Apache
3,495 known vulnerabilities
Top Products
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulne
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulne
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulne
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulne
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulne
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is vulnera
Apache OFBiz has unsafe deserialization prior to 17.12.06. An unauthenticated attacker can use this vulnerability to suc
A carefully crafted PDF file can trigger an OutOfMemory-Exception while loading the file. This issue affects Apache PDFB
A carefully crafted PDF file can trigger an infinite loop while loading the file. This issue affects Apache PDFBox versi
Subversion's mod_authz_svn module will crash if the server is using in-repository authz rules with the AuthzSVNReposRela
In Apache Ambari versions 2.6.2.2 and earlier, malicious users can construct file names for directory traversal and trav
Apache Hive cookie signature verification used a non constant time comparison which is known to be vulnerable to timing
If was found that the NetTest web service can be used to overload the bandwidth of a Apache OpenMeetings server. This is
The default error page for VelocityView in Apache Velocity Tools prior to 3.1 reflects back the vm file that was entered
An attacker that is able to modify Velocity templates may execute arbitrary Java code or run arbitrary system commands w
Netty is an open-source, asynchronous event-driven network application framework for rapid development of maintainable h
There is a race condition in OozieSharelibCLI in Apache Oozie before version 5.2.1 which allows a malicious attacker to
Apache Superset up to and including 0.38.0 allowed the creation of a Markdown component on a Dashboard page for describi
A cross-site scripting issue was found in Apache Ambari Views. This was addressed in Apache Ambari 2.7.4.
When loading a UDF, a specially crafted zip file could allow files to be placed outside of the UDF deployment directory.
The fix for CVE-2020-9484 was incomplete. When using Apache Tomcat 10.0.0-M1 to 10.0.0, 9.0.0.M1 to 9.0.41, 8.5.0 to 8.5
When responding to new h2c connection requests, Apache Tomcat versions 10.0.0-M1 to 10.0.0, 9.0.0.M1 to 9.0.41 and 8.5.0
In Eclipse Jetty 9.4.6.v20170531 to 9.4.36.v20210114 (inclusive), 10.0.0, and 11.0.0 when Jetty handles a request contai
Apache XmlGraphics Commons 2.4 and earlier is vulnerable to server-side request forgery, caused by improper input valida
Apache Batik 1.13 is vulnerable to server-side request forgery, caused by improper input validation by the NodePickerPan
Livy server version 0.7.0-incubating (only) is vulnerable to a cross site scripting issue in the session name. A malicio
In the default configuration, Apache MyFaces Core versions 2.2.0 to 2.2.13, 2.3.0 to 2.3.7, 2.3-next-M1 to 2.3-next-M4,
The lineage endpoint of the deprecated Experimental API was not protected by authentication in Airflow 2.0.0. This allow
Improper Access Control on Configurations Endpoint for the Stable API of Apache Airflow allows users with Viewer or User
The System Information Library for Node.JS (npm package "systeminformation") is an open source collection of functions t
In Apache Thrift 0.9.3 to 0.13.0, malicious RPC clients could send short messages which would result in a large memory a
An instance of a cross-site scripting vulnerability was identified to be present in the web based administration console
Apache Shiro before 1.7.1, when using Apache Shiro with Spring, a specially crafted HTTP request may cause an authentica
Apache Cassandra versions 2.1.0 to 2.1.22, 2.2.0 to 2.2.19, 3.0.0 to 3.0.23, and 3.11.0 to 3.11.9, when using 'dc' or 'r
Apache Druid includes the ability to execute user-provided JavaScript code embedded in various types of requests. This f
While investigating ARTEMIS-2964 it was found that the creation of advisory messages in the OpenWire protocol head of Ap
The optional ActiveMQ LDAP login module can be configured to use anonymous access to the LDAP server. In this case, for
In Apache Hadoop 3.2.0 to 3.2.1, 3.0.0-alpha1 to 3.1.3, and 2.0.0-alpha to 2.10.0, WebHDFS client might send SPNEGO auth
A flaw was discovered in OpenLDAP before 2.4.57 leading in an assertion failure in slapd in the X.509 DN parsing in deco
When ORT (now via atstccfg) generates ip_allow.config files in Apache Traffic Control 3.0.0 to 3.1.0 and 4.0.0 to 4.1.0,
An XML external entity (XXE) injection vulnerability was discovered in the Nutch DmozParser and is known to affect Nutch
When handler-router component is enabled in servicecomb-java-chassis, authenticated user may inject some data and cause
Apache Guacamole 1.2.0 and earlier do not consistently restrict access to connection history based on user visibility. I
A flaw was found in jackson-databind before 2.9.10.7. FasterXML mishandles the interaction between serialization gadgets
When serving resources from a network location using the NTFS file system, Apache Tomcat versions 10.0.0-M1 to 10.0.0-M9
The XML parsers used by XMLBeans up to version 2.6.0 did not set the properties needed to protect the user from maliciou
There exists a race condition between the deletion of the temporary file and the creation of the temporary directory in
ATS negative cache option is vulnerable to a cache poisoning attack. If you have this option enabled, please upgrade or
The ATS ESI plugin has a memory disclosure vulnerability. If you are running the plugin please upgrade. Apache Traffic S
Versions of Apache DolphinScheduler prior to 1.3.2 allowed an ordinary user under any tenant to override another users p
Frequently Asked Questions
How many CVEs affect Apache?
Apache has 3,495 CVE records in our database, including 596 critical and 1319 high severity vulnerabilities. 37 of these are listed in CISA's Known Exploited Vulnerabilities catalog.
What are the most severe Apache vulnerabilities?
Apache has 596 critical severity (CVSS 9.0+) and 1319 high severity (CVSS 7.0-8.9) vulnerabilities. 37 vulnerabilities are confirmed as actively exploited in the wild.
How can I scan for Apache vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Apache products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Apache Vulnerabilities
CyberStrike scans your infrastructure for Apache vulnerabilities and provides real-time remediation guidance.
Get Started