Apache Software Foundation fixes important flaws in Apache TomcatSecurity Affairs·Jul 25, 06:35 UTC · Jul 25, 2018Exploit / PoC in the wildCVE-2018-8037CVE-2018-1336CVE-2018-8034160
Apache Tomcat Patches Important Security VulnerabilitiesThe Hacker News·Jul 24, 11:36 UTC · Jul 24, 2018Vulnerability in the wildCVE-2018-8037CVE-2018-1336CVE-2018-803460
Apache releases the third patch to address a new Log4j flawSecurity Affairs·Dec 18, 15:20 UTC · Dec 18, 2021Vulnerability in the wildCVE-2021-45046CVE-2021-44228CVE-2021-45105160
Apache fixed Critical RCE flaw CVE-2023Security Affairs·Dec 11, 15:08 UTC · Dec 11, 2023Vulnerability in the wildCVE-2023-5016460
Apache fixed a critical SQL Injection in Apache Traffic ControlSecurity Affairs·Dec 26, 00:43 UTC · Dec 26, 2024VulnerabilityCVE-2024-45387CVE-2020-17530160
Log4j zero-day gets security fix just as scans for vulnerable systems ramp upThe Record·Dec 21, 00:00 UTC · Dec 21, 2022Exploit / PoCCVE-2021-4422860
Critical RCE 0day in Apache Log4j library exploited in the wild (CVE-2021-44228)Help Net Security·Dec 13, 12:51 UTC · Dec 13, 2021Exploit / PoC in the wildCVE-2021-4422860
Apache rolled out a new update in a few days to fix incomplete patch for actively exploited flawSecurity Affairs·Oct 8, 07:38 UTC · Oct 8, 2021Vulnerability in the wildCVE-2021-41773CVE-2021-4201360
Apache Spot: open source big data analytics for cyberCyberScoop·Sep 30, 01:20 UTC · Sep 30, 2016Exploit / PoC in the wild60
Experts Urge Rapid Patching of ‘Struts’ BugKrebs on Security·Aug 23, 20:36 UTC · Aug 23, 2018Vulnerability55
CISA adds Zoho, Apache, Qualcomm, Mikrotik flaws to the list of actively exploited issuesSecurity Affairs·Dec 2, 20:17 UTC · Dec 2, 2021Advisory in the wildCVE-2021-37415CVE-2021-44077CVE-2018-14847+2 CVEs60
CVE-2021-31805 RCE bug in Apache Struts was finally patchedSecurity Affairs·Apr 13, 19:32 UTC · Apr 13, 2022VulnerabilityCVE-2021-31805CVE-2020-1753060
Tech Giants to Team-Up on Open Source Security After White House MeetInfosecurity Magazine·Jan 14, 09:04 UTC · Jan 14, 2022Vulnerability55
DHS undersecretary: Log4j problem is not over, may take ‘a decade or longer’The Record·Jan 11, 00:00 UTC · Jan 11, 2023Vulnerability55
New Patch Released for Actively Exploited 0The Hacker News·Oct 11, 02:57 UTC · Oct 11, 2021Vulnerability in the wildCVE-2021-42013CVE-2021-4177360
CISA's new JCDC worked as intended, witnesses say at Senate hearing on Log4Shell bugCyberScoop·Feb 8, 18:22 UTC · Feb 8, 2022Exploit / PoC in the wild60
White House hosts open-source software security summit in light of expansive Log4j flawCyberScoop·Jan 13, 14:08 UTC · Jan 13, 2022Exploit / PoC in the wild60
Log4Shell attacks began two weeks ago, Cisco and Cloudflare sayThe Record·Jan 18, 00:00 UTC · Jan 18, 2023Ransomware in the wild60
Week in review: Strengthening firmware security, Help Net Security: XDR Report releasedHelp Net Security·Oct 17, 00:00 UTC · Oct 17, 2021Ransomware in the wildCVE-2021-33035CVE-2021-30883CVE-2021-4044960
Over 10,000 companies downloading software vulnerable to Equifax hackCyberScoop·May 8, 13:58 UTC · May 8, 2018Data breach in the wild60
Apache fixed a source code disclosure flaw in Apache HTTP ServerSecurity Affairs·Jul 7, 17:20 UTC · Jul 7, 2024VulnerabilityCVE-2024-3988460
Apache Struts 2.3.x vulnerable to two year old RCE flawHelp Net Security·Dec 15, 12:31 UTC · Dec 15, 2023VulnerabilityCVE-2016-100003160
Week in review: VirtualBox 0day, GPU side channel attacks, vulnerable self-encrypting SSDsHelp Net Security·Nov 11, 00:00 UTC · Nov 11, 2018Data breach60
Critical RCE Vulnerability Found in Apache OFBiz ERP Software—Patch NowThe Hacker News·Mar 22, 08:34 UTC · Mar 22, 2021VulnerabilityCVE-2021-2629560
Apache Struts 2 Flaws Affect Multiple Cisco ProductsThe Hacker News·Sep 12, 10:51 UTC · Sep 12, 2017Data breach in the wildCVE-2017-9805CVE-2017-5638CVE-2017-9793+2 CVEs60
PoC exploit for critical Apache Struts flaw found onlineHelp Net Security·Nov 20, 11:02 UTC · Nov 20, 2023Exploit / PoCCVE-2018-11776CVE-2017-563860
New Apache Web Server Bug Threatens Security of Shared Web HostsThe Hacker News·Apr 3, 09:07 UTC · Apr 3, 2019Exploit / PoCCVE-2019-0211CVE-2019-0217CVE-2019-021560
Extremely Critical Log4J Vulnerability Leaves Much of the Internet at RiskThe Hacker News·Dec 11, 05:29 UTC · Dec 11, 2021Vulnerability in the wildCVE-2021-4422860
Equifax attackers got in through an Apache Struts flaw?Help Net Security·Oct 6, 11:01 UTC · Oct 6, 2017Data breach in the wildCVE-2017-9805CVE-2017-563860
Apache Tomcat Patches Important Remote Code Execution FlawThe Hacker News·Oct 5, 11:16 UTC · Oct 5, 2017VulnerabilityCVE-2017-12617CVE-2017-12615260
Apache Tomcat Patches Important Remote Code Execution FlawThe Hacker News·Apr 15, 00:00 UTC · Apr 15, 2019VulnerabilityCVE-2019-023260
Apache fixes actively exploited web server zeroThe Record·Dec 16, 00:00 UTC · Dec 16, 2022Exploit / PoC in the wildCVE-2021-4177360
China suspends deal with Alibaba for not sharing Log4j 0The Hacker News·Dec 23, 15:13 UTC · Dec 23, 2021Vulnerability in the wildCVE-2021-4422860
Critical SQL Injection Vulnerability in Apache Traffic Control Rated 9.9 CVSS — Patch NowThe Hacker News·Dec 25, 13:30 UTC · Dec 25, 2024VulnerabilityCVE-2024-45387CVE-2024-43441CVE-2024-56337160
Apache MINA CVE-2024-52046: CVSS 10.0 Flaw Enables RCE via Unsafe SerializationThe Hacker News·Dec 27, 06:46 UTC · Dec 27, 2024Vulnerability in the wildCVE-2024-52046CVE-2024-56337CVE-2024-45387+2 CVEs160
Expert published NMAP script for Apache CVE-2021Security Affairs·Oct 9, 12:04 UTC · Oct 9, 2021Vulnerability in the wildCVE-2021-41773CVE-2021-42013160
Apache fixes critical HTTP/2 double-free flaw CVE-2026Security Affairs·May 6, 11:00 UTC · May 6, 2026Exploit / PoCCVE-2026-23918160
Critical Apache HTTP/2 Flaw (CVE-2026The Hacker News·May 5, 16:46 UTC · May 5, 2026Exploit / PoCCVE-2026-2391860
Threat actors exploit Apache ActiveMQ flaw to deliver the Godzilla Web ShellSecurity Affairs·Jan 22, 11:19 UTC · Jan 22, 2024Threat actor in the wildCVE-2023-4660460
Hackers Started Exploiting Critical "Text4Shell" Apache Commons Text VulnerabilityThe Hacker News·Oct 24, 05:48 UTC · Oct 24, 2022Vulnerability in the wildCVE-2022-42889CVE-2022-3398060