Skip to main content

Vendor archive

apache CVEs

Beta · best-effort

3,142 CVEs tagged to vendor apache566 Critical, 1,128 High, 1,349 Medium, 97 Low, 2 Unrated.

CVE-2025-52434

Published Jul 10, 2025

Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability in Apache Tomcat when using the APR/Native connector. This was particular…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-53020

Published Jul 10, 2025

Late Release of Memory after Effective Lifetime vulnerability in Apache HTTP Server. This issue affects Apache HTTP Server: from 2.4.17 up to 2.4.63. Users are recommended to up…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-49812

Published Jul 10, 2025

In some mod_ssl configurations on Apache HTTP Server versions through to 2.4.63, an HTTP desynchronisation attack allows a man-in-the-middle attacker to hijack an HTTP session via…

CVSS 7.4 · High
Vendor/product tagsBeta · best-effort

CVE-2025-49630

Published Jul 10, 2025

In certain proxy configurations, a denial of service attack against Apache HTTP Server versions 2.4.26 through to 2.4.63 can be triggered by untrusted clients causing an assertion…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-23048

Published Jul 10, 2025

In some mod_ssl configurations on Apache HTTP Server 2.4.35 through to 2.4.63, an access control bypass by trusted clients is possible using TLS 1.3 session resumption. Configura…

CVSS 9.1 · Critical
evidence mentions
4
Buzz score
27.6
Vendor/product tagsBeta · best-effort

CVE-2024-47252

Published Jul 10, 2025

Insufficient escaping of user-supplied data in mod_ssl in Apache HTTP Server 2.4.63 and earlier allows an untrusted SSL/TLS client to insert escape characters into log files in so…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-43394

Published Jul 10, 2025

Server-Side Request Forgery (SSRF) in Apache HTTP Server on Windows allows to potentially leak NTLM hashes to a malicious server via  mod_rewrite or apache expressions that pass u…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-43204

Published Jul 10, 2025

SSRF in Apache HTTP Server with mod_proxy loaded allows an attacker to send outbound proxy requests to a URL controlled by the attacker.  Requires an unlikely configuration where…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-42516

Published Jul 10, 2025

HTTP response splitting in the core of Apache HTTP Server allows an attacker who can manipulate the Content-Type response headers of applications hosted or proxied by the server c…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-27446

Published Jul 6, 2025

Incorrect Permission Assignment for Critical Resource vulnerability in Apache APISIX(java-plugin-runner). Local listening file permissions in APISIX plugin runner allow a local a…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2025-46647

Published Jul 2, 2025

A vulnerability of plugin openid-connect in Apache APISIX. This vulnerability will only have an impact if all of the following conditions are met: 1. Use the openid-connect plugi…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-35164

Published Jul 2, 2025

The terminal emulator of Apache Guacamole 1.5.5 and older does not properly validate console codes received from servers via text-based protocols like SSH. If a malicious user has…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-32897

Published Jun 28, 2025

Deserialization of Untrusted Data vulnerability in Apache Seata (incubating). This security vulnerability is the same as CVE-2024-47552, but the version range described in the CV…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-50213

Published Jun 24, 2025

Failure to Sanitize Special Elements into a Different Plane (Special Element Injection) vulnerability in Apache Airflow Providers Snowflake. This issue affects Apache Airflow Pro…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-32896

Published Jun 19, 2025

# Summary Unauthorized users can perform Arbitrary File Read and Deserialization attack by submit job using restful api-v1. # Details Unauthorized users can access `/hazelcast/r…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-49763

Published Jun 19, 2025

ESI plugin does not have the limit for maximum inclusion depth, and that allows excessive memory consumption if malicious instructions are inserted. Users can use a new setting f…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-31698

Published Jun 19, 2025

ACL configured in ip_allow.config or remap.config does not use IP addresses that are provided by PROXY protocol. Users can use a new setting (proxy.config.acl.subjects) to choose…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-49125

Published Jun 16, 2025

Authentication Bypass Using an Alternate Path or Channel vulnerability in Apache Tomcat.  When using PreResources or PostResources mounted other than at the root of the web applic…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-49124

Published Jun 16, 2025

Untrusted Search Path vulnerability in Apache Tomcat installer for Windows. During installation, the Tomcat installer for Windows used icacls.exe without specifying a full path.…

CVSS 8.4 · High
Vendor/product tagsBeta · best-effort

CVE-2025-48988

Published Jun 16, 2025

Allocation of Resources Without Limits or Throttling vulnerability in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.7, from 10.1.0-M1 through 10.1.…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-48976

Published Jun 16, 2025

Allocation of resources for multipart headers with insufficient limits enabled a DoS vulnerability in Apache Commons FileUpload. This issue affects Apache Commons FileUpload: fro…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-47869

Published Jun 16, 2025

Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability was discovered in Apache NuttX RTOS apps/exapmles/xmlrpc application. In this example applica…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-47868

Published Jun 16, 2025

Out-of-bounds Write resulting in possible Heap-based Buffer Overflow vulnerability was discovered in tools/bdf-converter font conversion utility that is part of Apache NuttX RTOS…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-30675

Published Jun 11, 2025

In Apache CloudStack, a flaw in access control affects the listTemplates and listIsos APIs. A malicious Domain Admin or Resource Admin can exploit this issue by intentionally spec…

CVSS 4.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-47849

Published Jun 10, 2025

A privilege escalation vulnerability exists in Apache CloudStack versions 4.10.0.0 through 4.20.0.0 where a malicious Domain Admin user in the ROOT domain can get the API key and…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort
Showing 551-575 of 3,142 CVEsPage 23 of 126