Apache Known Exploited Vulnerabilities
Evidence-backed KEV intelligence for Apache products — CISA KEV status, confidence, sensor telemetry, and virtual-patch availability.
Total KEVs
65
In CISA KEV
39
Beyond CISA KEV
26
Sensor Observed
6
Virtual Patch Available
2
Apache KEVs Added by Year
65 Apache KEVs added all time (primary attestation date).
Attested CVEs
| CVE | Product | Confidence | CISA KEV | Added |
|---|---|---|---|---|
|
CVE-2016-3081
Apache Struts 2.3.19 to 2.3.20.2, 2.3.21 to 2.3.24.1, and 2.3.25 to 2.3.28, when Dynamic Method Invocation is enabled, allow remote attackers to... |
Struts | Confirmed | Not in CISA | 23 Jul 2026 |
|
CVE-2025-68493
Apache Struts, Apache Struts: XXE vulnerability in outdated XWork component |
Apache Struts | High | Not in CISA | 20 Jul 2026 |
|
CVE-2021-30128
Unsafe deserialization in Apache OFBiz |
Apache OFBiz | Confirmed | Not in CISA | 12 Jun 2026 |
|
CVE-2021-31805
Forced OGNL evaluation, when evaluated on raw not validated user input in tag attributes, may lead to RCE. |
Apache Struts | Confirmed | Not in CISA | 12 Jun 2026 |
|
CVE-2020-17518
Apache Flink directory traversal attack: remote file writing through the REST API |
Apache Flink | Confirmed | Not in CISA | 05 Dec 2025 |
|
CVE-2023-50968
Apache OFBiz: Arbitrary file properties reading and SSRF attack |
Apache OFBiz | High | Not in CISA | 25 Nov 2025 |
|
CVE-2021-37580
Apache ShenYu Admin bypass JWT authentication |
Apache ShenYu Admin | High | Not in CISA | 08 Nov 2025 |
|
CVE-2020-11991
When using the StreamGenerator, the code parse a user-provided XML. A specially crafted XML, including external system entities, could be used to... |
Cocoon | Confirmed | Not in CISA | 29 Jul 2025 |
|
CVE-2023-49070
Pre-auth RCE in Apache Ofbiz 18.12.09 due to XML-RPC still present |
Apache OFBiz | High | Not in CISA | 07 Jul 2025 |
|
CVE-2023-51467
Apache OFBiz: Pre-authentication Remote Code Execution (RCE) vulnerability |
Apache OFBiz | High | Not in CISA | 30 Jun 2025 |
|
CVE-2018-1335
From Apache Tika versions 1.7 to 1.17, clients could send carefully crafted headers to tika-server that could be used to inject commands into the... |
Apache Tika | High | Not in CISA | 05 Jul 2025 |
|
CVE-2024-45507
Apache OFBiz: Prevent use of URLs in files when loading them from Java or Groovy, leading to a RCE |
Apache OFBiz | High | Not in CISA | 26 Jun 2025 |
|
CVE-2020-13942
Remote Code Execution in Apache Unomi |
Apache Unomi | High | Not in CISA | 09 Jun 2025 |
|
CVE-2023-47248
PyArrow, PyArrow: Arbitrary code execution when loading a malicious data file |
PyArrow | High | Not in CISA | 09 Jun 2025 |
|
CVE-2026-34197
Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Authenticated users could perform RCE via Jolokia MBeans |
Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ | Confirmed | In CISA | 01 Jun 2026 |
|
CVE-2022-42889
Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults |
Apache Commons Text | High | Not in CISA | 20 Oct 2022 |
|
CVE-2011-1752
The mod_dav_svn module for the Apache HTTP Server, as distributed in Apache Subversion before 1.6.17, allows remote attackers to cause a denial of... |
Subversion | High | Not in CISA | 06 Jun 2011 |
|
CVE-2024-38475
Apache HTTP Server weakness in mod_rewrite when first segment of substitution matches filesystem path. |
Apache HTTP Server | Confirmed | In CISA | 01 May 2025 |
|
CVE-2010-0219
Apache Axis2, as used in dswsbobje.war in SAP BusinessObjects Enterprise XI 3.2, CA ARCserve D2D r15, and other products, has a default password of... |
Axis2 | High | Not in CISA | 23 Apr 2025 |
|
CVE-2018-11759
The Apache Web Server (httpd) specific code that normalised the requested path before matching it to the URI-worker map in Apache Tomcat JK... |
Apache Tomcat Connectors | High | Not in CISA | 24 Apr 2025 |
|
CVE-2017-12635
Due to differences in the Erlang-based JSON parser and JavaScript-based JSON parser, it is possible in Apache CouchDB before 1.7.0 and 2.x before... |
Apache CouchDB | High | Not in CISA | 25 Apr 2025 |
|
CVE-2021-26295
RCE vulnerability in latest Apache OFBiz due to Java serialisation using RMI |
Apache OFBiz | High | Not in CISA | 28 Apr 2025 |
|
CVE-2021-27850
Bypass of the fix for CVE-2019-0195 |
Apache Tapestry | High | Not in CISA | 28 Apr 2025 |
|
CVE-2021-25646
Authenticated users can override system configurations in their requests which allows them to execute arbitrary code. |
Apache Druid | High | Not in CISA | 28 Apr 2025 |
|
CVE-2018-11776
Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullNamespace is true (either by... |
Apache Struts | Confirmed | In CISA | 03 Nov 2021 |
Common Vulnerability Classes (CWE)
- CWE-502 — Deserialization of Untrusted Data 8
- CWE-94 — Improper Control of Generation of Code ('Code Injection') 7
- CWE-78 — Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') 5
- CWE-22 — Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') 5
- CWE-20 — Improper Input Validation 4
- CWE-434 — Unrestricted Upload of File with Dangerous Type 4
- CWE-918 — Server-Side Request Forgery (SSRF) 4
- CWE-917 — Improper Neutralization of Special Elements used in an Expression Language Statement ('Expression Language Injection') 3
Browse all known exploited vulnerabilities · What is a known exploited vulnerability? · Methodology