Product of Apache

OFBiz

As of , 3 Apache OFBiz vulnerabilities are on CISA's list of exploited vulnerabilities; 0 were added in 2026. Patch first: CVE-2024-38856.

Patch first

Patch first
#VulnerabilityProductOur groupListedDeadlineEPSS
1CVE-2024-38856Incorrect AuthorizationApache OFBizPatch this weekMetasploit module; EPSS 0.990.99
2CVE-2024-32113Path TraversalApache OFBizPatch this weekMetasploit module; EPSS 0.990.99
3CVE-2024-45195Forced BrowsingApache OFBizPatch this weekEPSS 0.990.99

Added each year

0.511.522024: 2220242025: 1120252026: nonenone2026
Entries CISA added each year, removed ones included. Source: CISA KEV.
Show the numbers
Periodentries added
20242
20251
2026none

Used in ransomware

Changes CISA made to these entries

  1. CVE-2024-45195 Apache OFBizEdited: notes.
  2. CVE-2024-45195 Apache OFBizEdited: notes.

Every change we recorded