VulnSea

Apache has 188 CVEs on record. Cadence is steady at roughly 82 per quarter. The busiest recent month was September 2026 with 46. The median CVSS is 7.5 (high), with 34 rated critical. 4% have been exploited in the wild, in line with the corpus average. The median gap from publication to a KEV listing is 1633 days (7 cases). The dominant weakness classes are CWE-502 (18) and CWE-200 (11). Most affected products: airflow (21), tomcat (21), cxf (11).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
4% vs 1% corpus
Median CVSS
7.5
Publish → KEV
1633 d median(7)
Last 90 days
82 prev 63

Products

  • airflow 21
  • tomcat 21
  • cxf 11
  • thrift 9
  • artemis 8
  • http_server 8
188
Total CVEs
34
Critical
7
CISA KEV
7
Exploited

Apache vulnerabilities

CVEs affecting Apache, newest first. Open any entry for full detail, references, and exploit status.

188 CVEsRSS

CVE-2020-9484High· 7.0PoC
6y ago

When using Apache Tomcat versions 10.0.0-M1 to 10.0.0-M4, 9.0.0.M1 to 9.0.34, 8.5.0 to 8.5.54 and 7.0.0 to 7.0.103 if a) an attacker is able to control the contents and name of a file on the server; and b) the server is configured to use…

When using Apache Tomcat versions 10.0.0-M1 to 10.0.0-M4, 9.0.0.M1 to 9.0.34, 8.5.0 to 8.5.54 and 7.0.0 to 7.0.103 if a) an attacker is able to control the contents and name of a file on the server; and b) the server is configured to use…

▾ Midnightapache · tomcatEPSS 56%via NVD
CVE-2020-1938Critical· 9.8CISA KEVPoC
6y ago

When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat

When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomcat treats AJP connections as having higher trust than, for example, a similar HTTP connection. If such connections ar…

▾ Hadalapache · geodeEPSS 99%via NVD
CVE-2019-17569Medium· 4.8
6y ago

The refactoring present in Apache Tomcat 9.0.28 to 9.0.30, 8.5.48 to 8.5.50 and 7.0.98 to 7.0.99 introduced a regression

The refactoring present in Apache Tomcat 9.0.28 to 9.0.30, 8.5.48 to 8.5.50 and 7.0.98 to 7.0.99 introduced a regression. The result of the regression was that invalid Transfer-Encoding headers were incorrectly processed leading to a pos…

▾ Sunlitapache · tomcatEPSS 8.9%via NVD
CVE-2019-10086High· 7.3
7y ago

In Apache Commons Beanutils 1.9.2, a special BeanIntrospector class was added which allows suppressing the ability for an attacker to access the classloader via the class property available on all Java objects

In Apache Commons Beanutils 1.9.2, a special BeanIntrospector class was added which allows suppressing the ability for an attacker to access the classloader via the class property available on all Java objects. We, however were not using…

▾ Twilightapache · commons_beanutilsEPSS 28%via NVD
CVE-2017-12617High· 8.1CISA KEVPoC
8y ago

When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTTP PUTs enabled (e.g

When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTTP PUTs enabled (e.g. via setting the readonly initialisation parameter of the Default servlet to false) it was possib…

▾ Abyssalapache · tomcatEPSS 100%via NVD
CVE-2017-12615High· 8.1CISA KEVPoC
9y ago

When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g

When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g. via setting the readonly initialisation parameter of the Default to false) it was possible to upload a JSP file to the server via a specially crafted requ…

▾ Abyssalapache · tomcatEPSS 100%via NVD
CVE-2016-8735Critical· 9.8CISA KEV
9y ago

Remote code execution is possible with Apache Tomcat before 6.0.48, 7.x before 7.0.73, 8.x before 8.0.39, 8.5.x before 8.5.7, and 9.x before 9.0.0.M12 if JmxRemoteLifecycleListener is used and an attacker can reach JMX ports

Remote code execution is possible with Apache Tomcat before 6.0.48, 7.x before 7.0.73, 8.x before 8.0.39, 8.5.x before 8.5.7, and 9.x before 9.0.0.M12 if JmxRemoteLifecycleListener is used and an attacker can reach JMX ports. The issue e…

▾ Hadalapache · tomcatEPSS 90%via NVD
CVE-2021-44228Critical· 10.0CISA KEV0dayPoC

Log4Shell: JNDI RCE in Apache Log4j 2

Log4j 2 evaluates ${jndi:...} lookups in logged strings, allowing an attacker who controls any logged value to load and execute remote code via LDAP/RMI. Trivial to exploit, ubiquitous, and mass-exploited within hours of disclosure.

▾ HadalApache · Log4j 2JavaEPSS 100%via NVD
Apache vulnerabilities (CVEs) — page 7 · VulnSea