Apache Known Exploited Vulnerabilities
Evidence-backed KEV intelligence for Apache products — CISA KEV status, confidence, sensor telemetry, and virtual-patch availability.
Total KEVs
65
In CISA KEV
39
Beyond CISA KEV
26
Sensor Observed
6
Virtual Patch Available
2
Apache KEVs Added by Year
65 Apache KEVs added all time (primary attestation date).
Attested CVEs
| CVE | Product | Confidence | CISA KEV | Added |
|---|---|---|---|---|
|
CVE-2017-5638
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception handling and error-message... |
Apache Struts | Confirmed | In CISA | 03 Nov 2021 |
|
CVE-2020-17530
Forced OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote code execution. Affected software : Apache Struts... |
Apache Struts | Confirmed | In CISA | 03 Nov 2021 |
|
CVE-2019-17558
Apache Solr 5.0.0 to Apache Solr 8.3.1 are vulnerable to a Remote Code Execution through the VelocityResponseWriter. A Velocity template can be... |
Apache Solr | Confirmed | In CISA | 03 Nov 2021 |
|
CVE-2016-4437
Apache Shiro before 1.2.5, when a cipher key has not been configured for the "remember me" feature, allows remote attackers to execute arbitrary... |
Shiro | Confirmed | In CISA | 03 Nov 2021 |
|
CVE-2019-0211
In Apache HTTP Server 2.4 releases 2.4.17 to 2.4.38, with MPM event, worker or prefork, code executing in less-privileged child processes or... |
Apache HTTP Server | Confirmed | In CISA | 03 Nov 2021 |
|
CVE-2021-41773
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49 |
Apache HTTP Server | Confirmed | In CISA | 03 Nov 2021 |
|
CVE-2021-42013
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773) |
Apache HTTP Server | Confirmed | In CISA | 03 Nov 2021 |
|
CVE-2017-9805
The REST Plugin in Apache Struts 2.1.1 through 2.3.x before 2.3.34 and 2.5.x before 2.5.13 uses an XStreamHandler with an instance of XStream for... |
Apache Struts | Confirmed | In CISA | 03 Nov 2021 |
|
CVE-2021-40438
mod_proxy SSRF |
Apache HTTP Server | Confirmed | In CISA | 01 Dec 2021 |
|
CVE-2021-44228
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints |
Apache Log4j2 | Confirmed | In CISA | 10 Dec 2021 |
|
CVE-2019-0193
In Apache Solr, the DataImportHandler, an optional but popular module to pull in data from databases and other sources, has a feature in which the... |
Apache Solr | Confirmed | In CISA | 10 Dec 2021 |
|
CVE-2020-13927
The previous default setting for Airflow's Experimental API was to allow all API requests without authentication, but this poses security risks to... |
Apache Airflow | Confirmed | In CISA | 18 Jan 2022 |
|
CVE-2020-11978
An issue was found in Apache Airflow versions 1.10.10 and below. A remote code/command injection vulnerability was discovered in one of the example... |
Apache Airflow | Confirmed | In CISA | 18 Jan 2022 |
|
CVE-2012-0391
The ExceptionDelegator component in Apache Struts before 2.2.3.1 interprets parameter values as OGNL expressions during certain exception handling... |
Struts | Confirmed | In CISA | 21 Jan 2022 |
|
CVE-2006-1547
ActionForm in Apache Software Foundation (ASF) Struts before 1.2.9 with BeanUtils 1.7 allows remote attackers to cause a denial of service via a... |
Struts | Confirmed | In CISA | 21 Jan 2022 |
|
CVE-2016-3088
The Fileserver web application in Apache ActiveMQ 5.x before 5.14.0 allows remote attackers to upload and execute arbitrary files via an HTTP PUT... |
ActiveMQ | Confirmed | In CISA | 10 Feb 2022 |
|
CVE-2017-9791
The Struts 1 plugin in Apache Struts 2.1.x and 2.3.x might allow remote code execution via a malicious field value passed in a raw message to the... |
Apache Struts | Confirmed | In CISA | 10 Feb 2022 |
|
CVE-2020-1938
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomcat treats AJP connections... |
Apache Tomcat | Confirmed | In CISA | 03 Mar 2022 |
|
CVE-2013-2251
Apache Struts 2.0.0 through 2.3.15 allows remote attackers to execute arbitrary OGNL expressions via a parameter with a crafted (1) action:, (2)... |
Struts | Confirmed | In CISA | 25 Mar 2022 |
|
CVE-2017-12615
When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g. via setting the readonly initialisation parameter of the Default... |
Apache Tomcat | Confirmed | In CISA | 25 Mar 2022 |
|
CVE-2017-12617
When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTTP PUTs enabled (e.g. via... |
Apache Tomcat | Confirmed | In CISA | 25 Mar 2022 |
|
CVE-2020-1956
Apache Kylin 2.3.0, and releases up to 2.6.5 and 3.0.1 has some restful apis which will concatenate os command with the user input string, a user... |
Kylin | Confirmed | In CISA | 25 Mar 2022 |
|
CVE-2022-24112
apisix/batch-requests plugin allows overwriting the X-REAL-IP header |
Apache APISIX | Confirmed | In CISA | 25 Aug 2022 |
|
CVE-2022-24706
Remote Code Execution Vulnerability in Packaging |
Apache CouchDB | Confirmed | In CISA | 25 Aug 2022 |
|
CVE-2022-33891
Apache Spark shell command injection vulnerability via Spark UI |
Apache Spark | Confirmed | In CISA | 07 Mar 2023 |
Common Vulnerability Classes (CWE)
- CWE-502 — Deserialization of Untrusted Data 8
- CWE-94 — Improper Control of Generation of Code ('Code Injection') 7
- CWE-78 — Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') 5
- CWE-22 — Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') 5
- CWE-20 — Improper Input Validation 4
- CWE-434 — Unrestricted Upload of File with Dangerous Type 4
- CWE-918 — Server-Side Request Forgery (SSRF) 4
- CWE-917 — Improper Neutralization of Special Elements used in an Expression Language Statement ('Expression Language Injection') 3
Browse all known exploited vulnerabilities · What is a known exploited vulnerability? · Methodology