apache kayıtları
apache üreticisine ait 3.437 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 45 · %1,3
- Silahlaştırılmış
- 107 · %3,1
- Pre-auth RCE
- 333
- Düzeltme kaydı olan
- %87,2
- Yayından KEV’e ortanca
- 503 gün
Tekrar eden sınıflar
- CWE-20 Improper Input Validation292
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')248
- CWE-502 Deserialization of Untrusted Data193
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor180
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')105
- CWE-400 Uncontrolled Resource Consumption81
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
3.437 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
100Hemen | CVE-2021-44228Silahlaştırılmış | Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpointsapache · log4j · CWE-20 | Kritik10,0 | KEV | %100,0 | 10 Ara 2021 |
99Hemen | CVE-2017-5638Silahlaştırılmış | The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception handling and error-mesapache · struts · CWE-755 | Kritik9,8 | KEV | %100,0 | 10 Mar 2017 |
99Hemen | CVE-2013-2251Silahlaştırılmış | Apache Struts 2.0.0 through 2.3.15 allows remote attackers to execute arbitrary OGNL expressions via a parameter with a crafted (1) action:,apache · archiva · CWE-74 | Kritik9,8 | KEV | %100,0 | 19 Tem 2013 |
99Hemen | CVE-2021-41773Silahlaştırılmış | Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49apache · http server · CWE-22 | Kritik9,8 | KEV | %100,0 | 5 Eki 2021 |
99Hemen | CVE-2021-42013Silahlaştırılmış | Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)apache · http server · CWE-22 | Kritik9,8 | KEV | %100,0 | 7 Eki 2021 |
99Hemen | CVE-2025-24813Silahlaştırılmış | Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUTapache · tomcat · CWE-44 | Kritik9,8 | KEV | %99,9 | 10 Mar 2025 |
99Hemen | CVE-2024-32113Silahlaştırılmış | Apache OFBiz: Path traversal leading to RCEapache · ofbiz · CWE-22 | Kritik9,8 | KEV | %99,9 | 8 May 2024 |
99Hemen | CVE-2023-46604Silahlaştırılmış | Apache ActiveMQ, Apache ActiveMQ Legacy OpenWire Module: Unbounded deserialization causes ActiveMQ to be vulnerable to a remote code execution (RCE) attackapache · activemq · CWE-502 | Kritik9,8 | KEV | %99,9 | 27 Eki 2023 |
99Hemen | CVE-2020-13927Silahlaştırılmış | The previous default setting for Airflow's Experimental API was to allow all API requests without authentication, but this poses security riapache · airflow · CWE-306 | Kritik9,8 | KEV | %99,8 | 10 Kas 2020 |
99Hemen | CVE-2024-38856Silahlaştırılmış | Apache OFBiz: Unauthenticated endpoint could allow execution of screen rendering codeapache · ofbiz · CWE-863 | Kritik9,8 | KEV | %99,4 | 5 Ağu 2024 |
99Hemen | CVE-2020-1938Silahlaştırılmış | When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat.apache · geode | Kritik9,8 | KEV | %99,3 | 24 Şub 2020 |
99Hemen | CVE-2024-27348Silahlaştırılmış | Apache HugeGraph-Server: Command execution in gremlinapache · hugegraph · CWE-284 | Kritik9,8 | KEV | %99,2 | 22 Nis 2024 |
99Hemen | CVE-2017-9791Silahlaştırılmış | The Struts 1 plugin in Apache Struts 2.1.x and 2.3.x might allow remote code execution via a malicious field value passed in a raw message tapache · struts · CWE-20 | Kritik9,8 | KEV | %98,9 | 10 Tem 2017 |
99Hemen | CVE-2016-3088Silahlaştırılmış | The Fileserver web application in Apache ActiveMQ 5.x before 5.14.0 allows remote attackers to upload and execute arbitrary files via an HTTapache · activemq · CWE-434 | Kritik9,8 | KEV | %98,5 | 1 Haz 2016 |
98Hemen | CVE-2023-27524Silahlaştırılmış | Apache Superset: Session validation vulnerability when using provided default SECRET_KEYapache · superset · CWE-1188 | Kritik9,8 | KEV | %97,4 | 24 Nis 2023 |
98Hemen | CVE-2018-1273Silahlaştırılmış | Spring Data Commons, versions prior to 1.13 to 1.13.10, 2.0 to 2.0.5, and older unsupported versions, contain a property binder vulnerabilitbroadcom · spring data commons · CWE-94 | Kritik9,8 | KEV | %97,0 | 11 Nis 2018 |
98Hemen | CVE-2023-33246Silahlaştırılmış | Apache RocketMQ: Possible remote code execution vulnerability when using the update configuration functionapache · rocketmq · CWE-94 | Kritik9,8 | KEV | %96,6 | 24 May 2023 |
98Hemen | CVE-2022-24112Silahlaştırılmış | apisix/batch-requests plugin allows overwriting the X-REAL-IP headerapache · apisix · CWE-290 | Kritik9,8 | KEV | %96,1 | 11 Şub 2022 |
98Hemen | CVE-2020-17530Silahlaştırılmış | Forced OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote code execution.apache · struts · CWE-917 | Kritik9,8 | KEV | %95,9 | 10 Ara 2020 |
97Hemen | CVE-2016-4437Silahlaştırılmış | Apache Shiro before 1.2.5, when a cipher key has not been configured for the "remember me" feature, allows remote attackers to execute arbitapache · aurora · CWE-321 | Kritik9,8 | KEV | %93,0 | 7 Haz 2016 |
97Hemen | CVE-2022-24706Silahlaştırılmış | Remote Code Execution Vulnerability in Packagingapache · couchdb · CWE-1188 | Kritik9,8 | KEV | %92,5 | 26 Nis 2022 |
97Hemen | CVE-2016-3427Silahlaştırılmış | Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77; Java SE Embedded 8u77; and JRockit R28.3.9 allows remote attackers to afforacle · jdk · CWE-284 | Kritik9,8 | KEV | %92,3 | 21 Nis 2016 |
96Hemen | CVE-2021-40438Silahlaştırılmış | A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user.resf · rocky linux · CWE-918 | Kritik9,0 | KEV | %100,0 | 16 Eyl 2021 |
96Hemen | CVE-2021-45046Silahlaştırılmış | Apache Log4j2 Thread Context Message Pattern and Context Lookup Pattern vulnerable to a denial of service attackapache · log4j · CWE-917 | Kritik9,0 | KEV | %100,0 | 14 Ara 2021 |
96Hemen | CVE-2024-38475Silahlaştırılmış | Apache HTTP Server weakness in mod_rewrite when first segment of substitution matches filesystem path.apache · http server · CWE-116 | Kritik9,1 | KEV | %100,0 | 1 Tem 2024 |
- CVE-2021-44228100Hemen
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
KritikCVSS 10,0KEVSilahlaştırılmışEPSS %100apache · log4j10 Ara 2021
- CVE-2017-563899Hemen
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception handling and error-mes
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100apache · struts10 Mar 2017
- CVE-2013-225199Hemen
Apache Struts 2.0.0 through 2.3.15 allows remote attackers to execute arbitrary OGNL expressions via a parameter with a crafted (1) action:,
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100apache · archiva19 Tem 2013
- CVE-2021-4177399Hemen
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100apache · http server5 Eki 2021
- CVE-2021-4201399Hemen
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100apache · http server7 Eki 2021
- CVE-2025-2481399Hemen
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100apache · tomcat10 Mar 2025
- CVE-2024-3211399Hemen
Apache OFBiz: Path traversal leading to RCE
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100apache · ofbiz8 May 2024
- CVE-2023-4660499Hemen
Apache ActiveMQ, Apache ActiveMQ Legacy OpenWire Module: Unbounded deserialization causes ActiveMQ to be vulnerable to a remote code execution (RCE) attack
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100apache · activemq27 Eki 2023
- CVE-2020-1392799Hemen
The previous default setting for Airflow's Experimental API was to allow all API requests without authentication, but this poses security ri
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100apache · airflow10 Kas 2020
- CVE-2024-3885699Hemen
Apache OFBiz: Unauthenticated endpoint could allow execution of screen rendering code
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %99apache · ofbiz5 Ağu 2024
- CVE-2020-193899Hemen
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat.
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %99apache · geode24 Şub 2020
- CVE-2024-2734899Hemen
Apache HugeGraph-Server: Command execution in gremlin
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %99apache · hugegraph22 Nis 2024
- CVE-2017-979199Hemen
The Struts 1 plugin in Apache Struts 2.1.x and 2.3.x might allow remote code execution via a malicious field value passed in a raw message t
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %99apache · struts10 Tem 2017
- CVE-2016-308899Hemen
The Fileserver web application in Apache ActiveMQ 5.x before 5.14.0 allows remote attackers to upload and execute arbitrary files via an HTT
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %99apache · activemq1 Haz 2016
- CVE-2023-2752498Hemen
Apache Superset: Session validation vulnerability when using provided default SECRET_KEY
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %97apache · superset24 Nis 2023
- CVE-2018-127398Hemen
Spring Data Commons, versions prior to 1.13 to 1.13.10, 2.0 to 2.0.5, and older unsupported versions, contain a property binder vulnerabilit
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %97broadcom · spring data commons11 Nis 2018
- CVE-2023-3324698Hemen
Apache RocketMQ: Possible remote code execution vulnerability when using the update configuration function
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %97apache · rocketmq24 May 2023
- CVE-2022-2411298Hemen
apisix/batch-requests plugin allows overwriting the X-REAL-IP header
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %96apache · apisix11 Şub 2022
- CVE-2020-1753098Hemen
Forced OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote code execution.
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %96apache · struts10 Ara 2020
- CVE-2016-443797Hemen
Apache Shiro before 1.2.5, when a cipher key has not been configured for the "remember me" feature, allows remote attackers to execute arbit
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %93apache · aurora7 Haz 2016
- CVE-2022-2470697Hemen
Remote Code Execution Vulnerability in Packaging
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %93apache · couchdb26 Nis 2022
- CVE-2016-342797Hemen
Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77; Java SE Embedded 8u77; and JRockit R28.3.9 allows remote attackers to aff
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %92oracle · jdk21 Nis 2016
- CVE-2021-4043896Hemen
A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user.
KritikCVSS 9,0KEVSilahlaştırılmışEPSS %100resf · rocky linux16 Eyl 2021
- CVE-2021-4504696Hemen
Apache Log4j2 Thread Context Message Pattern and Context Lookup Pattern vulnerable to a denial of service attack
KritikCVSS 9,0KEVSilahlaştırılmışEPSS %100apache · log4j14 Ara 2021
- CVE-2024-3847596Hemen
Apache HTTP Server weakness in mod_rewrite when first segment of substitution matches filesystem path.
KritikCVSS 9,1KEVSilahlaştırılmışEPSS %100apache · http server1 Tem 2024