Apache Software Foundation
46 exploits
Active since Aug 2013
Apache 2.4.49/2.4.50 Traversal RCE
Apache Maven maven-shared-utils <3.3.3 - Command Injection
CVSS 9.8
Apache Commons Compress <1.19 - DoS
CVSS 7.5
Apache Commons Compress 1.11-1.15 - Denial of Service via ZIP Extra Field Parser
CVSS 5.5
Apache Commons Compress 1.7-1.17 - Denial of Service via Malformed ZIP Archive
CVSS 5.5
Apache Commons Email <1.5 - Info Disclosure
CVSS 7.5
Apache CXF Fediz <1.4.0-1.3.2 - CSRF
CVSS 8.8
Apache CXF Fediz <1.4.0-1.2.4 - CSRF
CVSS 8.8
Apache Tika < 1.14 - Remote Code Execution via MATLAB File Deserialization
CVSS 9.8
Apache Jackrabbit < 2.4.6 - CSRF
CVSS 8.8
Apache Qpid AMQP JMS Client < 6.0.4 & JMS (AMQP 1.0) < 0.10.0 - RCE via JMS ObjectMessage Deserialization
CVSS 7.5
Apache CXF Fediz 1.2.0-1.2.2 and 1.3.0 - Improper Access Control via SAML AudienceRestriction Bypass
CVSS 9.8
Apache Tika Server < 1.10 - Exposure of Sensitive Information via HTTP fileUrl Header
CVSS 5.3
Apache Santuario XML Security for Java <1.5.6 - DoS
Apache Santuario XML Security for Java <1.4.8/1.5.5 XML Signature Spoofing
Apache Sling Servlets Resolver < 2.11.0 - Path Traversal and Remote Code Execution
CVSS 8.5
PyArrow 0.14.0-14.0.0 - Remote Code Execution via Untrusted Data Deserialization
CVSS 9.8
Apache NiFi <1.22.0 - Authenticated RCE
CVSS 8.8
Apache Shiro < 1.12.0 - Path Traversal and Authentication Bypass via Non-Normalized Request Routing
CVSS 9.8
Apache JSPWiki < 2.12.0 - Cross-Site Scripting via Crafted Plugin Request
CVSS 6.1
Apache Commons Text 1.5-1.9 - Remote Code Execution via String Interpolation
CVSS 9.8
Apache Maven maven-shared-utils <3.3.3 - Command Injection
CVSS 9.8
Apache Commons Compress 1.6-1.19 - Denial of Service via Malicious 7Z Archive
CVSS 7.5
Apache Commons Compress 1.6-1.19 - Denial of Service via Crafted 7Z Archive
CVSS 7.5
Apache Commons IO - Path Traversal via FileNameUtils.normalize
CVSS 4.8