Apache

Apache

Top 1K site
Bounty Partial Safe Harbor

Known Exploited Vulnerabilities 40CVEs

8 linked to ransomware campaigns

  • CVE-2026-34486TomcatAug 4, 202698.6% EPSS

    Apache Tomcat contains a missing encryption of sensitive data vulnerability that allows the bypass of the EncryptInterceptor. This vulnerability can be chained with CVE‑2025‑24813.

  • CVE-2026-34197ActiveMQApr 16, 202698.3% EPSS

    Apache ActiveMQ contains an improper input validation vulnerability that allows for code injection.

  • CVE-2024-38475HTTP ServerMay 1, 2025100.0% EPSS

    Apache HTTP Server contains an improper escaping of output vulnerability in mod_rewrite that allows an attacker to map URLs to filesystem locations that are permitted to be served by the server but are not intentionally/directly reachable by any URL, resulting in code execution or source code disclosure.

  • CVE-2025-24813TomcatApr 1, 202599.9% EPSS

    Apache Tomcat contains a path equivalence vulnerability that allows a remote attacker to execute code, disclose information, or inject malicious content via a partial PUT request. This vulnerability can be chained with CVE‑2026‑34486.

  • CVE-2024-45195OFBizFeb 4, 2025100.0% EPSS

    Apache OFBiz contains a forced browsing vulnerability that allows a remote attacker to obtain unauthorized access.

  • CVE-2024-27348HugeGraph-ServerSep 18, 202499.2% EPSS

    Apache HugeGraph-Server contains an improper access control vulnerability that could allow a remote attacker to execute arbitrary code.

  • CVE-2024-38856OFBizAug 27, 202499.4% EPSS

    Apache OFBiz contains an incorrect authorization vulnerability that could allow remote code execution via a Groovy payload in the context of the OFBiz user process by an unauthenticated attacker.

  • CVE-2024-32113OFBizAug 7, 202499.4% EPSS

    Apache OFBiz contains a path traversal vulnerability that could allow for remote code execution.

  • CVE-2020-17519FlinkMay 23, 202497.8% EPSS

    Apache Flink contains an improper access control vulnerability that allows an attacker to read any file on the local filesystem of the JobManager through its REST interface.

  • CVE-2023-27524SupersetJan 8, 202497.4% EPSS

    Apache Superset contains an insecure default initialization of a resource vulnerability that allows an attacker to authenticate and access unauthorized resources on installations that have not altered the default configured SECRET_KEY according to installation instructions.

and 30 more - view full CISA catalog →

security.txt

Contact
https://security.apache.org/report/
Policy
https://security.apache.org/report/
Languages
en
Expires
Aug 7, 2027
View raw security.txt →