Apache
Apache known exploited vulnerabilities
Every Apache vulnerability in CISA's Known Exploited Vulnerabilities catalog, newest first. 8 of them are known to be used by ransomware.
40 CVEs
- CVE-2026-34486Apache Tomcat Missing Encryption of Sensitive Data Vulnerability · added August 4, 2026
- CVE-2026-34197Apache ActiveMQ Improper Input Validation Vulnerability · added April 16, 2026
- CVE-2024-38475Apache HTTP Server Improper Escaping of Output Vulnerability · added May 1, 2025
- CVE-2025-24813Apache Tomcat Path Equivalence Vulnerability · added April 1, 2025
- CVE-2024-45195Apache OFBiz Forced Browsing Vulnerability · added February 4, 2025
- CVE-2024-27348Apache HugeGraph-Server Improper Access Control Vulnerability · added September 18, 2024
- CVE-2024-38856Apache OFBiz Incorrect Authorization Vulnerability · added August 27, 2024
- CVE-2024-32113Apache OFBiz Path Traversal Vulnerability · added August 7, 2024
- CVE-2020-17519Apache Flink Improper Access Control Vulnerability · added May 23, 2024
- CVE-2023-27524Apache Superset Insecure Default Initialization of Resource Vulnerability · added January 8, 2024
- CVE-2023-46604 ransomwareApache ActiveMQ Deserialization of Untrusted Data Vulnerability · added November 2, 2023
- CVE-2023-33246Apache RocketMQ Command Execution Vulnerability · added September 6, 2023
- CVE-2016-8735Apache Tomcat Remote Code Execution Vulnerability · added May 12, 2023
- CVE-2021-45046 ransomwareApache Log4j2 Deserialization of Untrusted Data Vulnerability · added May 1, 2023
- CVE-2022-33891Apache Spark Command Injection Vulnerability · added March 7, 2023
- CVE-2022-24706Apache CouchDB Insecure Default Initialization of Resource Vulnerability · added August 25, 2022
- CVE-2022-24112Apache APISIX Authentication Bypass Vulnerability · added August 25, 2022
- CVE-2020-1956Apache Kylin OS Command Injection Vulnerability · added March 25, 2022
- CVE-2017-12617Apache Tomcat Remote Code Execution Vulnerability · added March 25, 2022
- CVE-2017-12615 ransomwareApache Tomcat on Windows Remote Code Execution Vulnerability · added March 25, 2022
- CVE-2013-2251Apache Struts Improper Input Validation Vulnerability · added March 25, 2022
- CVE-2020-1938Apache Tomcat Improper Privilege Management Vulnerability · added March 3, 2022
- CVE-2017-9791Apache Struts 1 Improper Input Validation Vulnerability · added February 10, 2022
- CVE-2016-3088Apache ActiveMQ Improper Input Validation Vulnerability · added February 10, 2022
- CVE-2012-0391Apache Struts 2 Improper Input Validation Vulnerability · added January 21, 2022
- CVE-2006-1547Apache Struts 1 ActionForm Denial-of-Service Vulnerability · added January 21, 2022
- CVE-2020-13927Apache Airflow's Experimental API Authentication Bypass · added January 18, 2022
- CVE-2020-11978Apache Airflow Command Injection · added January 18, 2022
- CVE-2021-44228 ransomwareApache Log4j2 Remote Code Execution Vulnerability · added December 10, 2021
- CVE-2019-0193Apache Solr DataImportHandler Code Injection Vulnerability · added December 10, 2021
- CVE-2021-40438 ransomwareApache HTTP Server-Side Request Forgery (SSRF) · added December 1, 2021
- CVE-2021-42013 ransomwareApache HTTP Server Path Traversal Vulnerability · added November 3, 2021
- CVE-2021-41773 ransomwareApache HTTP Server Path Traversal Vulnerability · added November 3, 2021
- CVE-2020-17530Apache Struts Remote Code Execution Vulnerability · added November 3, 2021
- CVE-2019-17558Apache Solr VelocityResponseWriter Plug-In Remote Code Execution Vulnerability · added November 3, 2021
- CVE-2019-0211Apache HTTP Server Privilege Escalation Vulnerability · added November 3, 2021
- CVE-2018-11776Apache Struts Remote Code Execution Vulnerability · added November 3, 2021
- CVE-2017-9805Apache Struts Deserialization of Untrusted Data Vulnerability · added November 3, 2021
- CVE-2017-5638 ransomwareApache Struts Remote Code Execution Vulnerability · added November 3, 2021
- CVE-2016-4437Apache Shiro Code Execution Vulnerability · added November 3, 2021
Source: CISA Known Exploited Vulnerabilities Catalog (public domain).