Apache Known Exploited Vulnerabilities
Evidence-backed KEV intelligence for Apache products — CISA KEV status, confidence, sensor telemetry, and virtual-patch availability.
Total KEVs
65
In CISA KEV
39
Beyond CISA KEV
26
Sensor Observed
6
Virtual Patch Available
2
Apache KEVs Added by Year
65 Apache KEVs added all time (primary attestation date).
Attested CVEs
| CVE | Product | Confidence | CISA KEV | Added |
|---|---|---|---|---|
|
CVE-2021-45046
Apache Log4j2 Thread Context Message Pattern and Context Lookup Pattern vulnerable to a denial of service attack |
Apache Log4j | Confirmed | In CISA | 01 May 2023 |
|
CVE-2016-8735
Remote code execution is possible with Apache Tomcat before 6.0.48, 7.x before 7.0.73, 8.x before 8.0.39, 8.5.x before 8.5.7, and 9.x before... |
Apache Tomcat | Confirmed | In CISA | 12 May 2023 |
|
CVE-2023-33246
Apache RocketMQ: Possible remote code execution vulnerability when using the update configuration function |
Apache RocketMQ | Confirmed | In CISA | 06 Sep 2023 |
|
CVE-2023-46604
Apache ActiveMQ, Apache ActiveMQ Legacy OpenWire Module: Unbounded deserialization causes ActiveMQ to be vulnerable to a remote code execution (RCE) attack |
Apache ActiveMQ, Apache ActiveMQ Legacy OpenWire Module | Confirmed | In CISA | 02 Nov 2023 |
|
CVE-2023-27524
Apache Superset: Session validation vulnerability when using provided default SECRET_KEY |
Apache Superset | Confirmed | In CISA | 08 Jan 2024 |
|
CVE-2020-17519
Apache Flink directory traversal attack: reading remote files through the REST API |
Apache Flink | Confirmed | In CISA | 23 May 2024 |
|
CVE-2024-32113
Apache OFBiz: Path traversal leading to RCE |
Apache OFBiz | Confirmed | In CISA | 07 Aug 2024 |
|
CVE-2024-38856
Apache OFBiz: Unauthenticated endpoint could allow execution of screen rendering code |
Apache OFBiz | Confirmed | In CISA | 27 Aug 2024 |
|
CVE-2024-27348
Apache HugeGraph-Server: Command execution in gremlin |
Apache HugeGraph-Server | Confirmed | In CISA | 18 Sep 2024 |
|
CVE-2024-45195
Apache OFBiz: Confused controller-view authorization logic (forced browsing) |
Apache OFBiz | Confirmed | In CISA | 04 Feb 2025 |
|
CVE-2025-24813
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT |
Apache Tomcat | Confirmed | In CISA | 01 Apr 2025 |
|
CVE-2024-53677
Apache Struts: Mixing setters for uploaded files and normal fields can allow bypass file upload checks |
Apache Struts | High | Not in CISA | 11 Dec 2024 |
|
CVE-2022-24288
Apache Airflow: RCE in example DAGs |
Apache Airflow | High | Not in CISA | 25 Feb 2022 |
|
CVE-2020-1943
Data sent with contentId to /control/stream is not sanitized, allowing XSS attacks in Apache OFBiz 16.11.01 to 16.11.07. |
Apache OFBiz | High | Not in CISA | 01 Apr 2020 |
|
CVE-2018-8006
An instance of a cross-site scripting vulnerability was identified to be present in the web based administration console on the queue.jsp page of... |
Apache ActiveMQ | High | Not in CISA | 10 Oct 2018 |
Common Vulnerability Classes (CWE)
- CWE-502 — Deserialization of Untrusted Data 8
- CWE-94 — Improper Control of Generation of Code ('Code Injection') 7
- CWE-78 — Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') 5
- CWE-22 — Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') 5
- CWE-20 — Improper Input Validation 4
- CWE-434 — Unrestricted Upload of File with Dangerous Type 4
- CWE-918 — Server-Side Request Forgery (SSRF) 4
- CWE-917 — Improper Neutralization of Special Elements used in an Expression Language Statement ('Expression Language Injection') 3
Browse all known exploited vulnerabilities · What is a known exploited vulnerability? · Methodology