Apache
3,495 known vulnerabilities
Top Products
Improper Privilege Management vulnerability in Apache Syncope. When: * the all-Java user workflow adapter is configure
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Syncope. A
Improper Isolation or Compartmentalization vulnerability in Apache Syncope. An administrator with adequate entitlemen
Improper Isolation or Compartmentalization vulnerability in Apache Syncope. An administrator with adequate entitlements
Uncontrolled Resource Consumption vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: fro
Improper Handling of Insufficient Privileges vulnerability in Apache Accumulo. An authenticated, but low-privileged user
The PackagerResolver of Apache Ivy is able to download online artifacts and to (re)package them in a format defined by a
A SQL Injection vulnerability exists in Apache Fineract's Office Search API (GET /api/v1/offices) in versions up to and
A boolean-based SQL Injection vulnerability exists in Apache Fineract's Client Search API (GET /api/v1/clients) in versi
A SQL Injection vulnerability exists in Apache Fineract's Report Execution API (runreports endpoint) in versions up to a
Improper Handling of Insufficient Permissions or Privileges vulnerability in Apache Kylin. Improper authorization in job
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Apache Kylin
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Kylin. A ba
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache OpenMeetings. Th
Certain Apache Doris FE HTTP REST administrative APIs were accessible without proper authentication. An unauthenticated
Insufficient Technical Documentation vulnerability in Apache Tomcat since the requirements to securely configure the Enc
Improper Handling of URL Encoding (Hex Encoding) vulnerability in Apache Tomcat's rewrite valve allowed security constra
In the Apache Airflow FAB auth manager, a DAG whose `dag_id` is `DAGs` collided with the global all-DAGs permission reso
The Apache Airflow Git provider runs its git-over-SSH operations with `StrictHostKeyChecking=no` by default, disabling S
Authenticated SSRF in Gravitino JobManager allows server-side HTTP requests to internal network and cloud metadata endpo
URL path injection via unencoded user-supplied identifiers vulnerability in Apache Gravitino. This issue affects Apache
Improper encoding of non-finite floating-point values during MapMessage JSON serialization in Apache Log4j API produces
Permissive Cross-Origin Resource Sharing (CORS) in the REST API (helix-rest, org.apache.helix.rest.server.filters.CORSFi
In Apache Airflow before 3.3.0, the REST API task-instance detail and list endpoints returned a deferred task's trigger
Before apache-airflow 3.3.0, a user authorized to read one Dag could disclose the source of other Dags co-located in the
The Config API in Apache Airflow surfaced per-key secrets-backend overrides (environment variables like `AIRFLOW__SECRET
A bug in Apache Airflow's `/ui/dependencies` scheduling graph endpoint applied the caller's readable-Dag filter to the t
The Bulk Variables API in Apache Airflow called the redactor without passing the variable's key, so the key-based `shoul
A bug in `BaseSerialization.deserialize()` allowed unrestricted `import_string()` of attacker-controlled class paths whe
Untrusted Java Deserialization in Apache OpenNLP SvmDoccatModel Versions Affected: before 3.0.0-M4 (libsvm document c
Apache Airflow's Google provider operators `GCSToSFTPOperator` and `GCSTimeSpanFileTransformOperator` joined GCS object
Improper Input Validation vulnerability in Apache Camel. This issue affects Apache Camel: from 4.8.0 through 4.18.2, fr
Improper Input Validation vulnerability in Apache Camel. This issue affects Apache Camel: through 4.14.7, from 4.15.0 t
Improper Input Validation vulnerability in Apache Camel. This issue affects Apache Camel: through 4.14.7, from 4.15.0 t
Improper Input Validation vulnerability in Apache Camel AWS SNS component. The camel-aws2-sns component filters Camel
Generation of Error Message Containing Sensitive Information vulnerability in Apache Camel Undertow Component. The came
Improper Input Validation, Exposure of Sensitive Information to an Unauthorized Actor, Server-Side Request Forgery (SSRF
Improper Input Validation, Exposure of Sensitive Information to an Unauthorized Actor, Server-Side Request Forgery (SSRF
Improper Authentication, Missing Authentication for Critical Function, Not Failing Securely ('Failing Open') vulnerabili
Generation of Error Message Containing Sensitive Information vulnerability in Apache Camel Netty HTTP component. The ca
Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection'), Authorization Bypass
Improper Input Validation, Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Inject
Improper Input Validation, Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Inject
Improper Input Validation, Unintended Proxy or Intermediary ('Confused Deputy') vulnerability in Apache Camel DAPR compo
Improper Input Validation, Authorization Bypass Through User-Controlled Key vulnerability in Apache Camel JIRA component
Improper Input Validation, Server-Side Request Forgery (SSRF) vulnerability in Apache Camel DNS component. The camel-dn
Improper Input Validation, Improper Access Control vulnerability in Apache Camel in Camel Mongodb Gridfs component. The
Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection'), Improper Input Valid
Improper Input Validation, Exposure of Sensitive Information to an Unauthorized Actor, Server-Side Request Forgery (SSRF
Improper Input Validation, Unintended Proxy or Intermediary ('Confused Deputy') vulnerability in Apache Camel CXF SOAP c
Frequently Asked Questions
How many CVEs affect Apache?
Apache has 3,495 CVE records in our database, including 596 critical and 1319 high severity vulnerabilities. 37 of these are listed in CISA's Known Exploited Vulnerabilities catalog.
What are the most severe Apache vulnerabilities?
Apache has 596 critical severity (CVSS 9.0+) and 1319 high severity (CVSS 7.0-8.9) vulnerabilities. 37 vulnerabilities are confirmed as actively exploited in the wild.
How can I scan for Apache vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Apache products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Apache Vulnerabilities
CyberStrike scans your infrastructure for Apache vulnerabilities and provides real-time remediation guidance.
Get Started