Apache Known Exploited Vulnerabilities

Evidence-backed KEV intelligence for Apache products — CISA KEV status, confidence, sensor telemetry, and virtual-patch availability.

Total KEVs

65

In CISA KEV

39

Beyond CISA KEV

26

Sensor Observed

6

Virtual Patch Available

2

Apache KEVs Added by Year

Loading...

65 Apache KEVs added all time (primary attestation date).

Attested CVEs

CVE Confidence CISA KEV Added
CVE-2016-3081

Apache Struts 2.3.19 to 2.3.20.2, 2.3.21 to 2.3.24.1, and 2.3.25 to 2.3.28, when Dynamic Method Invocation is enabled, allow remote attackers to...

Confirmed Not in CISA 23 Jul 2026
CVE-2025-68493

Apache Struts, Apache Struts: XXE vulnerability in outdated XWork component

High Not in CISA 20 Jul 2026
CVE-2021-30128

Unsafe deserialization in Apache OFBiz

Confirmed Not in CISA 12 Jun 2026
CVE-2021-31805

Forced OGNL evaluation, when evaluated on raw not validated user input in tag attributes, may lead to RCE.

Confirmed Not in CISA 12 Jun 2026
CVE-2020-17518

Apache Flink directory traversal attack: remote file writing through the REST API

Confirmed Not in CISA 05 Dec 2025
CVE-2023-50968

Apache OFBiz: Arbitrary file properties reading and SSRF attack

High Not in CISA 25 Nov 2025
CVE-2021-37580

Apache ShenYu Admin bypass JWT authentication

High Not in CISA 08 Nov 2025
CVE-2020-11991

When using the StreamGenerator, the code parse a user-provided XML. A specially crafted XML, including external system entities, could be used to...

Confirmed Not in CISA 29 Jul 2025
CVE-2023-49070

Pre-auth RCE in Apache Ofbiz 18.12.09 due to XML-RPC still present

High Not in CISA 07 Jul 2025
CVE-2023-51467

Apache OFBiz: Pre-authentication Remote Code Execution (RCE) vulnerability

High Not in CISA 30 Jun 2025
CVE-2018-1335

From Apache Tika versions 1.7 to 1.17, clients could send carefully crafted headers to tika-server that could be used to inject commands into the...

High Not in CISA 05 Jul 2025
CVE-2024-45507

Apache OFBiz: Prevent use of URLs in files when loading them from Java or Groovy, leading to a RCE

High Not in CISA 26 Jun 2025
CVE-2020-13942

Remote Code Execution in Apache Unomi

High Not in CISA 09 Jun 2025
CVE-2023-47248

PyArrow, PyArrow: Arbitrary code execution when loading a malicious data file

High Not in CISA 09 Jun 2025
CVE-2026-34197

Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Authenticated users could perform RCE via Jolokia MBeans

Confirmed In CISA 01 Jun 2026
CVE-2022-42889

Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults

High Not in CISA 20 Oct 2022
CVE-2011-1752

The mod_dav_svn module for the Apache HTTP Server, as distributed in Apache Subversion before 1.6.17, allows remote attackers to cause a denial of...

High Not in CISA 06 Jun 2011
CVE-2024-38475

Apache HTTP Server weakness in mod_rewrite when first segment of substitution matches filesystem path.

Confirmed In CISA 01 May 2025
CVE-2010-0219

Apache Axis2, as used in dswsbobje.war in SAP BusinessObjects Enterprise XI 3.2, CA ARCserve D2D r15, and other products, has a default password of...

High Not in CISA 23 Apr 2025
CVE-2018-11759

The Apache Web Server (httpd) specific code that normalised the requested path before matching it to the URI-worker map in Apache Tomcat JK...

High Not in CISA 24 Apr 2025
CVE-2017-12635

Due to differences in the Erlang-based JSON parser and JavaScript-based JSON parser, it is possible in Apache CouchDB before 1.7.0 and 2.x before...

High Not in CISA 25 Apr 2025
CVE-2021-26295

RCE vulnerability in latest Apache OFBiz due to Java serialisation using RMI

High Not in CISA 28 Apr 2025
CVE-2021-27850

Bypass of the fix for CVE-2019-0195

High Not in CISA 28 Apr 2025
CVE-2021-25646

Authenticated users can override system configurations in their requests which allows them to execute arbitrary code.

High Not in CISA 28 Apr 2025
CVE-2018-11776

Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullNamespace is true (either by...

Confirmed In CISA 03 Nov 2021

Common Vulnerability Classes (CWE)

  • CWE-502 — Deserialization of Untrusted Data 8
  • CWE-94 — Improper Control of Generation of Code ('Code Injection') 7
  • CWE-78 — Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') 5
  • CWE-22 — Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') 5
  • CWE-20 — Improper Input Validation 4
  • CWE-434 — Unrestricted Upload of File with Dangerous Type 4
  • CWE-918 — Server-Side Request Forgery (SSRF) 4
  • CWE-917 — Improper Neutralization of Special Elements used in an Expression Language Statement ('Expression Language Injection') 3

Browse all known exploited vulnerabilities · What is a known exploited vulnerability? · Methodology