Apache Software Foundation Known Exploited Vulnerabilities

Evidence-backed KEV intelligence for Apache Software Foundation products — CISA KEV status, confidence, sensor telemetry, and virtual-patch availability.

Total KEVs

50

In CISA KEV

29

Beyond CISA KEV

21

Sensor Observed

4

Virtual Patch Available

2

Apache Software Foundation KEVs Added by Year

Loading...

50 Apache Software Foundation KEVs added all time (primary attestation date).

Attested CVEs

CVE Confidence CISA KEV Added
CVE-2017-9805

The REST Plugin in Apache Struts 2.1.1 through 2.3.x before 2.3.34 and 2.5.x before 2.5.13 uses an XStreamHandler with an instance of XStream for...

Confirmed In CISA 03 Nov 2021
CVE-2021-40438

mod_proxy SSRF

Confirmed In CISA 01 Dec 2021
CVE-2021-44228

Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints

Confirmed In CISA 10 Dec 2021
CVE-2020-11978

An issue was found in Apache Airflow versions 1.10.10 and below. A remote code/command injection vulnerability was discovered in one of the example...

Confirmed In CISA 18 Jan 2022
CVE-2006-1547

ActionForm in Apache Software Foundation (ASF) Struts before 1.2.9 with BeanUtils 1.7 allows remote attackers to cause a denial of service via a...

Confirmed In CISA 21 Jan 2022
CVE-2017-9791

The Struts 1 plugin in Apache Struts 2.1.x and 2.3.x might allow remote code execution via a malicious field value passed in a raw message to the...

Confirmed In CISA 10 Feb 2022
CVE-2017-12615

When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g. via setting the readonly initialisation parameter of the Default...

Confirmed In CISA 25 Mar 2022
CVE-2017-12617

When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTTP PUTs enabled (e.g. via...

Confirmed In CISA 25 Mar 2022
CVE-2022-24112

apisix/batch-requests plugin allows overwriting the X-REAL-IP header

Confirmed In CISA 25 Aug 2022
CVE-2022-24706

Remote Code Execution Vulnerability in Packaging

Confirmed In CISA 25 Aug 2022
CVE-2022-33891

Apache Spark shell command injection vulnerability via Spark UI

Confirmed In CISA 07 Mar 2023
CVE-2021-45046

Apache Log4j2 Thread Context Message Pattern and Context Lookup Pattern vulnerable to a denial of service attack

Confirmed In CISA 01 May 2023
CVE-2016-8735

Remote code execution is possible with Apache Tomcat before 6.0.48, 7.x before 7.0.73, 8.x before 8.0.39, 8.5.x before 8.5.7, and 9.x before...

Confirmed In CISA 12 May 2023
CVE-2023-33246

Apache RocketMQ: Possible remote code execution vulnerability when using the update configuration function

Confirmed In CISA 06 Sep 2023
CVE-2023-46604

Apache ActiveMQ, Apache ActiveMQ Legacy OpenWire Module: Unbounded deserialization causes ActiveMQ to be vulnerable to a remote code execution (RCE) attack

Confirmed In CISA 02 Nov 2023
CVE-2023-27524

Apache Superset: Session validation vulnerability when using provided default SECRET_KEY

Confirmed In CISA 08 Jan 2024
CVE-2020-17519

Apache Flink directory traversal attack: reading remote files through the REST API

Confirmed In CISA 23 May 2024
CVE-2024-32113

Apache OFBiz: Path traversal leading to RCE

Confirmed In CISA 07 Aug 2024
CVE-2024-38856

Apache OFBiz: Unauthenticated endpoint could allow execution of screen rendering code

Confirmed In CISA 27 Aug 2024
CVE-2024-27348

Apache HugeGraph-Server: Command execution in gremlin

Confirmed In CISA 18 Sep 2024
CVE-2024-45195

Apache OFBiz: Confused controller-view authorization logic (forced browsing)

Confirmed In CISA 04 Feb 2025
CVE-2025-24813

Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT

Confirmed In CISA 01 Apr 2025
CVE-2024-53677

Apache Struts: Mixing setters for uploaded files and normal fields can allow bypass file upload checks

High Not in CISA 11 Dec 2024
CVE-2022-24288

Apache Airflow: RCE in example DAGs

High Not in CISA 25 Feb 2022
CVE-2018-8006

An instance of a cross-site scripting vulnerability was identified to be present in the web based administration console on the queue.jsp page of...

High Not in CISA 10 Oct 2018

Common Vulnerability Classes (CWE)

  • CWE-502 — Deserialization of Untrusted Data 8
  • CWE-22 — Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') 5
  • CWE-94 — Improper Control of Generation of Code ('Code Injection') 5
  • CWE-918 — Server-Side Request Forgery (SSRF) 4
  • CWE-20 — Improper Input Validation 4
  • CWE-78 — Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') 4
  • CWE-434 — Unrestricted Upload of File with Dangerous Type 3
  • CWE-917 — Improper Neutralization of Special Elements used in an Expression Language Statement ('Expression Language Injection') 3

Browse all known exploited vulnerabilities · What is a known exploited vulnerability? · Methodology