Skip to main content

Vendor archive

apache CVEs

Beta · best-effort

3,106 CVEs tagged to vendor apache557 Critical, 1,108 High, 1,342 Medium, 97 Low, 2 Unrated.

CVE-2025-66675

Published Dec 10, 2025

Denial of Service vulnerability in Apache Struts, file leak in multipart request processing causes disk exhaustion. This issue affects Apache Struts: from 2.0.0 through 6.7.4, fr…

CVSS 8.2 · High
Vendor/product tagsBeta · best-effort

CVE-2025-58098

Published Dec 5, 2025

Apache HTTP Server 2.4.65 and earlier with Server Side Includes (SSI) enabled and mod_cgid (but not mod_cgi) passes the shell-escaped query string to #exec cmd="..." directives.…

CVSS 8.3 · High
Vendor/product tagsBeta · best-effort

CVE-2025-66200

Published Dec 5, 2025

mod_userdir+suexec bypass via AllowOverride FileInfo vulnerability in Apache HTTP Server. Users with access to use the RequestHeader directive in htaccess can cause some CGI scrip…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-65082

Published Dec 5, 2025

Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in Apache HTTP Server through environment variables set via the Apache configuration unexpectedly super…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-59775

Published Dec 5, 2025

Server-Side Request Forgery (SSRF) vulnerability  in Apache HTTP Server on Windows with AllowEncodedSlashes On and MergeSlashes Off  allows to potentially leak NTLM hashes to…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-55753

Published Dec 5, 2025

An integer overflow in the case of failed ACME certificate renewal leads, after a number of failures (~30 days in default configurations), to the backoff timer becoming 0. Attempt…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-66516

Published Dec 4, 2025

Critical XXE in Apache Tika tika-core (1.13-3.2.1), tika-pdf-module (2.0.0-3.2.1) and tika-parsers (1.13-1.28.5) modules on all platforms allows an attacker to carry out XML Exter…

CVSS 8.4 · High
evidence mentions
11
Buzz score
32.9
Vendor/product tagsBeta · best-effort

CVE-2025-64775

Published Dec 1, 2025

Denial of Service vulnerability in Apache Struts, file leak in multipart request processing causes disk exhaustion. This issue affects Apache Struts: from 2.0.0 through 6.7.0, fr…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-59789

Published Dec 1, 2025

Uncontrolled recursion in the json2pb component in Apache bRPC (version < 1.15.0) on all platforms allows remote attackers to make the server crash via sending deep recursive json…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-59792

Published Nov 28, 2025

Reveals plaintext credentials in the MONITOR command vulnerability in Apache Kvrocks. This issue affects Apache Kvrocks: from 1.0.0 through 2.13.0. Users are recommended to upgr…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-59790

Published Nov 28, 2025

Improper Privilege Management vulnerability in Apache Kvrocks. This issue affects Apache Kvrocks: from v2.9.0 through v2.13.0. Users are recommended to upgrade to version 2.14.0…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-59454

Published Nov 27, 2025

In Apache CloudStack, a gap in access control checks affected the APIs - createNetworkACL - listNetworkACLs - listResourceDetails - listVirtualMachinesUsageHistory - listVolumesUs…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-59302

Published Nov 27, 2025

In Apache CloudStack improper control of generation of code ('Code Injection') vulnerability is found in the following APIs which are accessible only to admins. * quotaTariff…

CVSS 4.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-54057

Published Nov 27, 2025

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Apache SkyWalking. This issue affects Apache SkyWalking: <= 10.2.0. Users are reco…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-62728

Published Nov 26, 2025

SQL injection vulnerability in Hive Metastore Server (HMS) when processing delete column statistics requests via the Thrift APIs. The vulnerability is only exploitable by trusted/…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-59390

Published Nov 26, 2025

Apache Druid’s Kerberos authenticator uses a weak fallback secret when the `druid.auth.authenticator.kerberos.cookieSignatureSecret` configuration is not explicitly set. In this c…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-65998

Published Nov 24, 2025

Apache Syncope can be configured to store the user password values in the internal database with AES encryption, though this is not the default option. When AES is configured, th…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-64408

Published Nov 19, 2025

Apache Causeway faces Java deserialization vulnerabilities that allow remote code execution (RCE) through user-controllable URL parameters. These vulnerabilities affect all applic…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-64407

Published Nov 12, 2025

Apache OpenOffice documents can contain links. A missing Authorization vulnerability in Apache OpenOffice allowed an attacker to craft a document that would cause external links…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-61623

Published Nov 12, 2025

Reflected cross-site scripting vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 24.09.03. Users are recommended to upgrade to version 24.09.03, which fixes…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-59118

Published Nov 12, 2025

Unrestricted Upload of File with Dangerous Type vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 24.09.03. Users are recommended to upgrade to version 24.0…

CVSS 7.3 · High
Vendor/product tagsBeta · best-effort

CVE-2025-64406

Published Nov 12, 2025

An out-of-bounds Write vulnerability in Apache OpenOffice could allow an attacker to craft a document that would crash the program, or otherwise corrupt other memory areas. This…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-64405

Published Nov 12, 2025

Apache OpenOffice documents can contain links. A missing Authorization vulnerability in Apache OpenOffice allowed an attacker to craft a document that would cause external links…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-64404

Published Nov 12, 2025

Apache OpenOffice documents can contain links to other files. A missing Authorization vulnerability in Apache OpenOffice allowed an attacker to craft a document that would cause e…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-64403

Published Nov 12, 2025

Apache OpenOffice Calc spreadsheet can contain links to other files, in the form of "external data sources". A missing Authorization vulnerability in Apache OpenOffice allowed an…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort
Showing 426-450 of 3,106 CVEsPage 18 of 125