Apache vendor intelligence
Apache Known Exploited Vulnerabilities
Track evidence-backed exploitation affecting Apache products, including the gap beyond CISA KEV, confidence assessments, sensor observations, and practical response context.
- Total KEVs
- 66
- Known exploited vulnerabilities affecting Apache products
- In CISA KEV
- 40
- Records also listed in the official catalog
- Beyond CISA KEV
- 26
- Additional exploited vulnerabilities absent from CISA KEV
- Sensor Observed
- 9
- Apache KEVs with sensor-observed exploitation activity
The catalog gap matters for Apache exposure
26 of the 66 exploited Apache vulnerabilities tracked here are not in CISA KEV. Teams relying on the official catalog alone would miss 39% of this vendor portfolio.
- 61%
- Covered by CISA
- 39%
- Beyond CISA
- 33
- Product families
Attested Apache vulnerabilities
66 known exploited vulnerabilities in this exploited-vulnerability portfolio. Search, then narrow it to official CISA coverage or the additional records Previdian tracks beyond the catalog.
How exploitation is verified| CVE / description | Product | Confidence | CISA KEV | Added |
|---|---|---|---|---|
|
CVE-2022-33891
Apache Spark shell command injection vulnerability via Spark UI |
Apache Spark | Confirmed | In CISA | 07 Mar 2023 |
|
CVE-2021-45046
Apache Log4j2 Thread Context Message Pattern and Context Lookup Pattern vulnerable to a denial of service attack |
Apache Log4j | Confirmed | In CISA | 01 May 2023 |
|
CVE-2016-8735
Remote code execution is possible with Apache Tomcat before 6.0.48, 7.x before 7.0.73, 8.x before 8.0.39, 8.5.x before 8.5.7, and 9.x before... |
Apache Tomcat | Confirmed | In CISA | 12 May 2023 |
|
CVE-2023-33246
Apache RocketMQ: Possible remote code execution vulnerability when using the update configuration function |
Apache RocketMQ | Confirmed | In CISA | 06 Sep 2023 |
|
CVE-2023-46604
Apache ActiveMQ, Apache ActiveMQ Legacy OpenWire Module: Unbounded deserialization causes ActiveMQ to be vulnerable to a remote code execution (RCE) attack |
Apache ActiveMQ, Apache ActiveMQ Legacy OpenWire Module | Confirmed | In CISA | 02 Nov 2023 |
|
CVE-2023-27524
Apache Superset: Session validation vulnerability when using provided default SECRET_KEY |
Apache Superset | Confirmed | In CISA | 08 Jan 2024 |
|
CVE-2020-17519
Apache Flink directory traversal attack: reading remote files through the REST API |
Apache Flink | Confirmed | In CISA | 23 May 2024 |
|
CVE-2024-32113
Apache OFBiz: Path traversal leading to RCE |
Apache OFBiz | Confirmed | In CISA | 07 Aug 2024 |
|
CVE-2024-38856
Apache OFBiz: Unauthenticated endpoint could allow execution of screen rendering code |
Apache OFBiz | Confirmed | In CISA | 27 Aug 2024 |
|
CVE-2024-27348
Apache HugeGraph-Server: Command execution in gremlin |
Apache HugeGraph-Server | Confirmed | In CISA | 18 Sep 2024 |
|
CVE-2024-45195
Apache OFBiz: Confused controller-view authorization logic (forced browsing) |
Apache OFBiz | Confirmed | In CISA | 04 Feb 2025 |
|
CVE-2025-24813
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT |
Apache Tomcat | Confirmed | In CISA | 01 Apr 2025 |
|
CVE-2024-53677
Apache Struts: Mixing setters for uploaded files and normal fields can allow bypass file upload checks |
Apache Struts | High | Beyond CISA | 11 Dec 2024 |
|
CVE-2022-24288
Apache Airflow: RCE in example DAGs |
Apache Airflow | High | Beyond CISA | 25 Feb 2022 |
|
CVE-2020-1943
Data sent with contentId to /control/stream is not sanitized, allowing XSS attacks in Apache OFBiz 16.11.01 to 16.11.07. |
Apache OFBiz | High | Beyond CISA | 01 Apr 2020 |
|
CVE-2018-8006
An instance of a cross-site scripting vulnerability was identified to be present in the web based administration console on the queue.jsp page of... |
Apache ActiveMQ | High | Beyond CISA | 10 Oct 2018 |
No Apache vulnerabilities match this search or filter.
Showing 16 of 16 on this page (66 Apache known exploited vulnerabilities).
Recurring weakness patterns
Deserialization, control, and neutralization account for twenty mapped occurrences across this Apache KEV portfolio.
CWE-502
Deserialization of Untrusted Data
CWE-94
Improper Control of Generation of Code ('Code Injection')
CWE-78
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CWE-917
Improper Neutralization of Special Elements used in an Expression Language Statement ('Expression Language Injection')
CWE-20
Improper Input Validation
CWE-434
Unrestricted Upload of File with Dangerous Type
CWE-918
Server-Side Request Forgery (SSRF)