Skip to main content

Vendor archive

apache CVEs

Beta · best-effort

3,106 CVEs tagged to vendor apache557 Critical, 1,108 High, 1,342 Medium, 97 Low, 2 Unrated.

CVE-2025-68438

Published Jan 16, 2026

In Apache Airflow versions before 3.1.6, when rendered template fields in a Dag exceed [core] max_templated_field_length, sensitive values could be exposed in cleartext in the Ren…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-60021

Published Jan 16, 2026

Remote command injection vulnerability in heap profiler builtin service in Apache bRPC ((all versions < 1.15.0)) on all platforms allows attacker to inject remote command. Root…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-66169

Published Jan 14, 2026

Cypher Injection vulnerability in Apache Camel camel-neo4j component. This issue affects Apache Camel: from 4.10.0 before 4.10.8, from 4.14.0 before 4.14.3, from 4.15.0 before 4.…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-68493

Published Jan 11, 2026

Missing XML Validation vulnerability in Apache Struts, Apache Struts. This issue affects Apache Struts: from 2.0.0 before 2.2.1; Apache Struts: from 2.2.1 through 6.1.0. Users a…

CVSS 8.1 · High
evidence mentions
5
Buzz score
32.4
Vendor/product tagsBeta · best-effort

CVE-2025-62235

Published Jan 10, 2026

Authentication Bypass by Spoofing vulnerability in Apache NimBLE. Receiving specially crafted Security Request could lead to removal of original bond and re-bond with impostor. T…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2025-53477

Published Jan 10, 2026

NULL Pointer Dereference vulnerability in Apache Nimble. Missing validation of HCI connection complete or HCI command TX buffer could lead to NULL pointer dereference. This issue…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-53470

Published Jan 10, 2026

Out-of-bounds Read vulnerability in Apache NimBLE HCI H4 driver. Specially crafted HCI event could lead to invalid memory read in H4 driver. This issue affects Apache NimBLE: th…

CVSS 3.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-52435

Published Jan 10, 2026

J2EE Misconfiguration: Data Transmission Without Encryption vulnerability in Apache NimBLE. Improper handling of Pause Encryption procedure on Link Layer results in a previously…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-68637

Published Jan 7, 2026

The Uniffle HTTP client is configured to trust all SSL certificates and disables hostname verification by default. This insecure configuration exposes all REST API communication…

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-68280

Published Jan 5, 2026

Improper Restriction of XML External Entity Reference vulnerability in Apache SIS. It is possible to write XML files in such a way that, when parsed by Apache SIS, an XML file…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-66518

Published Jan 5, 2026

Any client who can access to Apache Kyuubi Server via Kyuubi frontend protocols can bypass server-side config kyuubi.session.local.dir.allow.list and use local files which are not…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2025-48769

Published Jan 1, 2026

Use After Free vulnerability was discovered in fs/vfs/fs_rename code of the Apache NuttX RTOS, that due recursive implementation and single buffer use by two different pointer var…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2025-48768

Published Jan 1, 2026

Release of Invalid Pointer or Reference vulnerability was discovered in fs/inode/fs_inoderemove code of the Apache NuttX RTOS that allowed root filesystem inode removal leading to…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-47411

Published Jan 1, 2026

A user with a legitimate non-administrator account can exploit a vulnerability in the user ID creation mechanism in Apache StreamPipes that allows them to swap the username of an…

CVSS 8.1 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-66524

Published Dec 19, 2025

Apache NiFi 1.20.0 through 2.6.0 include the GetAsanaObject Processor, which requires integration with a configurable Distribute Map Cache Client Service for storing and retrievin…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-68161

Published Dec 18, 2025

The Socket Appender in Apache Log4j Core versions 2.0-beta9 through 2.25.2 does not perform TLS hostname verification of the peer certificate, even when the verifyHostName https:…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-67895

Published Dec 17, 2025

Edge3 Worker RPC RCE on Airflow 2. This issue affects Apache Airflow Providers Edge3: before 2.0.0 - and only if you installed and configured it on Airflow 2. The Edge3 provid…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-66388

Published Dec 15, 2025

A vulnerability in Apache Airflow allowed authenticated UI users to view secret values in rendered templates due to secrets not being properly redacted, potentially exposing secre…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-53960

Published Dec 12, 2025

When issuing JSON Web Tokens (JWT), Apache StreamPark directly uses the user's password as the HMAC signing key (e.g., with the HS256 algorithm). An attacker can exploit this vuln…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-54981

Published Dec 12, 2025

Weak Encryption Algorithm in StreamPark, The use of an AES cipher in ECB mode and a weak random number generator for encrypting sensitive data, including JWT tokens, may have risk…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-54947

Published Dec 12, 2025

In Apache StreamPark versions 2.0.0 through 2.1.7, a security vulnerability involving a hard-coded encryption key exists. This vulnerability occurs because the system uses a fixed…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-58137

Published Dec 12, 2025

Authorization Bypass Through User-Controlled Key vulnerability in Apache Fineract. This issue affects Apache Fineract: through 1.11.0. The issue is fixed in version 1.12.1. User…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2025-58130

Published Dec 12, 2025

Insufficiently Protected Credentials vulnerability in Apache Fineract. This issue affects Apache Fineract: through 1.11.0. The issue is fixed in version 1.12.1. Users are encour…

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-26866

Published Dec 12, 2025

A remote code execution vulnerability exists where a malicious Raft node can exploit insecure Hessian deserialization within the PD store. The fix enforces IP-based authentication…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2025-23408

Published Dec 12, 2025

Weak Password Requirements vulnerability in Apache Fineract. This issue affects Apache Fineract: through 1.10.1. The issue is fixed in version 1.11.0. Users are encouraged to up…

CVSS 8.5 · High
Vendor/product tagsBeta · best-effort
Showing 401-425 of 3,106 CVEsPage 17 of 125