Skip to main content

Vendor archive

apache CVEs

Beta · best-effort

3,127 CVEs tagged to vendor apache564 Critical, 1,119 High, 1,345 Medium, 97 Low, 2 Unrated.

CVE-2025-62503

Published Oct 30, 2025

User with CREATE and no UPDATE privilege for Pools, Connections, Variables could update existing records via bulk create API with overwrite action.

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-62402

Published Oct 30, 2025

API users via `/api/v2/dagReports` could perform Dag code execution in the context of the api-server if the api-server was deployed in the environment where Dag files were availab…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-54941

Published Oct 30, 2025

An example dag `example_dag_decorator` had non-validated parameter that allowed the UI user to redirect the example to a malicious server and execute code on worker. This however…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-61795

Published Oct 27, 2025

Improper Resource Shutdown or Release vulnerability in Apache Tomcat. If an error occurred (including exceeding limits) during the processing of a multipart upload, temporary cop…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-55754

Published Oct 27, 2025

Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in Apache Tomcat. Tomcat did not escape ANSI escape sequences in log messages. If Tomcat was running i…

CVSS 9.6 · Critical
evidence mentions
3
Buzz score
25.4
Vendor/product tagsBeta · best-effort

CVE-2025-55752

Published Oct 27, 2025

Relative Path Traversal vulnerability in Apache Tomcat. The fix for bug 60013 introduced a regression where the rewritten URL was normalized before it was decoded. This int…

CVSS 7.5 · High
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2025-57738

Published Oct 20, 2025

Apache Syncope offers the ability to extend / customize the base behavior on every deployment by allowing to provide custom implementations of a few Java interfaces; such implemen…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2025-47410

Published Oct 18, 2025

Apache Geode is vulnerable to CSRF attacks through GET requests to the Management and Monitoring REST API that could allow an attacker who has tricked a user into giving up their…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2025-61581

Published Oct 16, 2025

** UNSUPPORTED WHEN ASSIGNED ** Inefficient Regular Expression Complexity vulnerability in Apache Traffic Control. This issue affects Apache Traffic Control: all versions. Peopl…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-54539

Published Oct 16, 2025

A Deserialization of Untrusted Data vulnerability exists in the Apache ActiveMQ NMS AMQP Client. This issue affects all versions of Apache ActiveMQ NMS AMQP up to and including 2…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-55039

Published Oct 15, 2025

This issue affects Apache Spark versions before 3.4.4, 3.5.2 and 4.0.0. Apache Spark versions before 4.0.0, 3.5.2 and 3.4.4 use an insecure default network encryption cipher f…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-44088

Published Oct 14, 2025

Malicious script injection ('Cross-site Scripting') vulnerability in Apache Geode web-api (REST). This vulnerability allows an attacker that tricks a logged-in user into clicking…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-30001

Published Oct 10, 2025

Incorrect Execution-Assigned Permissions vulnerability in Apache StreamPark. This issue affects Apache StreamPark: from 2.1.4 before 2.1.6. Users are recommended to upgrade to v…

CVSS 7.3 · High
Vendor/product tagsBeta · best-effort

CVE-2025-62228

Published Oct 9, 2025

Apache Flink CDC version 3.4.0 was vulnerable to a SQL injection via maliciously crafted identifiers eg. crafted database name or crafted table name. Even through only the logged-…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-61735

Published Oct 2, 2025

Server-Side Request Forgery (SSRF) vulnerability in Apache Kylin. This issue affects Apache Kylin: from 4.0.0 through 5.0.2. You are fine as long as the Kylin's system and projec…

CVSS 7.3 · High
Vendor/product tagsBeta · best-effort

CVE-2025-61734

Published Oct 2, 2025

Files or Directories Accessible to External Parties vulnerability in Apache Kylin. You are fine as long as the Kylin's system and project admin access is well protected. This is…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-61733

Published Oct 2, 2025

Authentication Bypass Using an Alternate Path or Channel vulnerability in Apache Kylin. This issue affects Apache Kylin: from 4.0.0 through 5.0.2. Users are recommended to upgra…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-61622

Published Oct 1, 2025

Deserialization of untrusted data in python in pyfory versions 0.12.0 through 0.12.2, or the legacy pyfury versions from 0.1.0 through 0.10.3: allows arbitrary code execution. An…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-54831

Published Sep 26, 2025

Apache Airflow 3 introduced a change to the handling of sensitive information in Connections. The intent was to restrict access to sensitive connection fields to Connection Editin…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-58457

Published Sep 24, 2025

Improper permission check in ZooKeeper AdminServer lets authorized clients to run snapshot and restore command with insufficient permissions. This issue affects Apache ZooKeeper:…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-48459

Published Sep 24, 2025

Deserialization of Untrusted Data vulnerability in Apache IoTDB. This issue affects Apache IoTDB: from 1.0.0 before 2.0.5. Users are recommended to upgrade to version 2.0.5, whi…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-48392

Published Sep 24, 2025

A vulnerability in Apache IoTDB. This issue affects Apache IoTDB: from 1.3.3 through 1.3.4, from 2.0.1-beta through 2.0.4. Users are recommended to upgrade to version 2.0.5, whi…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-59328

Published Sep 15, 2025

A vulnerability in Apache Fory allows a remote attacker to cause a Denial of Service (DoS). The issue stems from the insecure deserialization of untrusted data. An attacker can su…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-48208

Published Sep 9, 2025

Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection') vulnerability in Apache HertzBeat . The attacker needs to have an authenticated ac…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2025-24404

Published Sep 9, 2025

XML Injection RCE by parse http sitemap xml response vulnerability in Apache HertzBeat. The attacker needs to have an authenticated account with access, and add monito…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort
Showing 476-500 of 3,127 CVEsPage 20 of 126