Apache Security Vulnerabilities (CVEs)

Track 567 security vulnerabilities affecting Apache products and software. Get instant email alerts when new CVEs are discovered, automated security monitoring, and patch guidance.

202 Critical
267 High
95 Medium
3 Low
🔔 Get Alerts for Apache
CVE-2024-52316 9.8

This vulnerability in Apache Tomcat allows authentication bypass when using custom Jakarta Authentication components that throw exceptions without set...

Nov 18, 2024
CVE-2024-47208 9.8

This CVE describes a Server-Side Request Forgery (SSRF) and code injection vulnerability in Apache OFBiz. Attackers can exploit it to make the server ...

Nov 18, 2024
CVE-2024-45791 7.5

Apache HertzBeat versions before 1.6.1 contain an information disclosure vulnerability that allows unauthorized actors to access sensitive information...

Nov 18, 2024
CVE-2024-45784 7.5

Apache Airflow versions before 2.10.3 contain a vulnerability where sensitive configuration variables (secrets) can be exposed in task logs. This allo...

Nov 15, 2024
CVE-2024-50305 7.5

A vulnerability in Apache Traffic Server allows a specially crafted Host header to cause a denial-of-service crash. This affects Apache Traffic Server...

Nov 14, 2024
CVE-2024-50306 9.1

Apache Traffic Server fails to properly handle return values during startup, potentially allowing the service to retain elevated privileges it should ...

Nov 14, 2024
CVE-2024-38479 7.5

Apache Traffic Server has an improper input validation vulnerability (CWE-20) that could allow attackers to cause denial of service or potentially exe...

Nov 14, 2024
CVE-2024-50386 8.5

This vulnerability in Apache CloudStack allows attackers who can register templates to deploy malicious instances on KVM-based environments, potential...

Nov 12, 2024
CVE-2024-51504 9.1

This vulnerability allows attackers to bypass IP-based authentication in ZooKeeper Admin Server by spoofing the X-Forwarded-For HTTP header. It affect...

Nov 7, 2024
CVE-2024-38286 8.6

This vulnerability in Apache Tomcat allows attackers to cause denial of service by exploiting the TLS handshake process to trigger OutOfMemoryError co...

Nov 7, 2024
CVE-2024-23590 9.1

This CVE describes a session fixation vulnerability in Apache Kylin that allows attackers to hijack user sessions by fixing session identifiers before...

Nov 4, 2024
CVE-2024-45031 6.1

This stored cross-site scripting (XSS) vulnerability in Apache Syncope allows attackers to inject malicious scripts through incomplete HTML tags that ...

Oct 24, 2024
CVE-2024-45693 8.0

Apache CloudStack has a Cross-Site Request Forgery (CSRF) vulnerability that allows attackers to trick authenticated users into performing unauthorize...

Oct 16, 2024
CVE-2024-45216 9.8

This CVE describes an authentication bypass vulnerability in Apache Solr's PKIAuthenticationPlugin. Attackers can bypass authentication by appending a...

Oct 16, 2024
CVE-2024-45219 8.5

Apache CloudStack has a vulnerability where users can upload malicious KVM-compatible templates or volumes that bypass validation checks. This allows ...

Oct 16, 2024
CVE-2024-45462 6.3

This CVE describes a session expiration vulnerability in Apache CloudStack's web interface where logout doesn't properly invalidate user sessions. An ...

Oct 16, 2024
CVE-2023-50780 8.8

Apache ActiveMQ Artemis versions before 2.29.0 expose the Log4J2 MBean through the authenticated Jolokia endpoint, allowing authenticated non-administ...

Oct 14, 2024
CVE-2024-46911 4.7

This CSRF vulnerability in Apache Roller allows attackers to escalate privileges on multi-blog/user websites. By exploiting the CSRF protection defici...

Oct 14, 2024
CVE-2024-45720 8.2

On Windows, Subversion's command-line argument processing can misinterpret specially crafted arguments due to character encoding issues, potentially a...

Oct 9, 2024
CVE-2024-47554 4.3

This vulnerability in Apache Commons IO allows attackers to cause denial of service by consuming excessive CPU resources through maliciously crafted i...

Oct 3, 2024
CVE-2024-47561 7.3

This vulnerability in Apache Avro's Java SDK allows attackers to execute arbitrary code by exploiting schema parsing flaws. It affects all users of Ap...

Oct 3, 2024
CVE-2024-47197 7.5

The Maven Archetype Plugin versions 3.2.1 through 3.2.x expose sensitive credentials by copying the user's settings.xml file into test artifacts. This...

Sep 26, 2024
CVE-2024-40761 5.3

This vulnerability in Apache Answer uses weak MD5 hashing of user email addresses for Gravatar integration, potentially exposing email addresses throu...

Sep 25, 2024
CVE-2024-39928 7.5

Apache Linkis versions up to 1.5.0 use a cryptographically weak random string generator (Commons Lang's RandomStringUtils) for Py4j token generation i...

Sep 25, 2024
CVE-2024-46544 5.9

This vulnerability allows local users on Unix-like systems to view and modify shared memory containing mod_jk configuration due to incorrect default p...

Sep 23, 2024
CVE-2024-42323 8.8

This vulnerability allows authorized attackers to execute arbitrary code on Apache HertzBeat servers by exploiting insecure deserialization in SnakeYa...

Sep 21, 2024
CVE-2024-45384 5.3

A padding oracle vulnerability in Apache Druid's optional druid-pac4j extension could allow attackers to manipulate session cookies. This affects Drui...

Sep 17, 2024
CVE-2024-22399 9.8

This vulnerability allows attackers to execute arbitrary code on Apache Seata servers by sending malicious serialized data when authentication is disa...

Sep 16, 2024
CVE-2024-45195 7.5

This CVE describes a Direct Request (Forced Browsing) vulnerability in Apache OFBiz that allows attackers to access restricted resources by directly r...

Sep 4, 2024
CVE-2024-45507 9.8

This CVE describes a critical Server-Side Request Forgery (SSRF) and code injection vulnerability in Apache OFBiz. Attackers can exploit this to make ...

Sep 4, 2024
CVE-2023-49582 5.5

This CVE allows local users on Unix systems to read Apache Portable Runtime (APR) named shared memory segments due to overly permissive permissions. T...

Aug 26, 2024
CVE-2024-41937 6.1

Apache Airflow versions before 2.10.0 contain a cross-site scripting (XSS) vulnerability in provider documentation links. Malicious providers can exec...

Aug 21, 2024
CVE-2024-22281 7.5

Apache Helix Front (UI) contains a hard-coded secret that allows attackers to forge authentication cookies and spoof user sessions. This affects all v...

Aug 20, 2024
CVE-2024-42361 7.5

CVE-2024-42361 is a SQL injection vulnerability in Hertzbeat's monitoring endpoint that allows attackers to execute arbitrary SQL commands. This affec...

Aug 20, 2024
CVE-2024-43202 9.8

This vulnerability allows remote attackers to execute arbitrary code on Apache DolphinScheduler servers by exploiting improper input validation. It af...

Aug 20, 2024
CVE-2024-41909 5.9

This vulnerability allows attackers to intercept SSH traffic and drop specific packets, potentially downgrading or disabling security features in Apac...

Aug 12, 2024
CVE-2024-41888 5.3

Apache Answer versions through 1.3.5 have a vulnerability where password reset links remain valid after being used, allowing potential account takeove...

Aug 12, 2024
CVE-2024-30188 8.1

This vulnerability in Apache DolphinScheduler allows authenticated users to read and write files they shouldn't have access to, potentially exposing s...

Aug 12, 2024
CVE-2024-42062 7.2

A privilege escalation vulnerability in Apache CloudStack allows domain admin accounts to query API and secret keys of all account-users, including ro...

Aug 7, 2024
CVE-2024-36448 7.3

This CVE describes a Server-Side Request Forgery (SSRF) vulnerability in Apache IoTDB Workbench, allowing attackers to make unauthorized requests from...

Aug 5, 2024
CVE-2024-42447 9.8

This vulnerability in Apache Airflow's FAB provider prevents users from logging out, potentially allowing unauthorized access to sessions. It affects ...

Aug 5, 2024
CVE-2024-36268 9.8

This CVE describes a code injection vulnerability in Apache InLong that allows attackers to execute arbitrary code remotely. It affects Apache InLong ...

Aug 2, 2024
CVE-2024-27181 8.8

Apache Linkis versions up to 1.5.0 contain a privilege escalation vulnerability where trusted accounts can access token information they shouldn't hav...

Aug 2, 2024
CVE-2023-48396 9.1

This CVE describes an authentication bypass vulnerability in Apache SeaTunnel where a hardcoded JWT secret key allows attackers to forge authenticatio...

Jul 30, 2024
CVE-2024-35296 8.2

Apache Traffic Server versions 8.0.0-8.1.10 and 9.0.0-9.2.4 have a vulnerability where specially crafted Accept-Encoding headers can bypass cache look...

Jul 26, 2024
CVE-2023-38522 7.5

Apache Traffic Server improperly validates HTTP field names, allowing characters that violate HTTP specifications. This enables attackers to craft mal...

Jul 26, 2024
CVE-2023-48362 8.8

This vulnerability allows attackers to perform XML External Entity (XXE) attacks through Apache Drill's XML Format Plugin. By uploading a malicious XM...

Jul 24, 2024
CVE-2024-29070 9.1

This vulnerability allows session tokens to remain valid after logout, enabling attackers to reuse stolen or previously obtained 'Authorization' token...

Jul 23, 2024
CVE-2024-38503 5.4

This vulnerability allows attackers to inject HTML tags into text fields in Apache Syncope's Console and Enduser interfaces. When exploited, it enable...

Jul 22, 2024
CVE-2024-34457 6.5

This vulnerability in Apache Flink allows authenticated regular users to bypass authorization controls and access sensitive user information they shou...

Jul 22, 2024

Why Monitor Apache Security Vulnerabilities?

Real-time CVE tracking: Our automated system monitors 567+ known vulnerabilities affecting Apache products and software packages. Stay ahead of emerging threats with instant email notifications when new security issues are discovered.

Automated security monitoring: Unlike manual CVE checking, FixTheCVE automatically scans your servers and detects vulnerable Apache packages in under 60 seconds. No agents required - completely agentless scanning that works across Apache deployments.

Free vulnerability database: Access detailed information about every Apache CVE including CVSS scores, severity ratings, affected versions, and actionable patch guidance. Filter by critical, high, medium, or low severity to prioritize your security remediation efforts.

🚀 Get Started in 60 Seconds

  • Register free account & add your servers
  • Run one-time scan or schedule automatic monitoring (every 1-24 hours)
  • Receive instant alerts when new Apache CVEs affect your systems
  • Access dashboard with severity breakdown & fix instructions
Start Monitoring Apache CVEs Free