Skip to main content

Vendor archive

apache CVEs

Beta · best-effort

3,127 CVEs tagged to vendor apache564 Critical, 1,119 High, 1,345 Medium, 97 Low, 2 Unrated.

CVE-2025-58782

Published Sep 8, 2025

Deserialization of Untrusted Data vulnerability in Apache Jackrabbit Core and Apache Jackrabbit JCR Commons. This issue affects Apache Jackrabbit Core: from 1.0.0 through 2.22.1;…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-43166

Published Sep 3, 2025

Incorrect Default Permissions vulnerability in Apache DolphinScheduler. This issue affects Apache DolphinScheduler: before 3.2.2. Users are recommended to upgrade to version 3.3…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-43115

Published Sep 3, 2025

Improper Input Validation vulnerability in Apache DolphinScheduler. An authenticated user can execute any shell script server by alert script. This issue affects Apache DolphinS…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2025-26467

Published Aug 25, 2025

Privilege Defined With Unsafe Actions vulnerability in Apache Cassandra. An user with MODIFY permission ON ALL KEYSPACES can escalate privileges to superuser within a targeted Cas…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2025-54813

Published Aug 22, 2025

Improper Output Neutralization for Logs vulnerability in Apache Log4cxx. When using JSONLayout, not all payload bytes are properly escaped. If an attacker-supplied message contai…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-54812

Published Aug 22, 2025

Improper Output Neutralization for Logs vulnerability in Apache Log4cxx. When using HTMLLayout, logger names are not properly escaped when writing out to the HTML file. If untru…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2024-48988

Published Aug 22, 2025

SQL Injection vulnerability in Apache StreamPark. This issue affects Apache StreamPark: from 2.1.4 before 2.1.6. Users are recommended to upgrade to version 2.1.6, which fixes t…

CVSS 7.6 · High
Vendor/product tagsBeta · best-effort

CVE-2025-54988

Published Aug 20, 2025

Critical XXE in Apache Tika (tika-parser-pdf-module) in Apache Tika 1.13 through and including 3.2.1 on all platforms allows an attacker to carry out XML External Entity injection…

CVSS 8.4 · High
evidence mentions
6
Buzz score
27.5
Vendor/product tagsBeta · best-effort

CVE-2024-39954

Published Aug 20, 2025

CWE-918 Server-Side Request Forgery (SSRF) in eventmesh-runtime module in WebhookUtil.java on windows\linux\mac os e.g. allows the attacker can abuse functionality on the server t…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-53192

Published Aug 18, 2025

** UNSUPPORTED WHEN ASSIGNED ** Improper Neutralization of Expression/Command Delimiters vulnerability in Apache Commons OGNL. This issue affects Apache Commons OGNL: all version…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2025-54466

Published Aug 15, 2025

Improper Control of Generation of Code ('Code Injection') vulnerability leading to a possible RCE in Apache OFBiz scrum plugin. This issue affects Apache OFBiz: before 24.09.02 o…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-55675

Published Aug 14, 2025

Apache Superset contains an improper access control vulnerability in its /explore endpoint. A missing authorization check allows an authenticated user to discover metadata about d…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-55674

Published Aug 14, 2025

A bypass of the DISALLOWED_SQL_FUNCTIONS security feature in Apache Superset allows for the execution of blocked SQL functions. An attacker can use a special inline block to circu…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-55673

Published Aug 14, 2025

When a guest user accesses a chart in Apache Superset, the API response from the /chart/data endpoint includes a query field in its payload. This field contains the underlying que…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-55672

Published Aug 14, 2025

A stored Cross-Site Scripting (XSS) vulnerability exists in Apache Superset's chart visualization. An authenticated user with permissions to edit charts can inject a malicious pay…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-54472

Published Aug 14, 2025

Unlimited memory allocation in redis protocol parser in Apache bRPC (all versions < 1.14.1) on all platforms allows attackers to crash the service via network. Root Cause: In t…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-55668

Published Aug 13, 2025

Session Fixation vulnerability in Apache Tomcat via rewrite valve. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.7, from 10.1.0-M1 through 10.1.41, from 9.0.0.M1…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-48989

Published Aug 13, 2025

Improper Resource Shutdown or Release vulnerability in Apache Tomcat made Tomcat vulnerable to the made you reset attack. This issue affects Apache Tomcat: from 11.0.0-M1 through…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-53606

Published Aug 8, 2025

Deserialization of Untrusted Data vulnerability in Apache Seata (incubating). This issue affects Apache Seata (incubating): 2.4.0. Users are recommended to upgrade to version 2.…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-48913

Published Aug 8, 2025

If untrusted users are allowed to configure JMS for Apache CXF, previously they could use RMI or LDAP URLs, potentially leading to code execution capabilities. This interface is…

CVSS 9.8 · Critical
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2024-51775

Published Aug 3, 2025

Missing Origin Validation in WebSockets vulnerability in Apache Zeppelin. The attacker could access the Zeppelin server from another origin without any restriction, and get inter…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-52279

Published Aug 3, 2025

Improper Input Validation vulnerability in Apache Zeppelin. The fix for JDBC URL validation in CVE-2024-31864 did not account for URL encoded input. This issue affects Apache Zep…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-41177

Published Aug 3, 2025

Incomplete Blacklist to Cross-Site Scripting vulnerability in Apache Zeppelin. This issue affects Apache Zeppelin: before 0.12.0. Users are recommended to upgrade to version 0.1…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-24854

Published Jul 31, 2025

A carefully crafted request using the Image plugin could trigger an XSS vulnerability on Apache JSPWiki, which could allow the attacker to execute javascript in the victim's bro…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-24853

Published Jul 31, 2025

A carefully crafted request when creating a header link using the wiki markup syntax, which could allow the attacker to execute javascript in the victim's browser and get some s…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 501-525 of 3,127 CVEsPage 21 of 126