Product

Log4j2

Made by Apache Software Foundation. 2 of its vulnerabilities are known to have been exploited.

Coverage

No recent stories mention this product.

Actively exploited

CVE-2021-45046RansomwareCVSS 9.0

Apache Log4j2

Apache Log4j2 Deserialization of Untrusted Data Vulnerability

Added May 1, 2023Fed. due May 22, 2023
CVE-2021-44228RansomwareCVSS 10.0

Apache Log4j2

Apache Log4j2 Remote Code Execution Vulnerability

Added Dec 10, 2021Fed. due Dec 24, 2021