Skip to main content

Vendor archive

apache CVEs

Beta · best-effort

3,142 CVEs tagged to vendor apache566 Critical, 1,128 High, 1,349 Medium, 97 Low, 2 Unrated.

CVE-2025-31650

Published Apr 28, 2025

Improper Input Validation vulnerability in Apache Tomcat. Incorrect error handling for some invalid HTTP priority headers resulted in incomplete clean-up of the failed request whi…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-27820

Published Apr 24, 2025

A bug in PSL validation logic in Apache HttpClient 5.4.x disables domain checks, affecting cookie management and host name verification. Discovered by the Apache HttpClient team.…

CVSS 7.5 · High
evidence mentions
5
Buzz score
34.4
Vendor/product tagsBeta · best-effort

CVE-2025-26413

Published Apr 22, 2025

Improper Input Validation vulnerability in Apache Kvrocks. The SETRANGE command didn't check if the `offset` input is a positive integer and use it as an index of a string. So it…

CVSS 7.5 · High
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2025-29953

Published Apr 18, 2025

Deserialization of Untrusted Data vulnerability in Apache ActiveMQ NMS OpenWire Client. This issue affects Apache ActiveMQ NMS OpenWire Client before 2.1.1 when performing connec…

CVSS 9.8 · Critical
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2024-56736

Published Apr 16, 2025

Server-Side Request Forgery (SSRF) vulnerability in Apache HertzBeat. This issue affects Apache HertzBeat (incubating): before 1.7.0. Users are recommended to upgrade to version…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-24859

Published Apr 14, 2025

A session management vulnerability exists in Apache Roller before version 6.1.5 where active user sessions are not properly invalidated after password changes. When a user's passw…

CVSS 2.1 · Low
evidence mentions
5
Buzz score
34.4
Vendor/product tagsBeta · best-effort

CVE-2025-27391

Published Apr 9, 2025

Insertion of Sensitive Information into Log File vulnerability in Apache ActiveMQ Artemis. All the values of the broker properties are logged when the org.apache.activemq.artemis.…

CVSS 6.8 · Medium
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2025-30677

Published Apr 9, 2025

Apache Pulsar contains multiple connectors for integrating with Apache Kafka. The Pulsar IO Apache Kafka Source Connector, Sink Connector, and Kafka Connect Adaptor Sink Connector…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-30473

Published Apr 7, 2025

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Airflow Common SQL Provider. When using the partition clause in SQLTa…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-53868

Published Apr 3, 2025

Apache Traffic Server allows request smuggling if chunked messages are malformed.  This issue affects Apache Traffic Server: from 9.2.0 through 9.2.9, from 10.0.0 through 10.…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-30676

Published Apr 1, 2025

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 18.12.19. Users are recommen…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-30177

Published Apr 1, 2025

Bypass/Injection vulnerability in Apache Camel in Camel-Undertow component under particular conditions. This issue affects Apache Camel: from 4.10.0 before 4.10.3, from 4.8.0 bef…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-56325

Published Apr 1, 2025

Authentication Bypass Issue If the path does not contain / and contain., authentication is not required. Expected Normal Request and Response Example curl -X POST -H "Content-T…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-30065

Published Apr 1, 2025

Schema parsing in the parquet-avro module of Apache Parquet 1.15.0 and previous versions allows bad actors to execute arbitrary code Users are recommended to upgrade to version…

CVSS 10.0 · Critical
evidence mentions
8
Buzz score
30.0
Vendor/product tagsBeta · best-effort

CVE-2025-29868

Published Apr 1, 2025

Private Data Structure Returned From A Public Method vulnerability in Apache Answer. This issue affects Apache Answer: through 1.4.2. If a user uses an externally referenced ima…

CVSS 6.5 · Medium
evidence mentions
4
Buzz score
26.1
Vendor/product tagsBeta · best-effort

CVE-2025-27427

Published Apr 1, 2025

A vulnerability exists in Apache ActiveMQ Artemis whereby a user with the createDurableQueue or createNonDurableQueue permission on an address can augment the routing-type support…

CVSS 2.3 · Low
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2025-30067

Published Mar 27, 2025

Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Kylin. If an attacker gets access to Kylin's system or project admin permission, the JDBC connec…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2024-48944

Published Mar 27, 2025

Server-Side Request Forgery (SSRF) vulnerability in Apache Kylin. Through a kylin server, an attacker may forge a request to invoke "/kylin/api/xxx/diag" api on another internal h…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-53679

Published Mar 25, 2025

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache VCL in the User Lookup form. A user with sufficient rights to be able…

CVSS 8.4 · High
Vendor/product tagsBeta · best-effort

CVE-2024-53678

Published Mar 25, 2025

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache VCL. Users can modify form data submitted when requesting a new Block…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-30474

Published Mar 23, 2025

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Commons VFS. The FtpFileObject class can throw an exception when a file is not found, revealing…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-27553

Published Mar 23, 2025

Relative Path Traversal vulnerability in Apache Commons VFS before 2.10.0. The FileObject API in Commons VFS has a 'resolveFile' method that takes a 'scope' parameter. Specifying…

CVSS 7.5 · High
evidence mentions
3
Buzz score
25.4
Vendor/product tagsBeta · best-effort

CVE-2025-26796

Published Mar 22, 2025

** UNSUPPORTED WHEN ASSIGNED ** Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache Oozie. This issue affects Apache Oozi…

CVSS 5.4 · Medium
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2025-27888

Published Mar 20, 2025

Severity: medium (5.8) / important Server-Side Request Forgery (SSRF), Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'), URL Redirection to Un…

CVSS 5.8 · Medium
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort
Showing 601-625 of 3,142 CVEsPage 25 of 126