Apache Software Foundation Known Exploited Vulnerabilities

Evidence-backed KEV intelligence for Apache Software Foundation products — CISA KEV status, confidence, sensor telemetry, and virtual-patch availability.

Total KEVs

50

In CISA KEV

29

Beyond CISA KEV

21

Sensor Observed

4

Virtual Patch Available

2

Apache Software Foundation KEVs Added by Year

Loading...

50 Apache Software Foundation KEVs added all time (primary attestation date).

Attested CVEs

CVE Confidence CISA KEV Added
CVE-2025-68493

Apache Struts, Apache Struts: XXE vulnerability in outdated XWork component

High Not in CISA 20 Jul 2026
CVE-2021-30128

Unsafe deserialization in Apache OFBiz

Confirmed Not in CISA 12 Jun 2026
CVE-2021-31805

Forced OGNL evaluation, when evaluated on raw not validated user input in tag attributes, may lead to RCE.

Confirmed Not in CISA 12 Jun 2026
CVE-2020-17518

Apache Flink directory traversal attack: remote file writing through the REST API

Confirmed Not in CISA 05 Dec 2025
CVE-2023-50968

Apache OFBiz: Arbitrary file properties reading and SSRF attack

High Not in CISA 25 Nov 2025
CVE-2021-37580

Apache ShenYu Admin bypass JWT authentication

High Not in CISA 08 Nov 2025
CVE-2023-49070

Pre-auth RCE in Apache Ofbiz 18.12.09 due to XML-RPC still present

High Not in CISA 07 Jul 2025
CVE-2023-51467

Apache OFBiz: Pre-authentication Remote Code Execution (RCE) vulnerability

High Not in CISA 30 Jun 2025
CVE-2018-1335

From Apache Tika versions 1.7 to 1.17, clients could send carefully crafted headers to tika-server that could be used to inject commands into the...

High Not in CISA 05 Jul 2025
CVE-2024-45507

Apache OFBiz: Prevent use of URLs in files when loading them from Java or Groovy, leading to a RCE

High Not in CISA 26 Jun 2025
CVE-2020-13942

Remote Code Execution in Apache Unomi

High Not in CISA 09 Jun 2025
CVE-2023-47248

PyArrow, PyArrow: Arbitrary code execution when loading a malicious data file

High Not in CISA 09 Jun 2025
CVE-2026-34197

Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Authenticated users could perform RCE via Jolokia MBeans

Confirmed In CISA 01 Jun 2026
CVE-2022-42889

Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults

High Not in CISA 20 Oct 2022
CVE-2024-38475

Apache HTTP Server weakness in mod_rewrite when first segment of substitution matches filesystem path.

Confirmed In CISA 01 May 2025
CVE-2018-11759

The Apache Web Server (httpd) specific code that normalised the requested path before matching it to the URI-worker map in Apache Tomcat JK...

High Not in CISA 24 Apr 2025
CVE-2017-12635

Due to differences in the Erlang-based JSON parser and JavaScript-based JSON parser, it is possible in Apache CouchDB before 1.7.0 and 2.x before...

High Not in CISA 25 Apr 2025
CVE-2021-26295

RCE vulnerability in latest Apache OFBiz due to Java serialisation using RMI

High Not in CISA 28 Apr 2025
CVE-2021-27850

Bypass of the fix for CVE-2019-0195

High Not in CISA 28 Apr 2025
CVE-2021-25646

Authenticated users can override system configurations in their requests which allows them to execute arbitrary code.

High Not in CISA 28 Apr 2025
CVE-2018-11776

Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullNamespace is true (either by...

Confirmed In CISA 03 Nov 2021
CVE-2017-5638

The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception handling and error-message...

Confirmed In CISA 03 Nov 2021
CVE-2020-17530

Forced OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote code execution. Affected software : Apache Struts...

Confirmed In CISA 03 Nov 2021
CVE-2021-41773

Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49

Confirmed In CISA 03 Nov 2021
CVE-2021-42013

Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)

Confirmed In CISA 03 Nov 2021

Common Vulnerability Classes (CWE)

  • CWE-502 — Deserialization of Untrusted Data 8
  • CWE-22 — Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') 5
  • CWE-94 — Improper Control of Generation of Code ('Code Injection') 5
  • CWE-918 — Server-Side Request Forgery (SSRF) 4
  • CWE-20 — Improper Input Validation 4
  • CWE-78 — Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') 4
  • CWE-434 — Unrestricted Upload of File with Dangerous Type 3
  • CWE-917 — Improper Neutralization of Special Elements used in an Expression Language Statement ('Expression Language Injection') 3

Browse all known exploited vulnerabilities · What is a known exploited vulnerability? · Methodology