attack vulnerability in WebClientInfo of Apache Wicket allows an attacker to trig
Apache Traffic Server 9.0.0 is vulnerable to a remote DOS attack on the experimental Slicer plugin.
Apache Unomi prior to version 1.5.5 allows CRLF log injection because of the lack of escaping in the log statements.
The "origin" parameter passed to some of the endpoints like '/trigger' was vulnerable to XSS exploit. This issue affects
Apache OFBiz has unsafe deserialization prior to 17.12.07 version
Apache OFBiz has unsafe deserialization prior to 17.12.07 version An unauthenticated user can perform an RCE attack
Information Exposure vulnerability in context asset handling of Apache Tapestry allows an attacker to download files ins
Apache Superset up to and including 1.0.1 allowed for the creation of an external URL that could be malicious. By not ch
The S3 buckets and keys in a secure Apache Ozone Cluster must be inaccessible to anonymous access by default. The curren
Apache Maven will follow repositories that are defined in a dependency’s Project Object Model (pom) which may be surpris
An issue was discovered in giflib through 5.1.4. DumpScreen2RGB in gif2rgb.c has a heap-based buffer over-read.
The project received a report that all versions of Apache OpenOffice through 4.1.8 can open non-http(s) hyperlinks. The
A critical unauthenticated remote code execution vulnerability was found all recent versions of Apache Tapestry. The aff
When using ConfigurableInternodeAuthHadoopPlugin for authentication, Apache Solr versions prior to 8.8.2 would forward/p
In Apache Commons IO before 2.7, When invoking the method FileNameUtils.normalize with an improper input string, like "/
When starting Apache Solr versions prior to 8.8.2, configured with the SaslZkACLProvider or VMParamsAllAndReadonlyDigest
The ReplicationHandler (normally registered at "/replication" under a Solr core) in Apache Solr has a "masterUrl" (also
CXF supports (via JwtRequestCodeFilter) passing OAuth 2 parameters via a JWT token as opposed to query parameters (see:
In Eclipse Jetty 9.4.32 to 9.4.38, 10.0.0.beta2 to 10.0.1, and 11.0.0.beta2 to 11.0.1, if a user uses a webapps director
A carefully crafted or corrupt file may trigger an infinite loop in Tika's MP3Parser up to and including Tika 1.25. Apac
Apache Druid allows users to read data from other database systems using JDBC. This functionality is to allow trusted us
In Apache SpamAssassin before 3.4.5, malicious rule configuration (.cf) files can be configured to run system commands w
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulne
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulne
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulne
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulne
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulne
Frequently Asked Questions
How many CVEs affect Apache?
Apache has 3,495 CVE records in our database, including 596 critical and 1319 high severity vulnerabilities. 37 of these are listed in CISA's Known Exploited Vulnerabilities catalog.
What are the most severe Apache vulnerabilities?
Apache has 596 critical severity (CVSS 9.0+) and 1319 high severity (CVSS 7.0-8.9) vulnerabilities. 37 vulnerabilities are confirmed as actively exploited in the wild.
How can I scan for Apache vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Apache products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Apache Vulnerabilities
CyberStrike scans your infrastructure for Apache vulnerabilities and provides real-time remediation guidance.
Get Started