Skip to main content

Vendor archive

apache CVEs

Beta · best-effort

3,142 CVEs tagged to vendor apache566 Critical, 1,128 High, 1,349 Medium, 97 Low, 2 Unrated.

CVE-2025-54466

Published Aug 15, 2025

Improper Control of Generation of Code ('Code Injection') vulnerability leading to a possible RCE in Apache OFBiz scrum plugin. This issue affects Apache OFBiz: before 24.09.02 o…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-55675

Published Aug 14, 2025

Apache Superset contains an improper access control vulnerability in its /explore endpoint. A missing authorization check allows an authenticated user to discover metadata about d…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-55674

Published Aug 14, 2025

A bypass of the DISALLOWED_SQL_FUNCTIONS security feature in Apache Superset allows for the execution of blocked SQL functions. An attacker can use a special inline block to circu…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-55673

Published Aug 14, 2025

When a guest user accesses a chart in Apache Superset, the API response from the /chart/data endpoint includes a query field in its payload. This field contains the underlying que…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-55672

Published Aug 14, 2025

A stored Cross-Site Scripting (XSS) vulnerability exists in Apache Superset's chart visualization. An authenticated user with permissions to edit charts can inject a malicious pay…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-54472

Published Aug 14, 2025

Unlimited memory allocation in redis protocol parser in Apache bRPC (all versions < 1.14.1) on all platforms allows attackers to crash the service via network. Root Cause: In t…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-55668

Published Aug 13, 2025

Session Fixation vulnerability in Apache Tomcat via rewrite valve. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.7, from 10.1.0-M1 through 10.1.41, from 9.0.0.M1…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-48989

Published Aug 13, 2025

Improper Resource Shutdown or Release vulnerability in Apache Tomcat made Tomcat vulnerable to the made you reset attack. This issue affects Apache Tomcat: from 11.0.0-M1 through…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-53606

Published Aug 8, 2025

Deserialization of Untrusted Data vulnerability in Apache Seata (incubating). This issue affects Apache Seata (incubating): 2.4.0. Users are recommended to upgrade to version 2.…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-48913

Published Aug 8, 2025

If untrusted users are allowed to configure JMS for Apache CXF, previously they could use RMI or LDAP URLs, potentially leading to code execution capabilities. This interface is…

CVSS 9.8 · Critical
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2024-51775

Published Aug 3, 2025

Missing Origin Validation in WebSockets vulnerability in Apache Zeppelin. The attacker could access the Zeppelin server from another origin without any restriction, and get inter…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-52279

Published Aug 3, 2025

Improper Input Validation vulnerability in Apache Zeppelin. The fix for JDBC URL validation in CVE-2024-31864 did not account for URL encoded input. This issue affects Apache Zep…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-41177

Published Aug 3, 2025

Incomplete Blacklist to Cross-Site Scripting vulnerability in Apache Zeppelin. This issue affects Apache Zeppelin: before 0.12.0. Users are recommended to upgrade to version 0.1…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-24854

Published Jul 31, 2025

A carefully crafted request using the Image plugin could trigger an XSS vulnerability on Apache JSPWiki, which could allow the attacker to execute javascript in the victim's bro…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-24853

Published Jul 31, 2025

A carefully crafted request when creating a header link using the wiki markup syntax, which could allow the attacker to execute javascript in the victim's browser and get some s…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-54656

Published Jul 30, 2025

** UNSUPPORTED WHEN ASSIGNED ** Improper Output Neutralization for Logs vulnerability in Apache Struts. This issue affects Apache Struts Extras: before 2. When using LookupDispa…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-54090

Published Jul 23, 2025

A bug in Apache HTTP Server 2.4.64 results in all "RewriteCond expr ..." tests evaluating as "true". Users are recommended to upgrade to version 2.4.65, which fixes the issue.

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-50151

Published Jul 21, 2025

File access paths in configuration files uploaded by users with administrator access are not validated. This issue affects Apache Jena version up to 5.4.0. Users are recommended…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2025-49656

Published Jul 21, 2025

Users with administrator access can create databases files outside the files area of the Fuseki server. This issue affects Apache Jena version up to 5.4.0. Users are recommended…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-48795

Published Jul 15, 2025

Apache CXF stores large stream based messages as temporary files on the local filesystem. A bug was introduced which means that the entire temporary file is read into memory and t…

CVSS 5.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-53689

Published Jul 14, 2025

Blind XXE Vulnerabilities in jackrabbit-spi-commons and jackrabbit-core in Apache Jackrabbit < 2.23.2 due to usage of an unsecured document build to load privileges. Users are re…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-41169

Published Jul 12, 2025

The attacker can use the raft server protocol in an unauthenticated way. The attacker can see the server's resources, including directories and files. This issue affects Apache Z…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-48924

Published Jul 11, 2025

Uncontrolled Recursion vulnerability in Apache Commons Lang. This issue affects Apache Commons Lang: Starting with commons-lang:commons-lang 2.0 to 2.6, and, from org.apache.comm…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-53506

Published Jul 10, 2025

Uncontrolled Resource Consumption vulnerability in Apache Tomcat if an HTTP/2 client did not acknowledge the initial settings frame that reduces the maximum permitted concurrent s…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-52520

Published Jul 10, 2025

For some unlikely configurations of multipart upload, an Integer Overflow vulnerability in Apache Tomcat could lead to a DoS via bypassing of size limits. This issue affects Apac…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 526-550 of 3,142 CVEsPage 22 of 126