VendorsApachelog4j2.0
Vulnerabilities

Apache Software Foundation 2.0

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

4CVEs
CVE-2021-44228
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
Published 2021-12-10 · Analyzed
10.0KEV3 PoCEPSS 1.000
CVE-2021-45046
Apache Log4j2 Thread Context Message Pattern and Context Lookup Pattern vulnerable to a denial of service attack
Published 2021-12-14 · Analyzed
9.0KEVEPSS 1.000
CVE-2021-44832
Apache Log4j2 vulnerable to RCE via JDBC Appender when attacker controls configuration
Published 2021-12-28 · Modified
8.5EPSS 0.979
CVE-2025-68161
Apache Log4j Core: Missing TLS hostname verification in Socket appender
Published 2025-12-18 · Modified
6.3EPSS 0.008