apache
451 known vulnerabilities affecting apache products.
Products
traffic_server 41
airflow 34
cxf 27
tomcat 26
thrift 23
cloudstack 20
http_server 15
camel 14
answer 12
ranger 11
wicket 11
inlong 10
activemq 10
fory 9
artemis 8
apache-airflow-providers-fab 8
syncope 8
activemq_broker 7
qpid_broker-j 7
qpid_proton-dotnet 6
qpid_proton-j 6
nifi 6
nimble 6
opennlp 6
Vulnerabilities by priority
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2021-40438 | Act now | 100.0% | 9.0 | ● | A crafted request uri-path can cause mod_proxy to forward the request to an orig… |
| CVE-2021-44228 | Act now | 100.0% | 10.0 | ● | Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12… |
| CVE-2017-12617 | Act now | 100.0% | 8.1 | ● | When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC… |
| CVE-2017-12615 | Act now | 99.6% | 8.1 | ● | When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.… |
| CVE-2020-1938 | Act now | 99.3% | 9.8 | ● | When using the Apache JServ Protocol (AJP), care must be taken when trusting inc… |
| CVE-2026-34486 | Act now | 98.6% | 7.5 | ● | Missing Encryption of Sensitive Data vulnerability in Apache Tomcat due to the f… |
| CVE-2026-34197 | Act now | 98.3% | 8.8 | ● | Improper Input Validation, Improper Control of Generation of Code ('Code Injecti… |
| CVE-2018-1273 | Act now | 97.0% | 9.8 | ● | Spring Data Commons, versions prior to 1.13 to 1.13.10, 2.0 to 2.0.5, and older … |
| CVE-2016-8735 | Act now | 90.3% | 9.8 | ● | Remote code execution is possible with Apache Tomcat before 6.0.48, 7.x before 7… |
| CVE-2021-45105 | High | 100.0% | 5.9 | Apache Log4j2 versions 2.0-alpha1 through 2.16.0 (excluding 2.12.3 and 2.3.1) di… | |
| CVE-2020-13935 | High | 86.6% | 7.5 | The payload length in a WebSocket frame was not correctly validated in Apache To… | |
| CVE-2021-33037 | High | 75.4% | 5.3 | Apache Tomcat 10.0.0-M1 to 10.0.6, 9.0.0.M1 to 9.0.46 and 8.5.0 to 8.5.66 did no… | |
| CVE-2020-13934 | High | 64.1% | 7.5 | An h2c direct connection to Apache Tomcat 10.0.0-M1 to 10.0.0-M6, 9.0.0.M5 to 9.… | |
| CVE-2020-9484 | High | 56.6% | 7.0 | When using Apache Tomcat versions 10.0.0-M1 to 10.0.0-M4, 9.0.0.M1 to 9.0.34, 8.… | |
| CVE-2026-49975 | Medium | 34.3% | 7.5 | Memory Allocation with Excessive Size Value vulnerability in Apache HTTP Server'… | |
| CVE-2019-10086 | Medium | 29.2% | 7.3 | In Apache Commons Beanutils 1.9.2, a special BeanIntrospector class was added wh… | |
| CVE-2021-24122 | Medium | 22.9% | 5.9 | When serving resources from a network location using the NTFS file system, Apach… | |
| CVE-2021-25122 | Medium | 18.1% | 7.5 | When responding to new h2c connection requests, Apache Tomcat versions 10.0.0-M1… | |
| CVE-2020-25649 | Medium | 17.8% | 7.5 | A flaw was found in FasterXML Jackson Databind, where it did not have entity exp… | |
| CVE-2022-23437 | Medium | 11.6% | 6.5 | There's a vulnerability within the Apache Xerces Java (XercesJ) XML parser when … | |
| CVE-2021-29425 | Medium | 10.2% | 4.8 | In Apache Commons IO before 2.7, When invoking the method FileNameUtils.normaliz… | |
| CVE-2026-27446 | Medium | 10.0% | 9.8 | Missing Authentication for Critical Function (CWE-306) vulnerability in Apache A… | |
| CVE-2021-25329 | Medium | 9.5% | 7.0 | The fix for CVE-2020-9484 was incomplete. When using Apache Tomcat 10.0.0-M1 to … | |
| CVE-2026-29146 | Medium | 8.9% | 7.5 | Padding Oracle vulnerability in Apache Tomcat's EncryptInterceptor with default … | |
| CVE-2022-25762 | Medium | 8.4% | 8.6 | If a web application sends a WebSocket message concurrently with the WebSocket c… | |
| CVE-2021-20190 | Medium | 7.5% | 8.1 | A flaw was found in jackson-databind before 2.9.10.7. FasterXML mishandles the i… | |
| CVE-2021-40690 | Medium | 7.4% | 7.5 | All versions of Apache Santuario - XML Security for Java prior to 2.2.3 and 2.1.… | |
| CVE-2026-44825 | Medium | 2.9% | 8.1 | Hardcoded credentials in the Basic Authentication setup tool (bin/solr auth enab… | |
| CVE-2026-61400 | Medium | 1.5% | 8.8 | Improper Neutralization of Special Elements used in a Command ('Command Injectio… | |
| CVE-2026-28780 | Medium | 1.4% | 9.8 | Heap-based Buffer Overflow vulnerability in mod_proxy_ajp of Apache HTTP Server.… | |
| CVE-2026-28672 | Medium | 1.3% | 9.8 | Improper Neutralization of Special Elements used in a Command ('Command Injectio… | |
| CVE-2026-40860 | Medium | 1.2% | 9.8 | JmsBinding.extractBodyFromJms() in camel-jms, and the equivalent JmsBinding clas… | |
| CVE-2026-41602 | Medium | 1.2% | 7.5 | Integer Overflow or Wraparound vulnerability in Apache Thrift TFramedTransport G… | |
| CVE-2026-34355 | Medium | 1.2% | 7.5 | A buffer overflow in mod_proxy_html in Apache HTTP Server 2.4.67 and earlier all… | |
| CVE-2026-47359 | Medium | 1.1% | 8.8 | Improper Neutralization of Special Elements used in an OS Command ('OS Command I… | |
| CVE-2025-48431 | Medium | 1.1% | 7.5 | Mismatched Memory Management Routines vulnerability in Apache Thrift c_glib lang… | |
| CVE-2026-45112 | Medium | 1.1% | 7.5 | Allocation of Resources Without Limits or Throttling vulnerability in Apache Thr… | |
| CVE-2026-66713 | Medium | 1.0% | 9.8 | Deserialization of Untrusted Data (CWE-502) in the Tribes-based clustering compo… | |
| CVE-2026-42536 | Medium | 1.0% | 7.5 | Heap-based Buffer Overflow vulnerability in Apache HTTP Server with mod_xml2enc,… | |
| CVE-2026-25747 | Medium | 1.0% | 8.8 | Deserialization of Untrusted Data vulnerability in Apache Camel LevelDB componen… | |
| CVE-2026-40858 | Medium | 0.9% | 8.8 | The camel-infinispan component's ProtoStream-based remote aggregation repository… | |
| CVE-2026-41605 | Medium | 0.9% | 7.3 | Integer Overflow or Wraparound vulnerability in Apache Thrift. This issue affec… | |
| CVE-2026-41604 | Medium | 0.9% | 8.2 | Out-of-bounds Read vulnerability in Apache Thrift. This issue affects Apache Th… | |
| CVE-2026-54399 | Medium | 0.9% | 7.5 | Uncontrolled Resource Consumption vulnerability in the HTTP/1.1 message parser i… | |
| CVE-2026-54428 | Medium | 0.9% | 7.5 | Allocation of resources without limits or throttling in the HTTP/2 HPACK decoder… | |
| CVE-2026-50633 | Medium | 0.9% | 8.1 | A JNDI Injection vulnerability has been discovered in Apache CXF's JCA integrati… | |
| CVE-2026-52680 | Medium | 0.8% | 9.8 | Apache Kyuubi REST batch multipart upload handling uses the client-supplied mult… | |
| CVE-2026-57308 | Medium | 0.8% | 9.8 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injecti… | |
| CVE-2026-68763 | Medium | 0.8% | 7.5 | Uncontrolled Resource Consumption vulnerability in Apache Tomcat via an allocati… | |
| CVE-2026-84939 | Medium | 0.8% | 9.1 | Path traversal vulnerability in Apache FreeMarker template loading mechanism, if… |
Page 1 of 10
Next →