Apache Software Foundation Known Exploited Vulnerabilities
Evidence-backed KEV intelligence for Apache Software Foundation products — CISA KEV status, confidence, sensor telemetry, and virtual-patch availability.
Total KEVs
50
In CISA KEV
29
Beyond CISA KEV
21
Sensor Observed
4
Virtual Patch Available
2
Apache Software Foundation KEVs Added by Year
50 Apache Software Foundation KEVs added all time (primary attestation date).
Attested CVEs
| CVE | Product | Confidence | CISA KEV | Added |
|---|---|---|---|---|
|
CVE-2025-68493
Apache Struts, Apache Struts: XXE vulnerability in outdated XWork component |
Apache Struts | High | Not in CISA | 20 Jul 2026 |
|
CVE-2021-30128
Unsafe deserialization in Apache OFBiz |
Apache OFBiz | Confirmed | Not in CISA | 12 Jun 2026 |
|
CVE-2021-31805
Forced OGNL evaluation, when evaluated on raw not validated user input in tag attributes, may lead to RCE. |
Apache Struts | Confirmed | Not in CISA | 12 Jun 2026 |
|
CVE-2020-17518
Apache Flink directory traversal attack: remote file writing through the REST API |
Apache Flink | Confirmed | Not in CISA | 05 Dec 2025 |
|
CVE-2023-50968
Apache OFBiz: Arbitrary file properties reading and SSRF attack |
Apache OFBiz | High | Not in CISA | 25 Nov 2025 |
|
CVE-2021-37580
Apache ShenYu Admin bypass JWT authentication |
Apache ShenYu Admin | High | Not in CISA | 08 Nov 2025 |
|
CVE-2023-49070
Pre-auth RCE in Apache Ofbiz 18.12.09 due to XML-RPC still present |
Apache OFBiz | High | Not in CISA | 07 Jul 2025 |
|
CVE-2023-51467
Apache OFBiz: Pre-authentication Remote Code Execution (RCE) vulnerability |
Apache OFBiz | High | Not in CISA | 30 Jun 2025 |
|
CVE-2018-1335
From Apache Tika versions 1.7 to 1.17, clients could send carefully crafted headers to tika-server that could be used to inject commands into the... |
Apache Tika | High | Not in CISA | 05 Jul 2025 |
|
CVE-2024-45507
Apache OFBiz: Prevent use of URLs in files when loading them from Java or Groovy, leading to a RCE |
Apache OFBiz | High | Not in CISA | 26 Jun 2025 |
|
CVE-2020-13942
Remote Code Execution in Apache Unomi |
Apache Unomi | High | Not in CISA | 09 Jun 2025 |
|
CVE-2023-47248
PyArrow, PyArrow: Arbitrary code execution when loading a malicious data file |
PyArrow | High | Not in CISA | 09 Jun 2025 |
|
CVE-2026-34197
Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Authenticated users could perform RCE via Jolokia MBeans |
Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ | Confirmed | In CISA | 01 Jun 2026 |
|
CVE-2022-42889
Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults |
Apache Commons Text | High | Not in CISA | 20 Oct 2022 |
|
CVE-2024-38475
Apache HTTP Server weakness in mod_rewrite when first segment of substitution matches filesystem path. |
Apache HTTP Server | Confirmed | In CISA | 01 May 2025 |
|
CVE-2018-11759
The Apache Web Server (httpd) specific code that normalised the requested path before matching it to the URI-worker map in Apache Tomcat JK... |
Apache Tomcat Connectors | High | Not in CISA | 24 Apr 2025 |
|
CVE-2017-12635
Due to differences in the Erlang-based JSON parser and JavaScript-based JSON parser, it is possible in Apache CouchDB before 1.7.0 and 2.x before... |
Apache CouchDB | High | Not in CISA | 25 Apr 2025 |
|
CVE-2021-26295
RCE vulnerability in latest Apache OFBiz due to Java serialisation using RMI |
Apache OFBiz | High | Not in CISA | 28 Apr 2025 |
|
CVE-2021-27850
Bypass of the fix for CVE-2019-0195 |
Apache Tapestry | High | Not in CISA | 28 Apr 2025 |
|
CVE-2021-25646
Authenticated users can override system configurations in their requests which allows them to execute arbitrary code. |
Apache Druid | High | Not in CISA | 28 Apr 2025 |
|
CVE-2018-11776
Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullNamespace is true (either by... |
Apache Struts | Confirmed | In CISA | 03 Nov 2021 |
|
CVE-2017-5638
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception handling and error-message... |
Apache Struts | Confirmed | In CISA | 03 Nov 2021 |
|
CVE-2020-17530
Forced OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote code execution. Affected software : Apache Struts... |
Apache Struts | Confirmed | In CISA | 03 Nov 2021 |
|
CVE-2021-41773
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49 |
Apache HTTP Server | Confirmed | In CISA | 03 Nov 2021 |
|
CVE-2021-42013
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773) |
Apache HTTP Server | Confirmed | In CISA | 03 Nov 2021 |
Common Vulnerability Classes (CWE)
- CWE-502 — Deserialization of Untrusted Data 8
- CWE-22 — Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') 5
- CWE-94 — Improper Control of Generation of Code ('Code Injection') 5
- CWE-918 — Server-Side Request Forgery (SSRF) 4
- CWE-20 — Improper Input Validation 4
- CWE-78 — Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') 4
- CWE-434 — Unrestricted Upload of File with Dangerous Type 3
- CWE-917 — Improper Neutralization of Special Elements used in an Expression Language Statement ('Expression Language Injection') 3
Browse all known exploited vulnerabilities · What is a known exploited vulnerability? · Methodology