Cxf

Vendor:

First CVE: Aug 19, 2010 · Active for 15 years

57
Total CVEs
More Total CVEs than 98% of tracked products
4.1
Avg CVEs / Year
Higher CVE frequency than 86% of tracked products
6.9
Avg CVSS
Higher Avg CVSS than 40% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Cxf over time

Volume of CVEsAvg CVSS Base Score
First CVE
Aug 19, 2010
15 years ago
Most Recent CVE
Jun 12, 2026
42 days ago

CVE Severity & Scoring

Cxf57 CVEs
All CVEs352,294 CVEs
MediumHighCritical
Attack Vector
Local1 (1.8%)
Network40 (70.2%)
Unknown15 (26.3%)
Physical0 (0.0%)
Adjacent Network1 (1.8%)
Attack Complexity
Low36 (63.2%)
High6 (10.5%)
Unknown15 (26.3%)
User Interaction
None36 (63.2%)
Unknown15 (26.3%)
Required6 (10.5%)
Privileges Required
Low2 (3.5%)
High1 (1.8%)
None39 (68.4%)
Unknown15 (26.3%)

Top CVEs

Signals from CVEs in this product scope (57 CVEs).

57 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
A SSRF vulnerability using the Aegis DataBinding in versions of Apache CXF before 4.0.4, 3.6.3 and 3.5.8 allows an attacker to perform SSRF style attacks on webservices that take a
Mar 15, 20249.344NOYES
An LDAP injection vulnerability in the LDAP Certificate repository of the XKMS server in Apache CXF may allow an attacker to retrieve arbitrary certificates from the repository.  U
May 22, 20269.841NONO
A logic error in OAuthRequestFilter rejects legitimate requests originating from the bound IP address, while blindly allowing requests from any other IP address. Enabling this sec
Jun 12, 20269.840NONO
Apache CXF's EndpointReferenceUtils and W3CMultiSchemaFactory classes construct a SAXParserFactory without the necessary JAXP hardening configurations, enabling out-of-band (OOB)
Jun 12, 20269.840NONO
By default, Apache CXF creates a /services page containing a listing of the available endpoint names and addresses. This webpage is vulnerable to a reflected Cross-Site Scripting (
Nov 12, 20206.138NONO
The streaming XML parser in Apache CXF 2.5.x before 2.5.10, 2.6.x before 2.6.7, and 2.7.x before 2.7.4 allows remote attackers to cause a denial of service (CPU and memory consumpt
Aug 19, 20135.038NOYES
A further incomplete fix for a previous advisory CVE-2026-44417 (Untrusted JMS configuration can lead to RCE) for Apache CXF has been identified, which can allow code execution cap
Jun 12, 20268.837NONO
The JwtAccessTokenValidator class in Apache CXF fails to validate the 'aud' (Audience) claims of incoming JWT access tokens. This allows a JWT issued for one Resource Server to be
Jun 12, 20269.137NONO
Apache CXF before 3.3.4 and 3.2.11 provides all of the components that are required to build a fully fledged OpenId Connect service. There is a vulnerability in the access token se
Nov 6, 20199.837NONO
A JNDI Injection vulnerability has been discovered in Apache CXF's JCA integration module, which can allow for code execution, if an attacker is able to manipulate the JCA deployme
Jun 12, 20268.136NONO

Exploit Exposure

Signals from CVEs in this product scope (57 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
1.8% of CVEs· 96th percentile
ExploitDB
1 CVE
1.8% of CVEs· 87th percentile

Social Chatter

Signals from CVEs in this product scope (57 CVEs).

Media Mentions

Signals from CVEs in this product scope (57 CVEs).

Top CNAs Publishing CVEs For Cxf

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
4.2.037.50.6%00
4.1.015.60.6%00
4.0.615.60.6%00
3.6.515.60.6%00
3.5.1015.60.6%00
3.4.417.57.4%00
3.1.917.56.3%00
3.1.837.07.6%00
3.1.737.07.6%00
3.1.637.07.6%00
3.1.537.07.6%00
3.1.437.07.6%00
3.1.337.07.6%00
3.1.237.07.6%00
3.1.137.07.6%00
3.1.037.07.6%00
3.0.015.07.2%00
2.7.934.34.8%00
2.7.844.35.4%00
2.7.754.45.8%00