Apache vendor intelligence
Apache Known Exploited Vulnerabilities
Track evidence-backed exploitation affecting Apache products, including the gap beyond CISA KEV, confidence assessments, sensor observations, and practical response context.
- Total KEVs
- 66
- Known exploited vulnerabilities affecting Apache products
- In CISA KEV
- 40
- Records also listed in the official catalog
- Beyond CISA KEV
- 26
- Additional exploited CVEs absent from CISA KEV
- Sensor Observed
- 8
- Apache KEVs with sensor-observed exploitation activity
The catalog gap matters for Apache exposure
26 of the 66 exploited Apache CVEs tracked here are not in CISA KEV. Teams relying on the official catalog alone would miss 39% of this vendor portfolio.
- 61%
- Covered by CISA
- 39%
- Beyond CISA
- 33
- Product families
Attested Apache CVEs
Search the exploited-vulnerability portfolio, then narrow it to official CISA coverage or the additional records KEV Intelligence tracks beyond the catalog.
How exploitation is verified| CVE / description | Product | Confidence | CISA KEV | Added |
|---|---|---|---|---|
|
CVE-2026-34486
Apache Tomcat: Fix for CVE-2026-29146 allowed bypass of EncryptInterceptor |
Apache Tomcat | Confirmed | In CISA | 04 Aug 2026 |
|
CVE-2016-3081
Apache Struts 2.3.19 to 2.3.20.2, 2.3.21 to 2.3.24.1, and 2.3.25 to 2.3.28, when Dynamic Method Invocation is enabled, allow remote attackers to... |
Struts | Confirmed | Beyond CISA | 23 Jul 2026 |
|
CVE-2025-68493
Apache Struts, Apache Struts: XXE vulnerability in outdated XWork component |
Apache Struts | High | Beyond CISA | 20 Jul 2026 |
|
CVE-2021-30128
Unsafe deserialization in Apache OFBiz |
Apache OFBiz | Confirmed | Beyond CISA | 12 Jun 2026 |
|
CVE-2021-31805
Forced OGNL evaluation, when evaluated on raw not validated user input in tag attributes, may lead to RCE. |
Apache Struts | Confirmed | Beyond CISA | 12 Jun 2026 |
|
CVE-2020-17518
Apache Flink directory traversal attack: remote file writing through the REST API |
Apache Flink | Confirmed | Beyond CISA | 05 Dec 2025 |
|
CVE-2023-50968
Apache OFBiz: Arbitrary file properties reading and SSRF attack |
Apache OFBiz | High | Beyond CISA | 25 Nov 2025 |
|
CVE-2021-37580
Apache ShenYu Admin bypass JWT authentication |
Apache ShenYu Admin | High | Beyond CISA | 08 Nov 2025 |
|
CVE-2020-11991
When using the StreamGenerator, the code parse a user-provided XML. A specially crafted XML, including external system entities, could be used to... |
Cocoon | Confirmed | Beyond CISA | 29 Jul 2025 |
|
CVE-2023-49070
Pre-auth RCE in Apache Ofbiz 18.12.09 due to XML-RPC still present |
Apache OFBiz | High | Beyond CISA | 07 Jul 2025 |
|
CVE-2023-51467
Apache OFBiz: Pre-authentication Remote Code Execution (RCE) vulnerability |
Apache OFBiz | High | Beyond CISA | 30 Jun 2025 |
|
CVE-2018-1335
From Apache Tika versions 1.7 to 1.17, clients could send carefully crafted headers to tika-server that could be used to inject commands into the... |
Apache Tika | High | Beyond CISA | 05 Jul 2025 |
|
CVE-2024-45507
Apache OFBiz: Prevent use of URLs in files when loading them from Java or Groovy, leading to a RCE |
Apache OFBiz | High | Beyond CISA | 26 Jun 2025 |
|
CVE-2020-13942
Remote Code Execution in Apache Unomi |
Apache Unomi | High | Beyond CISA | 09 Jun 2025 |
|
CVE-2023-47248
PyArrow, PyArrow: Arbitrary code execution when loading a malicious data file |
PyArrow | High | Beyond CISA | 09 Jun 2025 |
|
CVE-2026-34197
Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Authenticated users could perform RCE via Jolokia MBeans |
Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ | Confirmed | In CISA | 01 Jun 2026 |
|
CVE-2022-42889
Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults |
Apache Commons Text | High | Beyond CISA | 20 Oct 2022 |
|
CVE-2011-1752
The mod_dav_svn module for the Apache HTTP Server, as distributed in Apache Subversion before 1.6.17, allows remote attackers to cause a denial of... |
Subversion | High | Beyond CISA | 06 Jun 2011 |
|
CVE-2024-38475
Apache HTTP Server weakness in mod_rewrite when first segment of substitution matches filesystem path. |
Apache HTTP Server | Confirmed | In CISA | 01 May 2025 |
|
CVE-2010-0219
Apache Axis2, as used in dswsbobje.war in SAP BusinessObjects Enterprise XI 3.2, CA ARCserve D2D r15, and other products, has a default password of... |
Axis2 | High | Beyond CISA | 23 Apr 2025 |
|
CVE-2018-11759
The Apache Web Server (httpd) specific code that normalised the requested path before matching it to the URI-worker map in Apache Tomcat JK... |
Apache Tomcat Connectors | High | Beyond CISA | 24 Apr 2025 |
|
CVE-2017-12635
Due to differences in the Erlang-based JSON parser and JavaScript-based JSON parser, it is possible in Apache CouchDB before 1.7.0 and 2.x before... |
Apache CouchDB | High | Beyond CISA | 25 Apr 2025 |
|
CVE-2021-26295
RCE vulnerability in latest Apache OFBiz due to Java serialisation using RMI |
Apache OFBiz | High | Beyond CISA | 28 Apr 2025 |
|
CVE-2021-27850
Bypass of the fix for CVE-2019-0195 |
Apache Tapestry | High | Beyond CISA | 28 Apr 2025 |
|
CVE-2021-25646
Authenticated users can override system configurations in their requests which allows them to execute arbitrary code. |
Apache Druid | High | Beyond CISA | 28 Apr 2025 |
|
CVE-2018-11776
Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullNamespace is true (either by... |
Apache Struts | Confirmed | In CISA | 03 Nov 2021 |
|
CVE-2017-5638
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception handling and error-message... |
Apache Struts | Confirmed | In CISA | 03 Nov 2021 |
|
CVE-2020-17530
Forced OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote code execution. Affected software : Apache Struts... |
Apache Struts | Confirmed | In CISA | 03 Nov 2021 |
|
CVE-2019-17558
Apache Solr 5.0.0 to Apache Solr 8.3.1 are vulnerable to a Remote Code Execution through the VelocityResponseWriter. A Velocity template can be... |
Apache Solr | Confirmed | In CISA | 03 Nov 2021 |
|
CVE-2016-4437
Apache Shiro before 1.2.5, when a cipher key has not been configured for the "remember me" feature, allows remote attackers to execute arbitrary... |
Shiro | Confirmed | In CISA | 03 Nov 2021 |
|
CVE-2019-0211
In Apache HTTP Server 2.4 releases 2.4.17 to 2.4.38, with MPM event, worker or prefork, code executing in less-privileged child processes or... |
Apache HTTP Server | Confirmed | In CISA | 03 Nov 2021 |
|
CVE-2021-41773
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49 |
Apache HTTP Server | Confirmed | In CISA | 03 Nov 2021 |
|
CVE-2021-42013
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773) |
Apache HTTP Server | Confirmed | In CISA | 03 Nov 2021 |
|
CVE-2017-9805
The REST Plugin in Apache Struts 2.1.1 through 2.3.x before 2.3.34 and 2.5.x before 2.5.13 uses an XStreamHandler with an instance of XStream for... |
Apache Struts | Confirmed | In CISA | 03 Nov 2021 |
|
CVE-2021-40438
mod_proxy SSRF |
Apache HTTP Server | Confirmed | In CISA | 01 Dec 2021 |
|
CVE-2021-44228
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints |
Apache Log4j2 | Confirmed | In CISA | 10 Dec 2021 |
|
CVE-2019-0193
In Apache Solr, the DataImportHandler, an optional but popular module to pull in data from databases and other sources, has a feature in which the... |
Apache Solr | Confirmed | In CISA | 10 Dec 2021 |
|
CVE-2020-13927
The previous default setting for Airflow's Experimental API was to allow all API requests without authentication, but this poses security risks to... |
Apache Airflow | Confirmed | In CISA | 18 Jan 2022 |
|
CVE-2020-11978
An issue was found in Apache Airflow versions 1.10.10 and below. A remote code/command injection vulnerability was discovered in one of the example... |
Apache Airflow | Confirmed | In CISA | 18 Jan 2022 |
|
CVE-2012-0391
The ExceptionDelegator component in Apache Struts before 2.2.3.1 interprets parameter values as OGNL expressions during certain exception handling... |
Struts | Confirmed | In CISA | 21 Jan 2022 |
|
CVE-2006-1547
ActionForm in Apache Software Foundation (ASF) Struts before 1.2.9 with BeanUtils 1.7 allows remote attackers to cause a denial of service via a... |
Struts | Confirmed | In CISA | 21 Jan 2022 |
|
CVE-2016-3088
The Fileserver web application in Apache ActiveMQ 5.x before 5.14.0 allows remote attackers to upload and execute arbitrary files via an HTTP PUT... |
ActiveMQ | Confirmed | In CISA | 10 Feb 2022 |
|
CVE-2017-9791
The Struts 1 plugin in Apache Struts 2.1.x and 2.3.x might allow remote code execution via a malicious field value passed in a raw message to the... |
Apache Struts | Confirmed | In CISA | 10 Feb 2022 |
|
CVE-2020-1938
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomcat treats AJP connections... |
Apache Tomcat | Confirmed | In CISA | 03 Mar 2022 |
|
CVE-2013-2251
Apache Struts 2.0.0 through 2.3.15 allows remote attackers to execute arbitrary OGNL expressions via a parameter with a crafted (1) action:, (2)... |
Struts | Confirmed | In CISA | 25 Mar 2022 |
|
CVE-2017-12615
When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g. via setting the readonly initialisation parameter of the Default... |
Apache Tomcat | Confirmed | In CISA | 25 Mar 2022 |
|
CVE-2017-12617
When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTTP PUTs enabled (e.g. via... |
Apache Tomcat | Confirmed | In CISA | 25 Mar 2022 |
|
CVE-2020-1956
Apache Kylin 2.3.0, and releases up to 2.6.5 and 3.0.1 has some restful apis which will concatenate os command with the user input string, a user... |
Kylin | Confirmed | In CISA | 25 Mar 2022 |
|
CVE-2022-24112
apisix/batch-requests plugin allows overwriting the X-REAL-IP header |
Apache APISIX | Confirmed | In CISA | 25 Aug 2022 |
|
CVE-2022-24706
Remote Code Execution Vulnerability in Packaging |
Apache CouchDB | Confirmed | In CISA | 25 Aug 2022 |
|
CVE-2022-33891
Apache Spark shell command injection vulnerability via Spark UI |
Apache Spark | Confirmed | In CISA | 07 Mar 2023 |
|
CVE-2021-45046
Apache Log4j2 Thread Context Message Pattern and Context Lookup Pattern vulnerable to a denial of service attack |
Apache Log4j | Confirmed | In CISA | 01 May 2023 |
|
CVE-2016-8735
Remote code execution is possible with Apache Tomcat before 6.0.48, 7.x before 7.0.73, 8.x before 8.0.39, 8.5.x before 8.5.7, and 9.x before... |
Apache Tomcat | Confirmed | In CISA | 12 May 2023 |
|
CVE-2023-33246
Apache RocketMQ: Possible remote code execution vulnerability when using the update configuration function |
Apache RocketMQ | Confirmed | In CISA | 06 Sep 2023 |
|
CVE-2023-46604
Apache ActiveMQ, Apache ActiveMQ Legacy OpenWire Module: Unbounded deserialization causes ActiveMQ to be vulnerable to a remote code execution (RCE) attack |
Apache ActiveMQ, Apache ActiveMQ Legacy OpenWire Module | Confirmed | In CISA | 02 Nov 2023 |
|
CVE-2023-27524
Apache Superset: Session validation vulnerability when using provided default SECRET_KEY |
Apache Superset | Confirmed | In CISA | 08 Jan 2024 |
|
CVE-2020-17519
Apache Flink directory traversal attack: reading remote files through the REST API |
Apache Flink | Confirmed | In CISA | 23 May 2024 |
|
CVE-2024-32113
Apache OFBiz: Path traversal leading to RCE |
Apache OFBiz | Confirmed | In CISA | 07 Aug 2024 |
|
CVE-2024-38856
Apache OFBiz: Unauthenticated endpoint could allow execution of screen rendering code |
Apache OFBiz | Confirmed | In CISA | 27 Aug 2024 |
|
CVE-2024-27348
Apache HugeGraph-Server: Command execution in gremlin |
Apache HugeGraph-Server | Confirmed | In CISA | 18 Sep 2024 |
|
CVE-2024-45195
Apache OFBiz: Confused controller-view authorization logic (forced browsing) |
Apache OFBiz | Confirmed | In CISA | 04 Feb 2025 |
|
CVE-2025-24813
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT |
Apache Tomcat | Confirmed | In CISA | 01 Apr 2025 |
|
CVE-2024-53677
Apache Struts: Mixing setters for uploaded files and normal fields can allow bypass file upload checks |
Apache Struts | High | Beyond CISA | 11 Dec 2024 |
|
CVE-2022-24288
Apache Airflow: RCE in example DAGs |
Apache Airflow | High | Beyond CISA | 25 Feb 2022 |
|
CVE-2020-1943
Data sent with contentId to /control/stream is not sanitized, allowing XSS attacks in Apache OFBiz 16.11.01 to 16.11.07. |
Apache OFBiz | High | Beyond CISA | 01 Apr 2020 |
|
CVE-2018-8006
An instance of a cross-site scripting vulnerability was identified to be present in the web based administration console on the queue.jsp page of... |
Apache ActiveMQ | High | Beyond CISA | 10 Oct 2018 |
No Apache CVEs match this search or filter.
Showing 66 of 66 Apache known exploited vulnerabilities.
Recurring weakness patterns
Deserialization, control, and neutralization account for twenty mapped occurrences across this Apache KEV portfolio.
CWE-502
Deserialization of Untrusted Data
CWE-94
Improper Control of Generation of Code ('Code Injection')
CWE-78
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CWE-20
Improper Input Validation
CWE-434
Unrestricted Upload of File with Dangerous Type
CWE-918
Server-Side Request Forgery (SSRF)
CWE-917
Improper Neutralization of Special Elements used in an Expression Language Statement ('Expression Language Injection')
Early warning alerts
Get alerts on high-impact exploitation
Receive curator-selected alerts when exploitation activity warrants attention. Each alert includes the evidence and context needed to decide what requires attention now.