<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom"><title>Exploit Reality — KEV: Apache</title><link href="https://xploitwatch.com/feed/hersteller/apache.xml" rel="self"/><link href="https://xploitwatch.com/"/><id>https://xploitwatch.com/feed/hersteller/apache.xml</id><updated>2026-08-04T00:00:00Z</updated><author><name>Exploit Reality</name></author><entry><title>CVE-2026-34486 — Tomcat</title><link href="https://xploitwatch.com/cve/CVE-2026-34486"/><id>https://xploitwatch.com/cve/CVE-2026-34486</id><updated>2026-08-04T00:00:00Z</updated><summary>Apache Tomcat Missing Encryption of Sensitive Data Vulnerability</summary></entry><entry><title>CVE-2026-34197 — ActiveMQ</title><link href="https://xploitwatch.com/cve/CVE-2026-34197"/><id>https://xploitwatch.com/cve/CVE-2026-34197</id><updated>2026-04-16T00:00:00Z</updated><summary>Apache ActiveMQ Improper Input Validation Vulnerability</summary></entry><entry><title>CVE-2024-38475 — HTTP Server</title><link href="https://xploitwatch.com/cve/CVE-2024-38475"/><id>https://xploitwatch.com/cve/CVE-2024-38475</id><updated>2025-05-01T00:00:00Z</updated><summary>Apache HTTP Server Improper Escaping of Output Vulnerability</summary></entry><entry><title>CVE-2025-24813 — Tomcat</title><link href="https://xploitwatch.com/cve/CVE-2025-24813"/><id>https://xploitwatch.com/cve/CVE-2025-24813</id><updated>2025-04-01T00:00:00Z</updated><summary>Apache Tomcat Path Equivalence Vulnerability</summary></entry><entry><title>CVE-2024-45195 — OFBiz</title><link href="https://xploitwatch.com/cve/CVE-2024-45195"/><id>https://xploitwatch.com/cve/CVE-2024-45195</id><updated>2025-02-04T00:00:00Z</updated><summary>Apache OFBiz Forced Browsing Vulnerability</summary></entry><entry><title>CVE-2024-27348 — HugeGraph-Server</title><link href="https://xploitwatch.com/cve/CVE-2024-27348"/><id>https://xploitwatch.com/cve/CVE-2024-27348</id><updated>2024-09-18T00:00:00Z</updated><summary>Apache HugeGraph-Server Improper Access Control Vulnerability</summary></entry><entry><title>CVE-2024-38856 — OFBiz</title><link href="https://xploitwatch.com/cve/CVE-2024-38856"/><id>https://xploitwatch.com/cve/CVE-2024-38856</id><updated>2024-08-27T00:00:00Z</updated><summary>Apache OFBiz Incorrect Authorization Vulnerability</summary></entry><entry><title>CVE-2024-32113 — OFBiz</title><link href="https://xploitwatch.com/cve/CVE-2024-32113"/><id>https://xploitwatch.com/cve/CVE-2024-32113</id><updated>2024-08-07T00:00:00Z</updated><summary>Apache OFBiz Path Traversal Vulnerability</summary></entry><entry><title>CVE-2020-17519 — Flink</title><link href="https://xploitwatch.com/cve/CVE-2020-17519"/><id>https://xploitwatch.com/cve/CVE-2020-17519</id><updated>2024-05-23T00:00:00Z</updated><summary>Apache Flink Improper Access Control Vulnerability</summary></entry><entry><title>CVE-2023-27524 — Superset</title><link href="https://xploitwatch.com/cve/CVE-2023-27524"/><id>https://xploitwatch.com/cve/CVE-2023-27524</id><updated>2024-01-08T00:00:00Z</updated><summary>Apache Superset Insecure Default Initialization of Resource Vulnerability</summary></entry><entry><title>CVE-2023-46604 — ActiveMQ</title><link href="https://xploitwatch.com/cve/CVE-2023-46604"/><id>https://xploitwatch.com/cve/CVE-2023-46604</id><updated>2023-11-02T00:00:00Z</updated><summary>Apache ActiveMQ Deserialization of Untrusted Data Vulnerability</summary></entry><entry><title>CVE-2023-33246 — RocketMQ</title><link href="https://xploitwatch.com/cve/CVE-2023-33246"/><id>https://xploitwatch.com/cve/CVE-2023-33246</id><updated>2023-09-06T00:00:00Z</updated><summary>Apache RocketMQ Command Execution Vulnerability</summary></entry><entry><title>CVE-2016-8735 — Tomcat</title><link href="https://xploitwatch.com/cve/CVE-2016-8735"/><id>https://xploitwatch.com/cve/CVE-2016-8735</id><updated>2023-05-12T00:00:00Z</updated><summary>Apache Tomcat Remote Code Execution Vulnerability</summary></entry><entry><title>CVE-2021-45046 — Log4j2</title><link href="https://xploitwatch.com/cve/CVE-2021-45046"/><id>https://xploitwatch.com/cve/CVE-2021-45046</id><updated>2023-05-01T00:00:00Z</updated><summary>Apache Log4j2 Deserialization of Untrusted Data Vulnerability</summary></entry><entry><title>CVE-2022-33891 — Spark</title><link href="https://xploitwatch.com/cve/CVE-2022-33891"/><id>https://xploitwatch.com/cve/CVE-2022-33891</id><updated>2023-03-07T00:00:00Z</updated><summary>Apache Spark Command Injection Vulnerability</summary></entry><entry><title>CVE-2022-24706 — CouchDB</title><link href="https://xploitwatch.com/cve/CVE-2022-24706"/><id>https://xploitwatch.com/cve/CVE-2022-24706</id><updated>2022-08-25T00:00:00Z</updated><summary>Apache CouchDB Insecure Default Initialization of Resource Vulnerability</summary></entry><entry><title>CVE-2022-24112 — APISIX</title><link href="https://xploitwatch.com/cve/CVE-2022-24112"/><id>https://xploitwatch.com/cve/CVE-2022-24112</id><updated>2022-08-25T00:00:00Z</updated><summary>Apache APISIX Authentication Bypass Vulnerability</summary></entry><entry><title>CVE-2020-1956 — Kylin</title><link href="https://xploitwatch.com/cve/CVE-2020-1956"/><id>https://xploitwatch.com/cve/CVE-2020-1956</id><updated>2022-03-25T00:00:00Z</updated><summary>Apache Kylin OS Command Injection Vulnerability</summary></entry><entry><title>CVE-2017-12617 — Tomcat</title><link href="https://xploitwatch.com/cve/CVE-2017-12617"/><id>https://xploitwatch.com/cve/CVE-2017-12617</id><updated>2022-03-25T00:00:00Z</updated><summary>Apache Tomcat Remote Code Execution Vulnerability</summary></entry><entry><title>CVE-2017-12615 — Tomcat</title><link href="https://xploitwatch.com/cve/CVE-2017-12615"/><id>https://xploitwatch.com/cve/CVE-2017-12615</id><updated>2022-03-25T00:00:00Z</updated><summary>Apache Tomcat on Windows Remote Code Execution Vulnerability</summary></entry><entry><title>CVE-2013-2251 — Struts</title><link href="https://xploitwatch.com/cve/CVE-2013-2251"/><id>https://xploitwatch.com/cve/CVE-2013-2251</id><updated>2022-03-25T00:00:00Z</updated><summary>Apache Struts Improper Input Validation Vulnerability</summary></entry><entry><title>CVE-2020-1938 — Tomcat</title><link href="https://xploitwatch.com/cve/CVE-2020-1938"/><id>https://xploitwatch.com/cve/CVE-2020-1938</id><updated>2022-03-03T00:00:00Z</updated><summary>Apache Tomcat Improper Privilege Management Vulnerability</summary></entry><entry><title>CVE-2017-9791 — Struts 1</title><link href="https://xploitwatch.com/cve/CVE-2017-9791"/><id>https://xploitwatch.com/cve/CVE-2017-9791</id><updated>2022-02-10T00:00:00Z</updated><summary>Apache Struts 1 Improper Input Validation Vulnerability</summary></entry><entry><title>CVE-2016-3088 — ActiveMQ</title><link href="https://xploitwatch.com/cve/CVE-2016-3088"/><id>https://xploitwatch.com/cve/CVE-2016-3088</id><updated>2022-02-10T00:00:00Z</updated><summary>Apache ActiveMQ Improper Input Validation Vulnerability</summary></entry><entry><title>CVE-2012-0391 — Struts 2</title><link href="https://xploitwatch.com/cve/CVE-2012-0391"/><id>https://xploitwatch.com/cve/CVE-2012-0391</id><updated>2022-01-21T00:00:00Z</updated><summary>Apache Struts 2 Improper Input Validation Vulnerability</summary></entry><entry><title>CVE-2006-1547 — Struts 1</title><link href="https://xploitwatch.com/cve/CVE-2006-1547"/><id>https://xploitwatch.com/cve/CVE-2006-1547</id><updated>2022-01-21T00:00:00Z</updated><summary>Apache Struts 1 ActionForm Denial-of-Service Vulnerability</summary></entry><entry><title>CVE-2020-13927 — Airflow's Experimental API</title><link href="https://xploitwatch.com/cve/CVE-2020-13927"/><id>https://xploitwatch.com/cve/CVE-2020-13927</id><updated>2022-01-18T00:00:00Z</updated><summary>Apache Airflow's Experimental API Authentication Bypass</summary></entry><entry><title>CVE-2020-11978 — Airflow</title><link href="https://xploitwatch.com/cve/CVE-2020-11978"/><id>https://xploitwatch.com/cve/CVE-2020-11978</id><updated>2022-01-18T00:00:00Z</updated><summary>Apache Airflow Command Injection</summary></entry><entry><title>CVE-2021-44228 — Log4j2</title><link href="https://xploitwatch.com/cve/CVE-2021-44228"/><id>https://xploitwatch.com/cve/CVE-2021-44228</id><updated>2021-12-10T00:00:00Z</updated><summary>Apache Log4j2 Remote Code Execution Vulnerability</summary></entry><entry><title>CVE-2019-0193 — Solr</title><link href="https://xploitwatch.com/cve/CVE-2019-0193"/><id>https://xploitwatch.com/cve/CVE-2019-0193</id><updated>2021-12-10T00:00:00Z</updated><summary>Apache Solr DataImportHandler Code Injection Vulnerability</summary></entry><entry><title>CVE-2021-40438 — Apache</title><link href="https://xploitwatch.com/cve/CVE-2021-40438"/><id>https://xploitwatch.com/cve/CVE-2021-40438</id><updated>2021-12-01T00:00:00Z</updated><summary>Apache HTTP Server-Side Request Forgery (SSRF)</summary></entry><entry><title>CVE-2021-42013 — HTTP Server</title><link href="https://xploitwatch.com/cve/CVE-2021-42013"/><id>https://xploitwatch.com/cve/CVE-2021-42013</id><updated>2021-11-03T00:00:00Z</updated><summary>Apache HTTP Server Path Traversal Vulnerability</summary></entry><entry><title>CVE-2021-41773 — HTTP Server</title><link href="https://xploitwatch.com/cve/CVE-2021-41773"/><id>https://xploitwatch.com/cve/CVE-2021-41773</id><updated>2021-11-03T00:00:00Z</updated><summary>Apache HTTP Server Path Traversal Vulnerability</summary></entry><entry><title>CVE-2020-17530 — Struts</title><link href="https://xploitwatch.com/cve/CVE-2020-17530"/><id>https://xploitwatch.com/cve/CVE-2020-17530</id><updated>2021-11-03T00:00:00Z</updated><summary>Apache Struts Remote Code Execution Vulnerability</summary></entry><entry><title>CVE-2019-17558 — Solr</title><link href="https://xploitwatch.com/cve/CVE-2019-17558"/><id>https://xploitwatch.com/cve/CVE-2019-17558</id><updated>2021-11-03T00:00:00Z</updated><summary>Apache Solr VelocityResponseWriter Plug-In Remote Code Execution Vulnerability</summary></entry><entry><title>CVE-2019-0211 — HTTP Server</title><link href="https://xploitwatch.com/cve/CVE-2019-0211"/><id>https://xploitwatch.com/cve/CVE-2019-0211</id><updated>2021-11-03T00:00:00Z</updated><summary>Apache HTTP Server Privilege Escalation Vulnerability</summary></entry><entry><title>CVE-2018-11776 — Struts</title><link href="https://xploitwatch.com/cve/CVE-2018-11776"/><id>https://xploitwatch.com/cve/CVE-2018-11776</id><updated>2021-11-03T00:00:00Z</updated><summary>Apache Struts Remote Code Execution Vulnerability</summary></entry><entry><title>CVE-2017-9805 — Struts</title><link href="https://xploitwatch.com/cve/CVE-2017-9805"/><id>https://xploitwatch.com/cve/CVE-2017-9805</id><updated>2021-11-03T00:00:00Z</updated><summary>Apache Struts Deserialization of Untrusted Data Vulnerability</summary></entry><entry><title>CVE-2017-5638 — Struts</title><link href="https://xploitwatch.com/cve/CVE-2017-5638"/><id>https://xploitwatch.com/cve/CVE-2017-5638</id><updated>2021-11-03T00:00:00Z</updated><summary>Apache Struts Remote Code Execution Vulnerability</summary></entry><entry><title>CVE-2016-4437 — Shiro</title><link href="https://xploitwatch.com/cve/CVE-2016-4437"/><id>https://xploitwatch.com/cve/CVE-2016-4437</id><updated>2021-11-03T00:00:00Z</updated><summary>Apache Shiro Code Execution Vulnerability</summary></entry></feed>
