Fixed Intel

CVE Tracker

Track known exploited vulnerabilities, CISA KEV alerts, and linked threat intelligence.

1,542

Total CVEs

1,542

CISA KEV

35

Known Exploits

9.3

Avg CVSS Score

Severity Distribution

HIGH 1542

Showing 20 of 42 CVEs matching "Apache"

CVE-2024-38475KEV
High

Apache HTTP Server contains an improper escaping of output vulnerability in mod_rewrite that allows an attacker to map URLs to filesystem locations that are permitted to be served by the server but are not intentionally/directly reachable by any URL, resulting in code execution or source code disclosure.

ApacheEPSS 93.4%
CVE-2025-24813KEV
High

Apache Tomcat contains a path equivalence vulnerability that allows a remote attacker to execute code, disclose information, or inject malicious content via a partial PUT request.

ApacheEPSS 94.2%
CVE-2017-3066KEV
High

Adobe ColdFusion contains a deserialization vulnerability in the Apache BlazeDS library that allows for arbitrary code execution.

AdobeEPSS 93.4%
CVE-2024-45195KEV
High

Apache OFBiz contains a forced browsing vulnerability that allows a remote attacker to obtain unauthorized access.

ApacheEPSS 94.1%
CVE-2024-27348KEV
High

Apache HugeGraph-Server contains an improper access control vulnerability that could allow a remote attacker to execute arbitrary code.

ApacheEPSS 94.3%
CVE-2024-38856KEV
High

Apache OFBiz contains an incorrect authorization vulnerability that could allow remote code execution via a Groovy payload in the context of the OFBiz user process by an unauthenticated attacker.

ApacheEPSS 94.3%
CVE-2024-32113KEV
High

Apache OFBiz contains a path traversal vulnerability that could allow for remote code execution.

ApacheEPSS 94.0%
CVE-2020-17519KEV
High

Apache Flink contains an improper access control vulnerability that allows an attacker to read any file on the local filesystem of the JobManager through its REST interface.

ApacheEPSS 94.4%
CVE-2023-27524KEV
High

Apache Superset contains an insecure default initialization of a resource vulnerability that allows an attacker to authenticate and access unauthorized resources on installations that have not altered the default configured SECRET_KEY according to installation instructions.

ApacheEPSS 84.1%
CVE-2023-46604KEV
High

Apache ActiveMQ contains a deserialization of untrusted data vulnerability that may allow a remote attacker with network access to a broker to run shell commands by manipulating serialized class types in the OpenWire protocol to cause the broker to instantiate any class on the classpath.

ApacheEPSS 94.4%
CVE-2023-33246KEV
High

Several components of Apache RocketMQ, including NameServer, Broker, and Controller, are exposed to the extranet and lack permission verification. An attacker can exploit this vulnerability by using the update configuration function to execute commands as the system users that RocketMQ is running as or achieve the same effect by forging the RocketMQ protocol content.

ApacheEPSS 94.4%
CVE-2023-38035KEV
High

Ivanti Sentry, formerly known as MobileIron Sentry, contains an authentication bypass vulnerability that may allow an attacker to bypass authentication controls on the administrative interface due to an insufficiently restrictive Apache HTTPD configuration.

IvantiEPSS 94.4%
CVE-2016-8735KEV
High

Apache Tomcat contains an unspecified vulnerability that allows for remote code execution if JmxRemoteLifecycleListener is used and an attacker can reach Java Management Extension (JMX) ports. This CVE exists because this listener wasn't updated for consistency with the Oracle patched issues for CVE-2016-3427 which affected credential types.

ApacheEPSS 93.7%
CVE-2021-45046KEV
High

Apache Log4j2 contains a deserialization of untrusted data vulnerability due to the incomplete fix of CVE-2021-44228, where the Thread Context Lookup Pattern is vulnerable to remote code execution in certain non-default configurations.

ApacheCVSS 9EPSS 94.3%
CVE-2022-33891KEV
High

Apache Spark contains a command injection vulnerability via Spark User Interface (UI) when Access Control Lists (ACLs) are enabled.

ApacheEPSS 93.5%
CVE-2022-47966KEV
High

Multiple Zoho ManageEngine products contain an unauthenticated remote code execution vulnerability due to the usage of an outdated third-party dependency, Apache Santuario.

ZohoEPSS 94.4%
CVE-2022-24112KEV
High

Apache APISIX contains an authentication bypass vulnerability that allows for remote code execution.

ApacheEPSS 94.4%
CVE-2022-24706KEV
High

Apache CouchDB contains an insecure default initialization of resource vulnerability which can allow an attacker to escalate to administrative privileges.

ApacheEPSS 94.4%
CVE-2020-1956KEV
High

Apache Kylin contains an OS command injection vulnerability which could permit an attacker to perform remote code execution.

ApacheEPSS 93.9%
CVE-2017-12615KEV
High

When running Apache Tomcat on Windows with HTTP PUTs enabled, it is possible to upload a JSP file to the server via a specially crafted request. This JSP could then be requested and any code it contained would be executed by the server.

ApacheEPSS 94.2%
Previous
Next