Записи apache
3 437 опубликованных записей вендора apache.
Профиль для исследователя
- Попали в KEV
- 45 · 1,3 %
- С эксплойтом
- 107 · 3,1 %
- Pre-auth RCE
- 333
- С записью об исправлении
- 87,2 %
- Медиана: публикация → KEV
- 503 дн.
Повторяющиеся классы
- CWE-20 Improper Input Validation292
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')248
- CWE-502 Deserialization of Untrusted Data193
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor180
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')105
- CWE-400 Uncontrolled Resource Consumption81
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
3 437 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
100Срочно | CVE-2021-44228Готовый эксплойт | Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpointsapache · log4j · CWE-20 | Критическая10,0 | KEV | 100,0 % | 10 дек. 2021 г. |
99Срочно | CVE-2017-5638Готовый эксплойт | The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception handling and error-mesapache · struts · CWE-755 | Критическая9,8 | KEV | 100,0 % | 10 мар. 2017 г. |
99Срочно | CVE-2013-2251Готовый эксплойт | Apache Struts 2.0.0 through 2.3.15 allows remote attackers to execute arbitrary OGNL expressions via a parameter with a crafted (1) action:,apache · archiva · CWE-74 | Критическая9,8 | KEV | 100,0 % | 19 июл. 2013 г. |
99Срочно | CVE-2021-41773Готовый эксплойт | Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49apache · http server · CWE-22 | Критическая9,8 | KEV | 100,0 % | 5 окт. 2021 г. |
99Срочно | CVE-2021-42013Готовый эксплойт | Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)apache · http server · CWE-22 | Критическая9,8 | KEV | 100,0 % | 7 окт. 2021 г. |
99Срочно | CVE-2025-24813Готовый эксплойт | Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUTapache · tomcat · CWE-44 | Критическая9,8 | KEV | 99,9 % | 10 мар. 2025 г. |
99Срочно | CVE-2024-32113Готовый эксплойт | Apache OFBiz: Path traversal leading to RCEapache · ofbiz · CWE-22 | Критическая9,8 | KEV | 99,9 % | 8 мая 2024 г. |
99Срочно | CVE-2023-46604Готовый эксплойт | Apache ActiveMQ, Apache ActiveMQ Legacy OpenWire Module: Unbounded deserialization causes ActiveMQ to be vulnerable to a remote code execution (RCE) attackapache · activemq · CWE-502 | Критическая9,8 | KEV | 99,9 % | 27 окт. 2023 г. |
99Срочно | CVE-2020-13927Готовый эксплойт | The previous default setting for Airflow's Experimental API was to allow all API requests without authentication, but this poses security riapache · airflow · CWE-306 | Критическая9,8 | KEV | 99,8 % | 10 нояб. 2020 г. |
99Срочно | CVE-2024-38856Готовый эксплойт | Apache OFBiz: Unauthenticated endpoint could allow execution of screen rendering codeapache · ofbiz · CWE-863 | Критическая9,8 | KEV | 99,4 % | 5 авг. 2024 г. |
99Срочно | CVE-2020-1938Готовый эксплойт | When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat.apache · geode | Критическая9,8 | KEV | 99,3 % | 24 февр. 2020 г. |
99Срочно | CVE-2024-27348Готовый эксплойт | Apache HugeGraph-Server: Command execution in gremlinapache · hugegraph · CWE-284 | Критическая9,8 | KEV | 99,2 % | 22 апр. 2024 г. |
99Срочно | CVE-2017-9791Готовый эксплойт | The Struts 1 plugin in Apache Struts 2.1.x and 2.3.x might allow remote code execution via a malicious field value passed in a raw message tapache · struts · CWE-20 | Критическая9,8 | KEV | 98,9 % | 10 июл. 2017 г. |
99Срочно | CVE-2016-3088Готовый эксплойт | The Fileserver web application in Apache ActiveMQ 5.x before 5.14.0 allows remote attackers to upload and execute arbitrary files via an HTTapache · activemq · CWE-434 | Критическая9,8 | KEV | 98,5 % | 1 июн. 2016 г. |
98Срочно | CVE-2023-27524Готовый эксплойт | Apache Superset: Session validation vulnerability when using provided default SECRET_KEYapache · superset · CWE-1188 | Критическая9,8 | KEV | 97,4 % | 24 апр. 2023 г. |
98Срочно | CVE-2018-1273Готовый эксплойт | Spring Data Commons, versions prior to 1.13 to 1.13.10, 2.0 to 2.0.5, and older unsupported versions, contain a property binder vulnerabilitbroadcom · spring data commons · CWE-94 | Критическая9,8 | KEV | 97,0 % | 11 апр. 2018 г. |
98Срочно | CVE-2023-33246Готовый эксплойт | Apache RocketMQ: Possible remote code execution vulnerability when using the update configuration functionapache · rocketmq · CWE-94 | Критическая9,8 | KEV | 96,6 % | 24 мая 2023 г. |
98Срочно | CVE-2022-24112Готовый эксплойт | apisix/batch-requests plugin allows overwriting the X-REAL-IP headerapache · apisix · CWE-290 | Критическая9,8 | KEV | 96,1 % | 11 февр. 2022 г. |
98Срочно | CVE-2020-17530Готовый эксплойт | Forced OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote code execution.apache · struts · CWE-917 | Критическая9,8 | KEV | 95,9 % | 10 дек. 2020 г. |
97Срочно | CVE-2016-4437Готовый эксплойт | Apache Shiro before 1.2.5, when a cipher key has not been configured for the "remember me" feature, allows remote attackers to execute arbitapache · aurora · CWE-321 | Критическая9,8 | KEV | 93,0 % | 7 июн. 2016 г. |
97Срочно | CVE-2022-24706Готовый эксплойт | Remote Code Execution Vulnerability in Packagingapache · couchdb · CWE-1188 | Критическая9,8 | KEV | 92,5 % | 26 апр. 2022 г. |
97Срочно | CVE-2016-3427Готовый эксплойт | Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77; Java SE Embedded 8u77; and JRockit R28.3.9 allows remote attackers to afforacle · jdk · CWE-284 | Критическая9,8 | KEV | 92,3 % | 21 апр. 2016 г. |
96Срочно | CVE-2021-40438Готовый эксплойт | A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user.resf · rocky linux · CWE-918 | Критическая9,0 | KEV | 100,0 % | 16 сент. 2021 г. |
96Срочно | CVE-2021-45046Готовый эксплойт | Apache Log4j2 Thread Context Message Pattern and Context Lookup Pattern vulnerable to a denial of service attackapache · log4j · CWE-917 | Критическая9,0 | KEV | 100,0 % | 14 дек. 2021 г. |
96Срочно | CVE-2024-38475Готовый эксплойт | Apache HTTP Server weakness in mod_rewrite when first segment of substitution matches filesystem path.apache · http server · CWE-116 | Критическая9,1 | KEV | 100,0 % | 1 июл. 2024 г. |
- CVE-2021-44228100Срочно
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
КритическаяCVSS 10,0KEVГотовый эксплойтEPSS 100 %apache · log4j10 дек. 2021 г.
- CVE-2017-563899Срочно
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception handling and error-mes
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %apache · struts10 мар. 2017 г.
- CVE-2013-225199Срочно
Apache Struts 2.0.0 through 2.3.15 allows remote attackers to execute arbitrary OGNL expressions via a parameter with a crafted (1) action:,
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %apache · archiva19 июл. 2013 г.
- CVE-2021-4177399Срочно
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %apache · http server5 окт. 2021 г.
- CVE-2021-4201399Срочно
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %apache · http server7 окт. 2021 г.
- CVE-2025-2481399Срочно
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %apache · tomcat10 мар. 2025 г.
- CVE-2024-3211399Срочно
Apache OFBiz: Path traversal leading to RCE
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %apache · ofbiz8 мая 2024 г.
- CVE-2023-4660499Срочно
Apache ActiveMQ, Apache ActiveMQ Legacy OpenWire Module: Unbounded deserialization causes ActiveMQ to be vulnerable to a remote code execution (RCE) attack
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %apache · activemq27 окт. 2023 г.
- CVE-2020-1392799Срочно
The previous default setting for Airflow's Experimental API was to allow all API requests without authentication, but this poses security ri
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %apache · airflow10 нояб. 2020 г.
- CVE-2024-3885699Срочно
Apache OFBiz: Unauthenticated endpoint could allow execution of screen rendering code
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 99 %apache · ofbiz5 авг. 2024 г.
- CVE-2020-193899Срочно
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat.
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 99 %apache · geode24 февр. 2020 г.
- CVE-2024-2734899Срочно
Apache HugeGraph-Server: Command execution in gremlin
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 99 %apache · hugegraph22 апр. 2024 г.
- CVE-2017-979199Срочно
The Struts 1 plugin in Apache Struts 2.1.x and 2.3.x might allow remote code execution via a malicious field value passed in a raw message t
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 99 %apache · struts10 июл. 2017 г.
- CVE-2016-308899Срочно
The Fileserver web application in Apache ActiveMQ 5.x before 5.14.0 allows remote attackers to upload and execute arbitrary files via an HTT
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 99 %apache · activemq1 июн. 2016 г.
- CVE-2023-2752498Срочно
Apache Superset: Session validation vulnerability when using provided default SECRET_KEY
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 97 %apache · superset24 апр. 2023 г.
- CVE-2018-127398Срочно
Spring Data Commons, versions prior to 1.13 to 1.13.10, 2.0 to 2.0.5, and older unsupported versions, contain a property binder vulnerabilit
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 97 %broadcom · spring data commons11 апр. 2018 г.
- CVE-2023-3324698Срочно
Apache RocketMQ: Possible remote code execution vulnerability when using the update configuration function
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 97 %apache · rocketmq24 мая 2023 г.
- CVE-2022-2411298Срочно
apisix/batch-requests plugin allows overwriting the X-REAL-IP header
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 96 %apache · apisix11 февр. 2022 г.
- CVE-2020-1753098Срочно
Forced OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote code execution.
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 96 %apache · struts10 дек. 2020 г.
- CVE-2016-443797Срочно
Apache Shiro before 1.2.5, when a cipher key has not been configured for the "remember me" feature, allows remote attackers to execute arbit
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 93 %apache · aurora7 июн. 2016 г.
- CVE-2022-2470697Срочно
Remote Code Execution Vulnerability in Packaging
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 93 %apache · couchdb26 апр. 2022 г.
- CVE-2016-342797Срочно
Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77; Java SE Embedded 8u77; and JRockit R28.3.9 allows remote attackers to aff
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 92 %oracle · jdk21 апр. 2016 г.
- CVE-2021-4043896Срочно
A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user.
КритическаяCVSS 9,0KEVГотовый эксплойтEPSS 100 %resf · rocky linux16 сент. 2021 г.
- CVE-2021-4504696Срочно
Apache Log4j2 Thread Context Message Pattern and Context Lookup Pattern vulnerable to a denial of service attack
КритическаяCVSS 9,0KEVГотовый эксплойтEPSS 100 %apache · log4j14 дек. 2021 г.
- CVE-2024-3847596Срочно
Apache HTTP Server weakness in mod_rewrite when first segment of substitution matches filesystem path.
КритическаяCVSS 9,1KEVГотовый эксплойтEPSS 100 %apache · http server1 июл. 2024 г.