| CVE ID | Description | CVSS | Priority | Trend | Exploit | Patch |
|---|---|---|---|---|---|---|
| CVE ID | Description | CVSS | Priority | Trend | Exploit | Patch |
|---|---|---|---|---|---|---|
Deploy autonomous AI agents that reason, exploit, and validate complex vulnerability chains — not another scanner, an agentic system that thinks like a senior pentester.
Known vulnerabilities affecting Log4j products and systems
| CVE ID | Description | CVSS | Priority | Trend | Exploit | Patch |
|---|---|---|---|---|---|---|
| CVE-2026-49844 | Improper encoding of non-finite floating-point values during MapMessage JSON serialization in Apache Log4j API produces output that is not valid JSON. This issue affects Apache Log4j API versions 2.13... | 5.9 | 256 | Neutral | Yes | Yes |
| CVE-2026-34481 | No description available | 7.5 | 386 | Neutral | No | Yes |
| CVE-2026-34480 | No description available | 7.5 | 386 | Neutral | No | Yes |
| CVE-2026-34479 | No description available | 7.5 | 386 | Neutral | No | Yes |
| CVE-2026-34478 | Apache Log4j Core's Rfc5424Layout https://logging.apache.org/log4j/2.x/manual/layouts.html#RFC5424Layout , in versions 2.21.0 through 2.25.3, is vulnerable to log injection via CRLF sequences due to ... | 7.5 | 386 | Neutral | No | Yes |
| CVE-2026-34477 | No description available | 5.9 | 155 | Neutral | No | Yes |
| CVE-2025-68161 | The Socket Appender in Apache Log4j Core versions 2.0-beta9 through 2.25.2 does not perform TLS hostname verification of the peer certificate, even when the verifyHostName https://logging.apache.org/... | 4.8 | 112 | Neutral | No | Yes |
| CVE-2023-26464 | A security update is now available for Red Hat JBoss Enterprise Application Platform 7.1 for Red Hat Enterprise Linux 7.Red Hat Product Security has rated this update as having a security impact of Im... | 8.1 | 514 | Neutral | No | Yes |
| CVE-2022-33915 | Versions of the Amazon AWS Apache Log4j hotpatch package before log4j-cve-2021-44228-hotpatch-1.3.5 are affected by a race condition that could lead to a local privilege escalation. This Hotpatch pack... | 7.0 | 287 | Neutral | No | Yes |
| CVE-2022-23307 | A security update is now available for Red Hat JBoss Enterprise Application Platform 7.3 for Red Hat Enterprise Linux 7.Red Hat Product Security has rated this update as having a security impact of Im... | 8.8 | 673 | Neutral | No | Yes |
| CVE-2022-23305 | A security update is now available for Red Hat JBoss Enterprise Application Platform 7.3 for Red Hat Enterprise Linux 7.Red Hat Product Security has rated this update as having a security impact of Im... | 6.6 | 819 | Low | Yes | Yes |
| CVE-2022-23302 | JMSSink in all versions of Log4j 1.x is vulnerable to deserialization of untrusted data when the attacker has write access to the Log4j configuration or if the configuration references an LDAP service... | 8.8 | 673 | Neutral | No | Yes |
| CVE-2022-21704 | log4js-node is a port of log4js to node.js. In affected versions default file permissions for log files created by the file, fileSync and dateFile appenders are world-readable (in unix). This could ca... | 5.5 | 125 | Neutral | No | Yes |
| CVE-2022-0070 | Incomplete fix for CVE-2021-3100. The Apache Log4j hotpatch package starting with log4j-cve-2021-44228-hotpatch-1.1-16 will now explicitly mimic the Linux capabilities and cgroups of the target Java p... | 8.8 | 648 | Neutral | Yes | Yes |
| CVE-2021-45105 | Apache Log4j2 versions 2.0-alpha1 through 2.16.0 (excluding 2.12.3 and 2.3.1) did not protect from uncontrolled recursion from self-referential lookups. This allows an attacker with control over Threa... | 5.9 | 342 | Trending | Yes | Yes |
| CVE-2021-45046 | Apache Log4j2 contains a deserialization of untrusted data vulnerability due to the incomplete fix of CVE-2021-44228, where the Thread Context Lookup Pattern is vulnerable to remote code execution in ... | 9.0 | 793 | Viral | Yes | Yes |
| CVE-2021-44832 | Apache Log4j2 versions 2.0-beta7 through 2.17.0 (excluding security fix releases 2.3.2 and 2.12.4) are vulnerable to a remote code execution (RCE) attack when a configuration uses a JDBC Appender with... | 6.6 | 400 | Neutral | Yes | Yes |
| CVE-2021-44228 | Multiple Atlassian products use the third-party Log4j library, which is vulnerable toCVE-2021-44228: | 9.8 | 999 | Viral | Yes | Yes |
| CVE-2021-4104 | A security update is now available for Red Hat JBoss Enterprise Application Platform 7.3 for Red Hat Enterprise Linux 7.Red Hat Product Security has rated this update as having a security impact of Im... | 4.1 | 609 | Low | Yes | Yes |
| CVE-2021-3100 | The Apache Log4j hotpatch package before log4j-cve-2021-44228-hotpatch-1.1-13 didn’t mimic the permissions of the JVM being patched, allowing it to escalate privileges. | 8.8 | 648 | Neutral | Yes | Yes |