Apache EPSS Rated Vulnerabilities
Apache vulnerabilities from the past 365 days which have an EPSS rating.
Vulnerability Published:
๐๏ธ Published
- Anytime
Sort By:
๐๏ธ Published Date
- Descending
Incorrect Authorization Vulnerability Affects Apache OFBiz Through 18.12.14
CVE-2024-38856ApacheApache Ofbiz๐ฅ๐๐ฐ๐พ๐กEPSS 94%๐ฆ ๐ฐ9.8CRITICALApache OFBiz vulnerable to 'Forced Browsing' (Direct Request) attack
CVE-2024-45195ApacheApache Ofbiz๐พEPSS 94%๐ฆ ๐ฐ7.5HIGHImproper Authentication Vulnerability in Apache Solr
CVE-2024-45216ApacheApache SolrEPSS 93%Apache OFBiz vulnerable to Path Traversal attack
CVE-2024-36104ApacheApache Ofbiz๐พEPSS 93%๐ฐ9.1CRITICALRemote Code Execution and Information Disclosure Vulnerability in Apache Tomcat Software
CVE-2025-24813ApacheApache Tomcat๐ฅ๐๐พ๐กEPSS 93%๐ฆ ๐ฐ9.8CRITICALSAML Authentication Vulnerability in CloudStack Environments
CVE-2024-41107ApacheApache Cloudstack๐พEPSS 93%๐ฐ8.1HIGHCode Execution or Source Code Disclosure Vulnerability in Apache HTTP Server's mod_rewrite
CVE-2024-38475ApacheApache Http Server๐๐พ๐กEPSS 92%๐ฆ ๐ฐ9.1CRITICALFlawed File Upload Logic in Apache Struts Exposes Vulnerability
CVE-2024-53677ApacheApache Struts๐ฅ๐๐ฐ๐พ๐กEPSS 91%๐ฐRace Condition Vulnerability in Apache Tomcat Leading to Remote Code Execution
CVE-2024-50379ApacheApache Tomcat๐ฅ๐๐พ๐กEPSS 89%๐ฐ9.8CRITICALServer-Side Request Forgery (SSRF) and Improper Control of Generation of Code (Code Injection) Vulnerability in Apache OFBiz
CVE-2024-45507ApacheApache Ofbiz๐EPSS 87%9.8CRITICALApache HTTP Server Vulnerability Could Leak NTML Hashes
CVE-2024-38472ApacheApache Http ServerEPSS 83%Crafted Requests Can Bypass Authentication in Apache HTTP Server's mod_proxy
CVE-2024-38473ApacheApache Http ServerEPSS 80%8.1HIGHIllegal Access to Additional Resource Files via File Read/Write Vulnerability
CVE-2024-30188ApacheApache DolphinschedulerEPSS 80%8.1HIGHSnakeYaml Deserialization RCE Vulnerability in Apache HertzBeat (incubating)
CVE-2024-42323ApacheApache HertzbeatEPSS 72%SQL Injection Vulnerability in Apache Superset by Apache
CVE-2024-39887ApacheApache SupersetEPSS 57%9.8CRITICALCryptographically Weak Pseudo-Random Number Generator (PRNG) Vulnerability Affects Apache StreamPipes from 0.69.0 to 0.93.0
CVE-2024-29868ApacheApache Streampipes๐พ๐กEPSS 52%Deserialization Vulnerability in Apache Seata by Apache
CVE-2024-22399ApacheSeataEPSS 48%9.8CRITICALBypass/Injection Vulnerability in Apache Camel by Apache
CVE-2025-27636ApacheApache Camel๐พEPSS 42%๐ฐ5.6MEDIUMAuthentication Bypass Vulnerability in Apache HugeGraph-Server
CVE-2024-43441ApacheApache Hugegraph-server๐พEPSS 35%๐ฐSQL Injection Vulnerability in Apache Traffic Control
CVE-2024-45387ApacheApache Traffic Control๐๐ฐ๐พEPSS 28%๐ฐ8.8HIGHAuthorization Flaw in Apache NiFi Affecting Parameter Contexts and Controller Services
CVE-2024-56512Apache Software F...Nifi๐พ๐กEPSS 28%5.4MEDIUMPartial Fix for Content-Type Based Configuration Ignores Use of Legacy Handlers, Leading to Source Code Disclosure
CVE-2024-40725ApacheApache Http Server๐ฅ๐๐พ๐กEPSS 24%๐ฐ5.3MEDIUMRemote Code Execution Risk in Apache MINA ObjectSerializationDecoder
CVE-2024-52046ApacheApache Mina๐ฅ๐EPSS 23%10CRITICALAccess Control Issue in Apache CloudStack Affects User Comments
CVE-2025-22828ApacheApache Cloudstack๐พ๐กRace Condition Vulnerability in Apache Tomcat Affects Multiple Versions
CVE-2024-56337ApacheApache Tomcat๐ฅ๐๐พ๐ฐ9.8CRITICAL