Apache Software Foundation vendor intelligence
Apache Software Foundation Known Exploited Vulnerabilities
Track evidence-backed exploitation affecting Apache Software Foundation products, including the gap beyond CISA KEV, confidence assessments, sensor observations, and practical response context.
- Total KEVs
- 51
- Known exploited vulnerabilities affecting Apache Software Foundation products
- In CISA KEV
- 30
- Records also listed in the official catalog
- Beyond CISA KEV
- 21
- Additional exploited CVEs absent from CISA KEV
- Sensor Observed
- 5
- Apache Software Foundation KEVs with sensor-observed exploitation activity
The catalog gap matters for Apache Software Foundation exposure
21 of the 51 exploited Apache Software Foundation CVEs tracked here are not in CISA KEV. Teams relying on the official catalog alone would miss 41% of this vendor portfolio.
- 59%
- Covered by CISA
- 41%
- Beyond CISA
- 26
- Product families
Attested Apache Software Foundation CVEs
Search the exploited-vulnerability portfolio, then narrow it to official CISA coverage or the additional records KEV Intelligence tracks beyond the catalog.
How exploitation is verified| CVE / description | Product | Confidence | CISA KEV | Added |
|---|---|---|---|---|
|
CVE-2026-34486
Apache Tomcat: Fix for CVE-2026-29146 allowed bypass of EncryptInterceptor |
Apache Tomcat | Confirmed | In CISA | 04 Aug 2026 |
|
CVE-2025-68493
Apache Struts, Apache Struts: XXE vulnerability in outdated XWork component |
Apache Struts | High | Beyond CISA | 20 Jul 2026 |
|
CVE-2021-30128
Unsafe deserialization in Apache OFBiz |
Apache OFBiz | Confirmed | Beyond CISA | 12 Jun 2026 |
|
CVE-2021-31805
Forced OGNL evaluation, when evaluated on raw not validated user input in tag attributes, may lead to RCE. |
Apache Struts | Confirmed | Beyond CISA | 12 Jun 2026 |
|
CVE-2020-17518
Apache Flink directory traversal attack: remote file writing through the REST API |
Apache Flink | Confirmed | Beyond CISA | 05 Dec 2025 |
|
CVE-2023-50968
Apache OFBiz: Arbitrary file properties reading and SSRF attack |
Apache OFBiz | High | Beyond CISA | 25 Nov 2025 |
|
CVE-2021-37580
Apache ShenYu Admin bypass JWT authentication |
Apache ShenYu Admin | High | Beyond CISA | 08 Nov 2025 |
|
CVE-2023-49070
Pre-auth RCE in Apache Ofbiz 18.12.09 due to XML-RPC still present |
Apache OFBiz | High | Beyond CISA | 07 Jul 2025 |
|
CVE-2023-51467
Apache OFBiz: Pre-authentication Remote Code Execution (RCE) vulnerability |
Apache OFBiz | High | Beyond CISA | 30 Jun 2025 |
|
CVE-2018-1335
From Apache Tika versions 1.7 to 1.17, clients could send carefully crafted headers to tika-server that could be used to inject commands into the... |
Apache Tika | High | Beyond CISA | 05 Jul 2025 |
|
CVE-2024-45507
Apache OFBiz: Prevent use of URLs in files when loading them from Java or Groovy, leading to a RCE |
Apache OFBiz | High | Beyond CISA | 26 Jun 2025 |
|
CVE-2020-13942
Remote Code Execution in Apache Unomi |
Apache Unomi | High | Beyond CISA | 09 Jun 2025 |
|
CVE-2023-47248
PyArrow, PyArrow: Arbitrary code execution when loading a malicious data file |
PyArrow | High | Beyond CISA | 09 Jun 2025 |
|
CVE-2026-34197
Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Authenticated users could perform RCE via Jolokia MBeans |
Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ | Confirmed | In CISA | 01 Jun 2026 |
|
CVE-2022-42889
Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults |
Apache Commons Text | High | Beyond CISA | 20 Oct 2022 |
|
CVE-2024-38475
Apache HTTP Server weakness in mod_rewrite when first segment of substitution matches filesystem path. |
Apache HTTP Server | Confirmed | In CISA | 01 May 2025 |
|
CVE-2018-11759
The Apache Web Server (httpd) specific code that normalised the requested path before matching it to the URI-worker map in Apache Tomcat JK... |
Apache Tomcat Connectors | High | Beyond CISA | 24 Apr 2025 |
|
CVE-2017-12635
Due to differences in the Erlang-based JSON parser and JavaScript-based JSON parser, it is possible in Apache CouchDB before 1.7.0 and 2.x before... |
Apache CouchDB | High | Beyond CISA | 25 Apr 2025 |
|
CVE-2021-26295
RCE vulnerability in latest Apache OFBiz due to Java serialisation using RMI |
Apache OFBiz | High | Beyond CISA | 28 Apr 2025 |
|
CVE-2021-27850
Bypass of the fix for CVE-2019-0195 |
Apache Tapestry | High | Beyond CISA | 28 Apr 2025 |
|
CVE-2021-25646
Authenticated users can override system configurations in their requests which allows them to execute arbitrary code. |
Apache Druid | High | Beyond CISA | 28 Apr 2025 |
|
CVE-2018-11776
Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullNamespace is true (either by... |
Apache Struts | Confirmed | In CISA | 03 Nov 2021 |
|
CVE-2017-5638
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception handling and error-message... |
Apache Struts | Confirmed | In CISA | 03 Nov 2021 |
|
CVE-2020-17530
Forced OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote code execution. Affected software : Apache Struts... |
Apache Struts | Confirmed | In CISA | 03 Nov 2021 |
|
CVE-2021-41773
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49 |
Apache HTTP Server | Confirmed | In CISA | 03 Nov 2021 |
|
CVE-2021-42013
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773) |
Apache HTTP Server | Confirmed | In CISA | 03 Nov 2021 |
|
CVE-2017-9805
The REST Plugin in Apache Struts 2.1.1 through 2.3.x before 2.3.34 and 2.5.x before 2.5.13 uses an XStreamHandler with an instance of XStream for... |
Apache Struts | Confirmed | In CISA | 03 Nov 2021 |
|
CVE-2021-40438
mod_proxy SSRF |
Apache HTTP Server | Confirmed | In CISA | 01 Dec 2021 |
|
CVE-2021-44228
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints |
Apache Log4j2 | Confirmed | In CISA | 10 Dec 2021 |
|
CVE-2020-11978
An issue was found in Apache Airflow versions 1.10.10 and below. A remote code/command injection vulnerability was discovered in one of the example... |
Apache Airflow | Confirmed | In CISA | 18 Jan 2022 |
|
CVE-2006-1547
ActionForm in Apache Software Foundation (ASF) Struts before 1.2.9 with BeanUtils 1.7 allows remote attackers to cause a denial of service via a... |
Struts | Confirmed | In CISA | 21 Jan 2022 |
|
CVE-2017-9791
The Struts 1 plugin in Apache Struts 2.1.x and 2.3.x might allow remote code execution via a malicious field value passed in a raw message to the... |
Apache Struts | Confirmed | In CISA | 10 Feb 2022 |
|
CVE-2017-12615
When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g. via setting the readonly initialisation parameter of the Default... |
Apache Tomcat | Confirmed | In CISA | 25 Mar 2022 |
|
CVE-2017-12617
When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTTP PUTs enabled (e.g. via... |
Apache Tomcat | Confirmed | In CISA | 25 Mar 2022 |
|
CVE-2022-24112
apisix/batch-requests plugin allows overwriting the X-REAL-IP header |
Apache APISIX | Confirmed | In CISA | 25 Aug 2022 |
|
CVE-2022-24706
Remote Code Execution Vulnerability in Packaging |
Apache CouchDB | Confirmed | In CISA | 25 Aug 2022 |
|
CVE-2022-33891
Apache Spark shell command injection vulnerability via Spark UI |
Apache Spark | Confirmed | In CISA | 07 Mar 2023 |
|
CVE-2021-45046
Apache Log4j2 Thread Context Message Pattern and Context Lookup Pattern vulnerable to a denial of service attack |
Apache Log4j | Confirmed | In CISA | 01 May 2023 |
|
CVE-2016-8735
Remote code execution is possible with Apache Tomcat before 6.0.48, 7.x before 7.0.73, 8.x before 8.0.39, 8.5.x before 8.5.7, and 9.x before... |
Apache Tomcat | Confirmed | In CISA | 12 May 2023 |
|
CVE-2023-33246
Apache RocketMQ: Possible remote code execution vulnerability when using the update configuration function |
Apache RocketMQ | Confirmed | In CISA | 06 Sep 2023 |
|
CVE-2023-46604
Apache ActiveMQ, Apache ActiveMQ Legacy OpenWire Module: Unbounded deserialization causes ActiveMQ to be vulnerable to a remote code execution (RCE) attack |
Apache ActiveMQ, Apache ActiveMQ Legacy OpenWire Module | Confirmed | In CISA | 02 Nov 2023 |
|
CVE-2023-27524
Apache Superset: Session validation vulnerability when using provided default SECRET_KEY |
Apache Superset | Confirmed | In CISA | 08 Jan 2024 |
|
CVE-2020-17519
Apache Flink directory traversal attack: reading remote files through the REST API |
Apache Flink | Confirmed | In CISA | 23 May 2024 |
|
CVE-2024-32113
Apache OFBiz: Path traversal leading to RCE |
Apache OFBiz | Confirmed | In CISA | 07 Aug 2024 |
|
CVE-2024-38856
Apache OFBiz: Unauthenticated endpoint could allow execution of screen rendering code |
Apache OFBiz | Confirmed | In CISA | 27 Aug 2024 |
|
CVE-2024-27348
Apache HugeGraph-Server: Command execution in gremlin |
Apache HugeGraph-Server | Confirmed | In CISA | 18 Sep 2024 |
|
CVE-2024-45195
Apache OFBiz: Confused controller-view authorization logic (forced browsing) |
Apache OFBiz | Confirmed | In CISA | 04 Feb 2025 |
|
CVE-2025-24813
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT |
Apache Tomcat | Confirmed | In CISA | 01 Apr 2025 |
|
CVE-2024-53677
Apache Struts: Mixing setters for uploaded files and normal fields can allow bypass file upload checks |
Apache Struts | High | Beyond CISA | 11 Dec 2024 |
|
CVE-2022-24288
Apache Airflow: RCE in example DAGs |
Apache Airflow | High | Beyond CISA | 25 Feb 2022 |
|
CVE-2018-8006
An instance of a cross-site scripting vulnerability was identified to be present in the web based administration console on the queue.jsp page of... |
Apache ActiveMQ | High | Beyond CISA | 10 Oct 2018 |
No Apache Software Foundation CVEs match this search or filter.
Showing 51 of 51 Apache Software Foundation known exploited vulnerabilities.
Recurring weakness patterns
Deserialization, limitation, and control account for eighteen mapped occurrences across this Apache Software Foundation KEV portfolio.
CWE-502
Deserialization of Untrusted Data
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CWE-94
Improper Control of Generation of Code ('Code Injection')
CWE-918
Server-Side Request Forgery (SSRF)
CWE-20
Improper Input Validation
CWE-78
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CWE-434
Unrestricted Upload of File with Dangerous Type
CWE-917
Improper Neutralization of Special Elements used in an Expression Language Statement ('Expression Language Injection')
Early warning alerts
Get alerts on high-impact exploitation
Receive curator-selected alerts when exploitation activity warrants attention. Each alert includes the evidence and context needed to decide what requires attention now.