Apache
3,495 known vulnerabilities
Top Products
In all versions of Apache Spark, its standalone resource manager accepts code to execute on a 'master' host, that then r
Apache Hadoop 3.1.0, 3.0.0-alpha to 3.0.2, 2.9.0 to 2.9.1, 2.8.0 to 2.8.4, 2.0.0-alpha to 2.7.6, 0.23.0 to 0.23.11 is ex
The Apache Qpid Proton-J transport includes an optional wrapper layer to perform TLS, enabled by use of the 'transport.s
In Apache Hive 2.3.3, 3.1.0 and earlier, Hive "EXPLAIN" operation does not check for necessary authorization of involved
In Apache Hive 2.3.3, 3.1.0 and earlier, local resources on HiveServer2 machines are not properly protected against mali
Versions of Superset prior to 0.23 used an unsafe load method from the pickle library to deserialize data leading to pos
An administrator with workflow definition entitlements can use DTD to perform malicious operations, including but not li
A malicious user with enough administration entitlements can inject html-like elements containing JavaScript statements
The Apache Web Server (httpd) specific code that normalised the requested path before matching it to the URI-worker map
In Apache Impala before 3.0.1, ALTER TABLE/VIEW RENAME required ALTER on the old table. This may pose a potential securi
Missing authorization check in Apache Impala before 3.0.1 allows a Kerberos-authenticated but unauthorized user to injec
Spark's Apache Maven-based build includes a convenience script, 'build/mvn', that downloads and runs a zinc server to sp
An instance of a cross-site scripting vulnerability was identified to be present in the web based administration console
In Apache Tika 1.19 (CVE-2018-11761), we added an entity expansion limit for XML parsing. However, Tika reuses SAXParser
In Apache PDFBox 1.8.0 to 1.8.15 and 2.0.0RC1 to 2.0.11, a carefully crafted PDF file can trigger an extremely long runn
UnixAuthenticationService in Apache Ranger 1.2.0 was updated to correctly handle user input to avoid Stack-based buffer
The statistics generator in Apache Pony Mail 0.7 to 0.9 was found to be returning timestamp data without proper authoriz
When the default servlet in Apache Tomcat versions 9.0.0.M1 to 9.0.11, 8.5.0 to 8.5.33 and 7.0.23 to 7.0.90 returned a r
In Apache HTTP Server 2.4.17 to 2.4.34, by sending continuous, large SETTINGS frames a client can occupy a connection, s
CouchDB in Vectra Networks Cognito Brain and Sensor before 4.3 contains a local code execution vulnerability.
Apache Mesos can be configured to require authentication to call the Executor HTTP API using JSON Web Token (JWT). In Ap
In Apache Tika 1.2 to 1.18, a carefully crafted file can trigger an infinite loop in the IptcAnpaParser.
In Apache Tika 0.9 to 1.18, in a rare edge case where a user does not specify an extract directory on the commandline (-
In Apache Tika 0.1 to 1.18, the XML parsers were not configured to limit entity expansion. They were therefore vulnerabl
In Apache Karaf version prior to 3.0.9, 4.0.9, 4.1.1, when the webconsole feature is installed in Karaf, it is available
In Apache Karaf prior to 4.2.0 release, if the sshd service in Karaf is left on so an administrator can manage the runni
Apache Camel's Mail 2.20.0 through 2.20.3, 2.21.0 through 2.21.1 and 2.22.0 is vulnerable to path traversal.
Apache SpamAssassin 3.4.2 fixes a local user code injection in the meta rule syntax.
A potential Remote Code Execution bug exists with the PDFInfo plugin in Apache SpamAssassin before 3.4.2.
A denial of service vulnerability was identified that exists in Apache SpamAssassin before 3.4.2. The vulnerability aris
When parsing a malformed JSON payload, libprocess in Apache Mesos versions 1.4.0 to 1.5.0 might crash due to an uncaught
TLS hostname verification when using the Apache ActiveMQ Client before 5.15.6 was missing which could make the client vu
Pages that are rendered using the ESI plugin can have access to the cookie header when the plugin is configured not to a
A carefully crafted invalid TLS handshake can cause Apache Traffic Server (ATS) to segfault. This affects version 6.2.2.
When there are multiple ranges in a range request, Apache Traffic Server (ATS) will read the entire object from cache. T
There are multiple HTTP smuggling and cache poisoning issues when clients making malicious requests interact with Apache
Adding method ACLs in remap.config can cause a segfault when the user makes a carefully crafted request. This affects ve
mod_perl 2.0 through 2.0.10 allows attackers to execute arbitrary Perl code by placing it in a user-owned .htaccess file
An authenticated user can execute ALTER TABLE EXCHANGE PARTITIONS without being authorized by Apache Sentry before 2.0.1
This affects Apache Cayenne 4.1.M1, 3.2.M1, 4.0.M2 to 4.0.M5, 4.0.B1, 4.0.B2, 4.0.RC1, 3.1, 3.1.1, 3.1.2. CayenneModeler
Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullN
When reading a specially crafted ZIP archive, the read method of Apache Commons Compress 1.7 to 1.17's ZipArchiveInputSt
Possible CRLF injection allowing HTTP response splitting attacks for sites which use mod_userdir. This issue was mitigat
From version 1.3.0 onward, Apache Spark's standalone master exposes a REST API for job submission, in addition to the su
CouchDB administrative users before 2.2.0 can configure the database server via HTTP(S). Due to insufficient validation
It was noticed an XSS in certain 404 pages that could be exploited to perform an XSS attack. Chrome will detect this as
If an async request was completed by the application at the same time as the container triggered the async timeout, a ra
An improper handing of overflow in the UTF-8 decoder with supplementary characters can lead to an infinite loop in the d
Apache Axis 1.x up to and including 1.4 is vulnerable to a cross-site scripting (XSS) attack in the default servlet/serv
The host name verification when using TLS with the WebSocket client was missing. It is now enabled by default. Versions
Frequently Asked Questions
How many CVEs affect Apache?
Apache has 3,495 CVE records in our database, including 596 critical and 1319 high severity vulnerabilities. 37 of these are listed in CISA's Known Exploited Vulnerabilities catalog.
What are the most severe Apache vulnerabilities?
Apache has 596 critical severity (CVSS 9.0+) and 1319 high severity (CVSS 7.0-8.9) vulnerabilities. 37 vulnerabilities are confirmed as actively exploited in the wild.
How can I scan for Apache vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Apache products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Apache Vulnerabilities
CyberStrike scans your infrastructure for Apache vulnerabilities and provides real-time remediation guidance.
Get Started