CISA · government feed

Known Exploited Vulnerabilities

Vulnerabilities under active exploitation, mandated by CISA for federal patching.

39 total matches · showing 39

CVEVendor / ProductStatus
CVE-2026-34197
Apache
ActiveMQ
Active
CVE-2024-38475
Apache
HTTP Server
Active
CVE-2025-24813
Apache
Tomcat
Active
CVE-2024-45195
Apache
OFBiz
Active
CVE-2024-27348
Apache
HugeGraph-Server
Active
CVE-2024-38856
Apache
OFBiz
Active
CVE-2024-32113
Apache
OFBiz
Active
CVE-2020-17519
Apache
Flink
Active
CVE-2023-27524
Apache
Superset
Active
CVE-2023-46604
Apache
ActiveMQ
Ransomware
CVE-2023-33246
Apache
RocketMQ
Active
CVE-2016-8735
Apache
Tomcat
Active
CVE-2021-45046
Apache
Log4j2
Ransomware
CVE-2022-33891
Apache
Spark
Active
CVE-2022-24112
Apache
APISIX
Active
CVE-2022-24706
Apache
CouchDB
Active
CVE-2013-2251
Apache
Struts
Active
CVE-2017-12615
Apache
Tomcat
Ransomware
CVE-2017-12617
Apache
Tomcat
Active
CVE-2020-1956
Apache
Kylin
Active
CVE-2020-1938
Apache
Tomcat
Active
CVE-2016-3088
Apache
ActiveMQ
Active
CVE-2017-9791
Apache
Struts 1
Active
CVE-2012-0391
Apache
Struts 2
Active
CVE-2006-1547
Apache
Struts 1
Active
CVE-2020-13927
Apache
Airflow's Experimental API
Active
CVE-2020-11978
Apache
Airflow
Active
CVE-2021-44228
Apache
Log4j2
Ransomware
CVE-2019-0193
Apache
Solr
Active
CVE-2021-40438
Apache
Apache
Active
CVE-2018-11776
Apache
Struts
Active
CVE-2017-5638
Apache
Struts
Ransomware
CVE-2020-17530
Apache
Struts
Active
CVE-2019-17558
Apache
Solr
Active
CVE-2016-4437
Apache
Shiro
Active
CVE-2019-0211
Apache
HTTP Server
Active
CVE-2021-41773
Apache
HTTP Server
Ransomware
CVE-2021-42013
Apache
HTTP Server
Ransomware
CVE-2017-9805
Apache
Struts
Active
Feedback

How was this page?

Spotted something off, or have an idea? Let us know.

0/1000