apache records
3,437 published records for vendor apache.
Researcher profile
- Entered KEV
- 45 · 1.3%
- Weaponized
- 107 · 3.1%
- Pre-auth RCE
- 333
- With a fix record
- 87.2%
- Median publish → KEV
- 503 days
Recurring classes
- CWE-20 Improper Input Validation292
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')248
- CWE-502 Deserialization of Untrusted Data193
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor180
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')105
- CWE-400 Uncontrolled Resource Consumption81
The weakness classes this vendor ships most often: where to look.
CWEAll records
3,437 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
100Now | CVE-2021-44228Weaponized | Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpointsapache · log4j · CWE-20 | Critical10.0 | KEV | 100.0% | Dec 10, 2021 |
99Now | CVE-2017-5638Weaponized | The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception handling and error-mesapache · struts · CWE-755 | Critical9.8 | KEV | 100.0% | Mar 10, 2017 |
99Now | CVE-2013-2251Weaponized | Apache Struts 2.0.0 through 2.3.15 allows remote attackers to execute arbitrary OGNL expressions via a parameter with a crafted (1) action:,apache · archiva · CWE-74 | Critical9.8 | KEV | 100.0% | Jul 19, 2013 |
99Now | CVE-2021-41773Weaponized | Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49apache · http server · CWE-22 | Critical9.8 | KEV | 100.0% | Oct 5, 2021 |
99Now | CVE-2021-42013Weaponized | Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)apache · http server · CWE-22 | Critical9.8 | KEV | 100.0% | Oct 7, 2021 |
99Now | CVE-2025-24813Weaponized | Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUTapache · tomcat · CWE-44 | Critical9.8 | KEV | 99.9% | Mar 10, 2025 |
99Now | CVE-2024-32113Weaponized | Apache OFBiz: Path traversal leading to RCEapache · ofbiz · CWE-22 | Critical9.8 | KEV | 99.9% | May 8, 2024 |
99Now | CVE-2023-46604Weaponized | Apache ActiveMQ, Apache ActiveMQ Legacy OpenWire Module: Unbounded deserialization causes ActiveMQ to be vulnerable to a remote code execution (RCE) attackapache · activemq · CWE-502 | Critical9.8 | KEV | 99.9% | Oct 27, 2023 |
99Now | CVE-2020-13927Weaponized | The previous default setting for Airflow's Experimental API was to allow all API requests without authentication, but this poses security riapache · airflow · CWE-306 | Critical9.8 | KEV | 99.8% | Nov 10, 2020 |
99Now | CVE-2024-38856Weaponized | Apache OFBiz: Unauthenticated endpoint could allow execution of screen rendering codeapache · ofbiz · CWE-863 | Critical9.8 | KEV | 99.4% | Aug 5, 2024 |
99Now | CVE-2020-1938Weaponized | When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat.apache · geode | Critical9.8 | KEV | 99.3% | Feb 24, 2020 |
99Now | CVE-2024-27348Weaponized | Apache HugeGraph-Server: Command execution in gremlinapache · hugegraph · CWE-284 | Critical9.8 | KEV | 99.2% | Apr 22, 2024 |
99Now | CVE-2017-9791Weaponized | The Struts 1 plugin in Apache Struts 2.1.x and 2.3.x might allow remote code execution via a malicious field value passed in a raw message tapache · struts · CWE-20 | Critical9.8 | KEV | 98.9% | Jul 10, 2017 |
99Now | CVE-2016-3088Weaponized | The Fileserver web application in Apache ActiveMQ 5.x before 5.14.0 allows remote attackers to upload and execute arbitrary files via an HTTapache · activemq · CWE-434 | Critical9.8 | KEV | 98.5% | Jun 1, 2016 |
98Now | CVE-2023-27524Weaponized | Apache Superset: Session validation vulnerability when using provided default SECRET_KEYapache · superset · CWE-1188 | Critical9.8 | KEV | 97.4% | Apr 24, 2023 |
98Now | CVE-2018-1273Weaponized | Spring Data Commons, versions prior to 1.13 to 1.13.10, 2.0 to 2.0.5, and older unsupported versions, contain a property binder vulnerabilitbroadcom · spring data commons · CWE-94 | Critical9.8 | KEV | 97.0% | Apr 11, 2018 |
98Now | CVE-2023-33246Weaponized | Apache RocketMQ: Possible remote code execution vulnerability when using the update configuration functionapache · rocketmq · CWE-94 | Critical9.8 | KEV | 96.6% | May 24, 2023 |
98Now | CVE-2022-24112Weaponized | apisix/batch-requests plugin allows overwriting the X-REAL-IP headerapache · apisix · CWE-290 | Critical9.8 | KEV | 96.1% | Feb 11, 2022 |
98Now | CVE-2020-17530Weaponized | Forced OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote code execution.apache · struts · CWE-917 | Critical9.8 | KEV | 95.9% | Dec 10, 2020 |
97Now | CVE-2016-4437Weaponized | Apache Shiro before 1.2.5, when a cipher key has not been configured for the "remember me" feature, allows remote attackers to execute arbitapache · aurora · CWE-321 | Critical9.8 | KEV | 93.0% | Jun 7, 2016 |
97Now | CVE-2022-24706Weaponized | Remote Code Execution Vulnerability in Packagingapache · couchdb · CWE-1188 | Critical9.8 | KEV | 92.5% | Apr 26, 2022 |
97Now | CVE-2016-3427Weaponized | Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77; Java SE Embedded 8u77; and JRockit R28.3.9 allows remote attackers to afforacle · jdk · CWE-284 | Critical9.8 | KEV | 92.3% | Apr 21, 2016 |
96Now | CVE-2021-40438Weaponized | A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user.resf · rocky linux · CWE-918 | Critical9.0 | KEV | 100.0% | Sep 16, 2021 |
96Now | CVE-2021-45046Weaponized | Apache Log4j2 Thread Context Message Pattern and Context Lookup Pattern vulnerable to a denial of service attackapache · log4j · CWE-917 | Critical9.0 | KEV | 100.0% | Dec 14, 2021 |
96Now | CVE-2024-38475Weaponized | Apache HTTP Server weakness in mod_rewrite when first segment of substitution matches filesystem path.apache · http server · CWE-116 | Critical9.1 | KEV | 100.0% | Jul 1, 2024 |
- CVE-2021-44228100Now
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
CriticalCVSS 10.0KEVWeaponizedEPSS 100%apache · log4jDec 10, 2021
- CVE-2017-563899Now
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception handling and error-mes
CriticalCVSS 9.8KEVWeaponizedEPSS 100%apache · strutsMar 10, 2017
- CVE-2013-225199Now
Apache Struts 2.0.0 through 2.3.15 allows remote attackers to execute arbitrary OGNL expressions via a parameter with a crafted (1) action:,
CriticalCVSS 9.8KEVWeaponizedEPSS 100%apache · archivaJul 19, 2013
- CVE-2021-4177399Now
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
CriticalCVSS 9.8KEVWeaponizedEPSS 100%apache · http serverOct 5, 2021
- CVE-2021-4201399Now
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
CriticalCVSS 9.8KEVWeaponizedEPSS 100%apache · http serverOct 7, 2021
- CVE-2025-2481399Now
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
CriticalCVSS 9.8KEVWeaponizedEPSS 100%apache · tomcatMar 10, 2025
- CVE-2024-3211399Now
Apache OFBiz: Path traversal leading to RCE
CriticalCVSS 9.8KEVWeaponizedEPSS 100%apache · ofbizMay 8, 2024
- CVE-2023-4660499Now
Apache ActiveMQ, Apache ActiveMQ Legacy OpenWire Module: Unbounded deserialization causes ActiveMQ to be vulnerable to a remote code execution (RCE) attack
CriticalCVSS 9.8KEVWeaponizedEPSS 100%apache · activemqOct 27, 2023
- CVE-2020-1392799Now
The previous default setting for Airflow's Experimental API was to allow all API requests without authentication, but this poses security ri
CriticalCVSS 9.8KEVWeaponizedEPSS 100%apache · airflowNov 10, 2020
- CVE-2024-3885699Now
Apache OFBiz: Unauthenticated endpoint could allow execution of screen rendering code
CriticalCVSS 9.8KEVWeaponizedEPSS 99%apache · ofbizAug 5, 2024
- CVE-2020-193899Now
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat.
CriticalCVSS 9.8KEVWeaponizedEPSS 99%apache · geodeFeb 24, 2020
- CVE-2024-2734899Now
Apache HugeGraph-Server: Command execution in gremlin
CriticalCVSS 9.8KEVWeaponizedEPSS 99%apache · hugegraphApr 22, 2024
- CVE-2017-979199Now
The Struts 1 plugin in Apache Struts 2.1.x and 2.3.x might allow remote code execution via a malicious field value passed in a raw message t
CriticalCVSS 9.8KEVWeaponizedEPSS 99%apache · strutsJul 10, 2017
- CVE-2016-308899Now
The Fileserver web application in Apache ActiveMQ 5.x before 5.14.0 allows remote attackers to upload and execute arbitrary files via an HTT
CriticalCVSS 9.8KEVWeaponizedEPSS 99%apache · activemqJun 1, 2016
- CVE-2023-2752498Now
Apache Superset: Session validation vulnerability when using provided default SECRET_KEY
CriticalCVSS 9.8KEVWeaponizedEPSS 97%apache · supersetApr 24, 2023
- CVE-2018-127398Now
Spring Data Commons, versions prior to 1.13 to 1.13.10, 2.0 to 2.0.5, and older unsupported versions, contain a property binder vulnerabilit
CriticalCVSS 9.8KEVWeaponizedEPSS 97%broadcom · spring data commonsApr 11, 2018
- CVE-2023-3324698Now
Apache RocketMQ: Possible remote code execution vulnerability when using the update configuration function
CriticalCVSS 9.8KEVWeaponizedEPSS 97%apache · rocketmqMay 24, 2023
- CVE-2022-2411298Now
apisix/batch-requests plugin allows overwriting the X-REAL-IP header
CriticalCVSS 9.8KEVWeaponizedEPSS 96%apache · apisixFeb 11, 2022
- CVE-2020-1753098Now
Forced OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote code execution.
CriticalCVSS 9.8KEVWeaponizedEPSS 96%apache · strutsDec 10, 2020
- CVE-2016-443797Now
Apache Shiro before 1.2.5, when a cipher key has not been configured for the "remember me" feature, allows remote attackers to execute arbit
CriticalCVSS 9.8KEVWeaponizedEPSS 93%apache · auroraJun 7, 2016
- CVE-2022-2470697Now
Remote Code Execution Vulnerability in Packaging
CriticalCVSS 9.8KEVWeaponizedEPSS 93%apache · couchdbApr 26, 2022
- CVE-2016-342797Now
Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77; Java SE Embedded 8u77; and JRockit R28.3.9 allows remote attackers to aff
CriticalCVSS 9.8KEVWeaponizedEPSS 92%oracle · jdkApr 21, 2016
- CVE-2021-4043896Now
A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user.
CriticalCVSS 9.0KEVWeaponizedEPSS 100%resf · rocky linuxSep 16, 2021
- CVE-2021-4504696Now
Apache Log4j2 Thread Context Message Pattern and Context Lookup Pattern vulnerable to a denial of service attack
CriticalCVSS 9.0KEVWeaponizedEPSS 100%apache · log4jDec 14, 2021
- CVE-2024-3847596Now
Apache HTTP Server weakness in mod_rewrite when first segment of substitution matches filesystem path.
CriticalCVSS 9.1KEVWeaponizedEPSS 100%apache · http serverJul 1, 2024