Apache Known Exploited Vulnerabilities

Evidence-backed KEV intelligence for Apache products — CISA KEV status, confidence, sensor telemetry, and virtual-patch availability.

Total KEVs

65

In CISA KEV

39

Beyond CISA KEV

26

Sensor Observed

6

Virtual Patch Available

2

Apache KEVs Added by Year

Loading...

65 Apache KEVs added all time (primary attestation date).

Attested CVEs

CVE Confidence CISA KEV Added
CVE-2021-45046

Apache Log4j2 Thread Context Message Pattern and Context Lookup Pattern vulnerable to a denial of service attack

Confirmed In CISA 01 May 2023
CVE-2016-8735

Remote code execution is possible with Apache Tomcat before 6.0.48, 7.x before 7.0.73, 8.x before 8.0.39, 8.5.x before 8.5.7, and 9.x before...

Confirmed In CISA 12 May 2023
CVE-2023-33246

Apache RocketMQ: Possible remote code execution vulnerability when using the update configuration function

Confirmed In CISA 06 Sep 2023
CVE-2023-46604

Apache ActiveMQ, Apache ActiveMQ Legacy OpenWire Module: Unbounded deserialization causes ActiveMQ to be vulnerable to a remote code execution (RCE) attack

Confirmed In CISA 02 Nov 2023
CVE-2023-27524

Apache Superset: Session validation vulnerability when using provided default SECRET_KEY

Confirmed In CISA 08 Jan 2024
CVE-2020-17519

Apache Flink directory traversal attack: reading remote files through the REST API

Confirmed In CISA 23 May 2024
CVE-2024-32113

Apache OFBiz: Path traversal leading to RCE

Confirmed In CISA 07 Aug 2024
CVE-2024-38856

Apache OFBiz: Unauthenticated endpoint could allow execution of screen rendering code

Confirmed In CISA 27 Aug 2024
CVE-2024-27348

Apache HugeGraph-Server: Command execution in gremlin

Confirmed In CISA 18 Sep 2024
CVE-2024-45195

Apache OFBiz: Confused controller-view authorization logic (forced browsing)

Confirmed In CISA 04 Feb 2025
CVE-2025-24813

Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT

Confirmed In CISA 01 Apr 2025
CVE-2024-53677

Apache Struts: Mixing setters for uploaded files and normal fields can allow bypass file upload checks

High Not in CISA 11 Dec 2024
CVE-2022-24288

Apache Airflow: RCE in example DAGs

High Not in CISA 25 Feb 2022
CVE-2020-1943

Data sent with contentId to /control/stream is not sanitized, allowing XSS attacks in Apache OFBiz 16.11.01 to 16.11.07.

High Not in CISA 01 Apr 2020
CVE-2018-8006

An instance of a cross-site scripting vulnerability was identified to be present in the web based administration console on the queue.jsp page of...

High Not in CISA 10 Oct 2018

Common Vulnerability Classes (CWE)

  • CWE-502 — Deserialization of Untrusted Data 8
  • CWE-94 — Improper Control of Generation of Code ('Code Injection') 7
  • CWE-78 — Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') 5
  • CWE-22 — Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') 5
  • CWE-20 — Improper Input Validation 4
  • CWE-434 — Unrestricted Upload of File with Dangerous Type 4
  • CWE-918 — Server-Side Request Forgery (SSRF) 4
  • CWE-917 — Improper Neutralization of Special Elements used in an Expression Language Statement ('Expression Language Injection') 3

Browse all known exploited vulnerabilities · What is a known exploited vulnerability? · Methodology