Apache vendor intelligence

Apache Known Exploited Vulnerabilities

Track evidence-backed exploitation affecting Apache products, including the gap beyond CISA KEV, confidence assessments, sensor observations, and practical response context.

Browse KEVs Full KEV feed
Total KEVs
66
Known exploited vulnerabilities affecting Apache products
In CISA KEV
40
Records also listed in the official catalog
Beyond CISA KEV
26
Additional exploited vulnerabilities absent from CISA KEV
Sensor Observed
9
Apache KEVs with sensor-observed exploitation activity

The catalog gap matters for Apache exposure

26 of the 66 exploited Apache vulnerabilities tracked here are not in CISA KEV. Teams relying on the official catalog alone would miss 39% of this vendor portfolio.

61%
Covered by CISA
39%
Beyond CISA
33
Product families

Attested Apache vulnerabilities

66 known exploited vulnerabilities in this exploited-vulnerability portfolio. Search, then narrow it to official CISA coverage or the additional records Previdian tracks beyond the catalog.

How exploitation is verified
CVE / description Product Confidence CISA KEV Added
CVE-2022-33891

Apache Spark shell command injection vulnerability via Spark UI

Apache Spark Confirmed In CISA 07 Mar 2023
CVE-2021-45046

Apache Log4j2 Thread Context Message Pattern and Context Lookup Pattern vulnerable to a denial of service attack

Apache Log4j Confirmed In CISA 01 May 2023
CVE-2016-8735

Remote code execution is possible with Apache Tomcat before 6.0.48, 7.x before 7.0.73, 8.x before 8.0.39, 8.5.x before 8.5.7, and 9.x before...

Apache Tomcat Confirmed In CISA 12 May 2023
CVE-2023-33246

Apache RocketMQ: Possible remote code execution vulnerability when using the update configuration function

Apache RocketMQ Confirmed In CISA 06 Sep 2023
CVE-2023-46604

Apache ActiveMQ, Apache ActiveMQ Legacy OpenWire Module: Unbounded deserialization causes ActiveMQ to be vulnerable to a remote code execution (RCE) attack

Apache ActiveMQ, Apache ActiveMQ Legacy OpenWire Module Confirmed In CISA 02 Nov 2023
CVE-2023-27524

Apache Superset: Session validation vulnerability when using provided default SECRET_KEY

Apache Superset Confirmed In CISA 08 Jan 2024
CVE-2020-17519

Apache Flink directory traversal attack: reading remote files through the REST API

Apache Flink Confirmed In CISA 23 May 2024
CVE-2024-32113

Apache OFBiz: Path traversal leading to RCE

Apache OFBiz Confirmed In CISA 07 Aug 2024
CVE-2024-38856

Apache OFBiz: Unauthenticated endpoint could allow execution of screen rendering code

Apache OFBiz Confirmed In CISA 27 Aug 2024
CVE-2024-27348

Apache HugeGraph-Server: Command execution in gremlin

Apache HugeGraph-Server Confirmed In CISA 18 Sep 2024
CVE-2024-45195

Apache OFBiz: Confused controller-view authorization logic (forced browsing)

Apache OFBiz Confirmed In CISA 04 Feb 2025
CVE-2025-24813

Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT

Apache Tomcat Confirmed In CISA 01 Apr 2025
CVE-2024-53677

Apache Struts: Mixing setters for uploaded files and normal fields can allow bypass file upload checks

Apache Struts High Beyond CISA 11 Dec 2024
CVE-2022-24288

Apache Airflow: RCE in example DAGs

Apache Airflow High Beyond CISA 25 Feb 2022
CVE-2020-1943

Data sent with contentId to /control/stream is not sanitized, allowing XSS attacks in Apache OFBiz 16.11.01 to 16.11.07.

Apache OFBiz High Beyond CISA 01 Apr 2020
CVE-2018-8006

An instance of a cross-site scripting vulnerability was identified to be present in the web based administration console on the queue.jsp page of...

Apache ActiveMQ High Beyond CISA 10 Oct 2018

Showing 16 of 16 on this page (66 Apache known exploited vulnerabilities).

Recurring weakness patterns

Deserialization, control, and neutralization account for twenty mapped occurrences across this Apache KEV portfolio.

Browse all KEVs →