Apache Known Exploited Vulnerabilities

Evidence-backed KEV intelligence for Apache products — CISA KEV status, confidence, sensor telemetry, and virtual-patch availability.

Total KEVs

65

In CISA KEV

39

Beyond CISA KEV

26

Sensor Observed

6

Virtual Patch Available

2

Apache KEVs Added by Year

Loading...

65 Apache KEVs added all time (primary attestation date).

Attested CVEs

CVE Confidence CISA KEV Added
CVE-2017-5638

The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception handling and error-message...

Confirmed In CISA 03 Nov 2021
CVE-2020-17530

Forced OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote code execution. Affected software : Apache Struts...

Confirmed In CISA 03 Nov 2021
CVE-2019-17558

Apache Solr 5.0.0 to Apache Solr 8.3.1 are vulnerable to a Remote Code Execution through the VelocityResponseWriter. A Velocity template can be...

Confirmed In CISA 03 Nov 2021
CVE-2016-4437

Apache Shiro before 1.2.5, when a cipher key has not been configured for the "remember me" feature, allows remote attackers to execute arbitrary...

Confirmed In CISA 03 Nov 2021
CVE-2019-0211

In Apache HTTP Server 2.4 releases 2.4.17 to 2.4.38, with MPM event, worker or prefork, code executing in less-privileged child processes or...

Confirmed In CISA 03 Nov 2021
CVE-2021-41773

Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49

Confirmed In CISA 03 Nov 2021
CVE-2021-42013

Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)

Confirmed In CISA 03 Nov 2021
CVE-2017-9805

The REST Plugin in Apache Struts 2.1.1 through 2.3.x before 2.3.34 and 2.5.x before 2.5.13 uses an XStreamHandler with an instance of XStream for...

Confirmed In CISA 03 Nov 2021
CVE-2021-40438

mod_proxy SSRF

Confirmed In CISA 01 Dec 2021
CVE-2021-44228

Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints

Confirmed In CISA 10 Dec 2021
CVE-2019-0193

In Apache Solr, the DataImportHandler, an optional but popular module to pull in data from databases and other sources, has a feature in which the...

Confirmed In CISA 10 Dec 2021
CVE-2020-13927

The previous default setting for Airflow's Experimental API was to allow all API requests without authentication, but this poses security risks to...

Confirmed In CISA 18 Jan 2022
CVE-2020-11978

An issue was found in Apache Airflow versions 1.10.10 and below. A remote code/command injection vulnerability was discovered in one of the example...

Confirmed In CISA 18 Jan 2022
CVE-2012-0391

The ExceptionDelegator component in Apache Struts before 2.2.3.1 interprets parameter values as OGNL expressions during certain exception handling...

Confirmed In CISA 21 Jan 2022
CVE-2006-1547

ActionForm in Apache Software Foundation (ASF) Struts before 1.2.9 with BeanUtils 1.7 allows remote attackers to cause a denial of service via a...

Confirmed In CISA 21 Jan 2022
CVE-2016-3088

The Fileserver web application in Apache ActiveMQ 5.x before 5.14.0 allows remote attackers to upload and execute arbitrary files via an HTTP PUT...

Confirmed In CISA 10 Feb 2022
CVE-2017-9791

The Struts 1 plugin in Apache Struts 2.1.x and 2.3.x might allow remote code execution via a malicious field value passed in a raw message to the...

Confirmed In CISA 10 Feb 2022
CVE-2020-1938

When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomcat treats AJP connections...

Confirmed In CISA 03 Mar 2022
CVE-2013-2251

Apache Struts 2.0.0 through 2.3.15 allows remote attackers to execute arbitrary OGNL expressions via a parameter with a crafted (1) action:, (2)...

Confirmed In CISA 25 Mar 2022
CVE-2017-12615

When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g. via setting the readonly initialisation parameter of the Default...

Confirmed In CISA 25 Mar 2022
CVE-2017-12617

When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTTP PUTs enabled (e.g. via...

Confirmed In CISA 25 Mar 2022
CVE-2020-1956

Apache Kylin 2.3.0, and releases up to 2.6.5 and 3.0.1 has some restful apis which will concatenate os command with the user input string, a user...

Confirmed In CISA 25 Mar 2022
CVE-2022-24112

apisix/batch-requests plugin allows overwriting the X-REAL-IP header

Confirmed In CISA 25 Aug 2022
CVE-2022-24706

Remote Code Execution Vulnerability in Packaging

Confirmed In CISA 25 Aug 2022
CVE-2022-33891

Apache Spark shell command injection vulnerability via Spark UI

Confirmed In CISA 07 Mar 2023

Common Vulnerability Classes (CWE)

  • CWE-502 — Deserialization of Untrusted Data 8
  • CWE-94 — Improper Control of Generation of Code ('Code Injection') 7
  • CWE-78 — Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') 5
  • CWE-22 — Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') 5
  • CWE-20 — Improper Input Validation 4
  • CWE-434 — Unrestricted Upload of File with Dangerous Type 4
  • CWE-918 — Server-Side Request Forgery (SSRF) 4
  • CWE-917 — Improper Neutralization of Special Elements used in an Expression Language Statement ('Expression Language Injection') 3

Browse all known exploited vulnerabilities · What is a known exploited vulnerability? · Methodology