Apache Software Foundation Known Exploited Vulnerabilities
Evidence-backed KEV intelligence for Apache Software Foundation products — CISA KEV status, confidence, sensor telemetry, and virtual-patch availability.
Total KEVs
50
In CISA KEV
29
Beyond CISA KEV
21
Sensor Observed
4
Virtual Patch Available
2
Apache Software Foundation KEVs Added by Year
50 Apache Software Foundation KEVs added all time (primary attestation date).
Attested CVEs
| CVE | Product | Confidence | CISA KEV | Added |
|---|---|---|---|---|
|
CVE-2017-9805
The REST Plugin in Apache Struts 2.1.1 through 2.3.x before 2.3.34 and 2.5.x before 2.5.13 uses an XStreamHandler with an instance of XStream for... |
Apache Struts | Confirmed | In CISA | 03 Nov 2021 |
|
CVE-2021-40438
mod_proxy SSRF |
Apache HTTP Server | Confirmed | In CISA | 01 Dec 2021 |
|
CVE-2021-44228
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints |
Apache Log4j2 | Confirmed | In CISA | 10 Dec 2021 |
|
CVE-2020-11978
An issue was found in Apache Airflow versions 1.10.10 and below. A remote code/command injection vulnerability was discovered in one of the example... |
Apache Airflow | Confirmed | In CISA | 18 Jan 2022 |
|
CVE-2006-1547
ActionForm in Apache Software Foundation (ASF) Struts before 1.2.9 with BeanUtils 1.7 allows remote attackers to cause a denial of service via a... |
Struts | Confirmed | In CISA | 21 Jan 2022 |
|
CVE-2017-9791
The Struts 1 plugin in Apache Struts 2.1.x and 2.3.x might allow remote code execution via a malicious field value passed in a raw message to the... |
Apache Struts | Confirmed | In CISA | 10 Feb 2022 |
|
CVE-2017-12615
When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g. via setting the readonly initialisation parameter of the Default... |
Apache Tomcat | Confirmed | In CISA | 25 Mar 2022 |
|
CVE-2017-12617
When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTTP PUTs enabled (e.g. via... |
Apache Tomcat | Confirmed | In CISA | 25 Mar 2022 |
|
CVE-2022-24112
apisix/batch-requests plugin allows overwriting the X-REAL-IP header |
Apache APISIX | Confirmed | In CISA | 25 Aug 2022 |
|
CVE-2022-24706
Remote Code Execution Vulnerability in Packaging |
Apache CouchDB | Confirmed | In CISA | 25 Aug 2022 |
|
CVE-2022-33891
Apache Spark shell command injection vulnerability via Spark UI |
Apache Spark | Confirmed | In CISA | 07 Mar 2023 |
|
CVE-2021-45046
Apache Log4j2 Thread Context Message Pattern and Context Lookup Pattern vulnerable to a denial of service attack |
Apache Log4j | Confirmed | In CISA | 01 May 2023 |
|
CVE-2016-8735
Remote code execution is possible with Apache Tomcat before 6.0.48, 7.x before 7.0.73, 8.x before 8.0.39, 8.5.x before 8.5.7, and 9.x before... |
Apache Tomcat | Confirmed | In CISA | 12 May 2023 |
|
CVE-2023-33246
Apache RocketMQ: Possible remote code execution vulnerability when using the update configuration function |
Apache RocketMQ | Confirmed | In CISA | 06 Sep 2023 |
|
CVE-2023-46604
Apache ActiveMQ, Apache ActiveMQ Legacy OpenWire Module: Unbounded deserialization causes ActiveMQ to be vulnerable to a remote code execution (RCE) attack |
Apache ActiveMQ, Apache ActiveMQ Legacy OpenWire Module | Confirmed | In CISA | 02 Nov 2023 |
|
CVE-2023-27524
Apache Superset: Session validation vulnerability when using provided default SECRET_KEY |
Apache Superset | Confirmed | In CISA | 08 Jan 2024 |
|
CVE-2020-17519
Apache Flink directory traversal attack: reading remote files through the REST API |
Apache Flink | Confirmed | In CISA | 23 May 2024 |
|
CVE-2024-32113
Apache OFBiz: Path traversal leading to RCE |
Apache OFBiz | Confirmed | In CISA | 07 Aug 2024 |
|
CVE-2024-38856
Apache OFBiz: Unauthenticated endpoint could allow execution of screen rendering code |
Apache OFBiz | Confirmed | In CISA | 27 Aug 2024 |
|
CVE-2024-27348
Apache HugeGraph-Server: Command execution in gremlin |
Apache HugeGraph-Server | Confirmed | In CISA | 18 Sep 2024 |
|
CVE-2024-45195
Apache OFBiz: Confused controller-view authorization logic (forced browsing) |
Apache OFBiz | Confirmed | In CISA | 04 Feb 2025 |
|
CVE-2025-24813
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT |
Apache Tomcat | Confirmed | In CISA | 01 Apr 2025 |
|
CVE-2024-53677
Apache Struts: Mixing setters for uploaded files and normal fields can allow bypass file upload checks |
Apache Struts | High | Not in CISA | 11 Dec 2024 |
|
CVE-2022-24288
Apache Airflow: RCE in example DAGs |
Apache Airflow | High | Not in CISA | 25 Feb 2022 |
|
CVE-2018-8006
An instance of a cross-site scripting vulnerability was identified to be present in the web based administration console on the queue.jsp page of... |
Apache ActiveMQ | High | Not in CISA | 10 Oct 2018 |
Common Vulnerability Classes (CWE)
- CWE-502 — Deserialization of Untrusted Data 8
- CWE-22 — Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') 5
- CWE-94 — Improper Control of Generation of Code ('Code Injection') 5
- CWE-918 — Server-Side Request Forgery (SSRF) 4
- CWE-20 — Improper Input Validation 4
- CWE-78 — Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') 4
- CWE-434 — Unrestricted Upload of File with Dangerous Type 3
- CWE-917 — Improper Neutralization of Special Elements used in an Expression Language Statement ('Expression Language Injection') 3
Browse all known exploited vulnerabilities · What is a known exploited vulnerability? · Methodology