Vendor
Apache
As of , 40 Apache vulnerabilities are on CISA's list of exploited vulnerabilities, 8 of them used in ransomware campaigns; 2 were added in 2026. Patch first: CVE-2020-17519.
Patch first
| # | Vulnerability | Product | Our group | Listed | Deadline | EPSS |
|---|---|---|---|---|---|---|
| 1 | CVE-2020-17519Improper Access Control | Apache Flink | Patch this weekMetasploit module; EPSS 0.98; verified Exploit-DB entry | 0.98 | ||
| 2 | CVE-2013-2251Improper Input Validation | Apache Struts | Patch this weekMetasploit module; EPSS 0.99; verified Exploit-DB entry | 0.99 | ||
| 3 | CVE-2017-12617Remote Code Execution | Apache Tomcat | Patch this weekMetasploit module; EPSS 0.99; verified Exploit-DB entry | 0.99 | ||
| 4 | CVE-2020-1938Improper Privilege Management | Apache Tomcat | Patch this weekMetasploit module; EPSS 0.99; verified Exploit-DB entry | 0.99 | ||
| 5 | CVE-2016-3088Improper Input Validation | Apache ActiveMQ | Patch this weekMetasploit module; EPSS 0.99; verified Exploit-DB entry | 0.99 | ||
| 6 | CVE-2017-9791Improper Input Validation | Apache Struts 1 | Patch this weekMetasploit module; EPSS 0.99; verified Exploit-DB entry | 0.99 | ||
| 7 | CVE-2012-0391Improper Input Validation | Apache Struts 2 | Patch this weekMetasploit module; EPSS 0.76; verified Exploit-DB entry | 0.76 | ||
| 8 | CVE-2016-4437Code Execution | Apache Shiro | Patch this weekMetasploit module; EPSS 0.93; verified Exploit-DB entry | 0.93 | ||
| 9 | CVE-2017-5638Remote Code Execution | Apache Struts | Patch this weekRansomware use; Metasploit module; EPSS 0.99; verified Exploit-DB entry | 0.99 | ||
| 10 | CVE-2018-11776Remote Code Execution | Apache Struts | Patch this weekMetasploit module; EPSS 0.99; verified Exploit-DB entry | 0.99 | ||
| 11 | CVE-2019-17558VelocityResponseWriter Plug-In Remote Code Execution | Apache Solr | Patch this weekMetasploit module; EPSS 0.99; verified Exploit-DB entry | 0.99 | ||
| 12 | CVE-2021-41773Path Traversal | Apache HTTP Server | Patch this weekRansomware use; Metasploit module; EPSS 0.99; verified Exploit-DB entry | 0.99 | ||
| 13 | CVE-2021-42013Path Traversal | Apache HTTP Server | Patch this weekRansomware use; Metasploit module; EPSS 0.99; verified Exploit-DB entry | 0.99 | ||
| 14 | CVE-2025-24813Path Equivalence | Apache Tomcat | Patch this weekMetasploit module; EPSS 0.99 | 0.99 | ||
| 15 | CVE-2024-27348Improper Access Control | Apache HugeGraph-Server | Patch this weekMetasploit module; EPSS 0.99 | 0.99 | ||
| 16 | CVE-2024-38856Incorrect Authorization | Apache OFBiz | Patch this weekMetasploit module; EPSS 0.99 | 0.99 | ||
| 17 | CVE-2024-32113Path Traversal | Apache OFBiz | Patch this weekMetasploit module; EPSS 0.99 | 0.99 | ||
| 18 | CVE-2023-27524Insecure Default Initialization of Resource | Apache Superset | Patch this weekMetasploit module; EPSS 0.97 | 0.97 | ||
| 19 | CVE-2023-46604Deserialization of Untrusted Data | Apache ActiveMQ | Patch this weekRansomware use; Metasploit module; EPSS 0.99 | 0.99 | ||
| 20 | CVE-2023-33246Command Execution | Apache RocketMQ | Patch this weekMetasploit module; EPSS 0.97 | 0.97 | ||
| 21 | CVE-2021-45046Deserialization of Untrusted Data | Apache Log4j2 | Patch this weekRansomware use; Metasploit module; EPSS 0.99 | 0.99 | ||
| 22 | CVE-2022-33891Command Injection | Apache Spark | Patch this weekMetasploit module; EPSS 0.93 | 0.93 | ||
| 23 | CVE-2022-24112Authentication Bypass | Apache APISIX | Patch this weekMetasploit module; EPSS 0.96 | 0.96 | ||
| 24 | CVE-2022-24706Insecure Default Initialization of Resource | Apache CouchDB | Patch this weekMetasploit module; EPSS 0.93 | 0.93 | ||
| 25 | CVE-2020-11978Command Injection | Apache Airflow | Patch this weekMetasploit module; EPSS 0.99 | 0.99 |
Products
- Tomcat6 entries
- Struts5 entries
- HTTP Server4 entries
- ActiveMQ3 entries
- OFBiz3 entries
- Log4j22 entries
- Solr2 entries
- Struts 12 entries
- Airflow1 entry
- Airflow's Experimental API1 entry
- Apache1 entry
- APISIX1 entry
- CouchDB1 entry
- Flink1 entry
- HugeGraph-Server1 entry
- Kylin1 entry
- RocketMQ1 entry
- Shiro1 entry
- Spark1 entry
- Struts 21 entry
- Superset1 entry
Added each year
Show the numbers
| Period | entries added |
|---|---|
| 2021 | 12 |
| 2022 | 13 |
| 2023 | 5 |
| 2024 | 5 |
| 2025 | 3 |
| 2026 | 2 |