Skip to main content

Vendor archive

apache CVEs

Beta · best-effort

3,142 CVEs tagged to vendor apache566 Critical, 1,128 High, 1,349 Medium, 97 Low, 2 Unrated.

CVE-2024-54016

Published Mar 20, 2025

Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in Apache Seata (incubating). This issue affects Apache Seata (incubating): through <=2.2.0. Users…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-47552

Published Mar 20, 2025

Deserialization of Untrusted Data vulnerability in Apache Seata (incubating). This issue affects Apache Seata (incubating): from 2.0.0 before 2.2.0. Severity Justificati…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-27018

Published Mar 19, 2025

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Airflow MySQL Provider. When user triggered a DAG with dump_sql or lo…

CVSS 6.3 · Medium
evidence mentions
4
Buzz score
27.6
Vendor/product tagsBeta · best-effort

CVE-2025-27017

Published Mar 12, 2025

Apache NiFi 1.13.0 through 2.2.0 includes the username and password used to authenticate with MongoDB in the NiFi provenance events that MongoDB components generate during process…

CVSS 6.9 · Medium
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2025-27867

Published Mar 12, 2025

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache Felix HTTP Webconsole Plugin. This issue affects Apache Felix HTTP We…

CVSS 5.6 · Medium
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2025-29891

Published Mar 12, 2025

Bypass/Injection vulnerability in Apache Camel. This issue affects Apache Camel: from 4.10.0 before 4.10.2, from 4.8.0 before 4.8.5, from 3.10.0 before 3.22.4. Users are recomme…

CVSS 4.8 · Medium
evidence mentions
4
Buzz score
32.1
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2025-26865

Published Mar 10, 2025

Improper Neutralization of Special Elements Used in a Template Engine vulnerability in Apache OFBiz. This issue affects Apache OFBiz: from 18.12.17 before 18.12.18.   It's a reg…

CVSS 3.5 · Low
evidence mentions
5
Buzz score
30.9
Vendor/product tagsBeta · best-effort

CVE-2025-27636

Published Mar 9, 2025

Bypass/Injection vulnerability in Apache Camel components under particular conditions. This issue affects Apache Camel: from 4.10.0 through <= 4.10.1, from 4.8.0 through <= 4.8.4…

CVSS 5.6 · Medium
evidence mentions
8
Buzz score
42.0
Vendor/product tagsBeta · best-effort

CVE-2024-56196

Published Mar 6, 2025

Improper Access Control vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 10.0.0 through 10.0.3. Users are recommended to upgrade to version…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-56195

Published Mar 6, 2025

Improper Access Control vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 9.2.0 through 9.2.8, from 10.0.0 through 10.0.3. Users are recomme…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-38311

Published Mar 6, 2025

Improper Input Validation vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.11, from 9.0.0 through 9.2.8, from 10.0.0 throu…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-56202

Published Mar 6, 2025

Expected Behavior Violation vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 9.0.0 through 9.2.8, from 10.0.0 through 10.0.3. Users are rec…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-55532

Published Mar 3, 2025

Improper Neutralization of Formula Elements in Export CSV feature of Apache Ranger in Apache Ranger Version < 2.6.0. Users are recommended to upgrade to version 2.6.0, which fixes…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-24778

Published Mar 3, 2025

Improper privilege management in a REST interface allowed registered users to access unauthorized resources if the resource ID was know. This issue affects Apache StreamPipe…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-56180

Published Feb 14, 2025

CWE-502 Deserialization of Untrusted Data at the eventmesh-meta-raft plugin module in Apache EventMesh master branch without release version on windows\linux\mac os e.g. platforms…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-52577

Published Feb 14, 2025

In Apache Ignite versions from 2.6.0 and before 2.17.0, configured Class Serialization Filters are ignored for some Ignite endpoints. The vulnerability could be exploited if an at…

CVSS 9.5 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-46910

Published Feb 13, 2025

An authenticated user can perform XSS and potentially impersonate another user. This issue affects Apache Atlas versions 2.3.0 and earlier. Users are recommended to upgrade to v…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2024-32838

Published Feb 12, 2025

SQL Injection vulnerability in various API endpoints - offices, dashboards, etc. Apache Fineract versions 1.9 and before have a vulnerability that allows an authenticated attacker…

CVSS 9.4 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-25247

Published Feb 10, 2025

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache Felix Webconsole. This issue affects Apache Felix Webconsole 4.x up t…

CVSS 6.1 · Medium
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2025-25069

Published Feb 7, 2025

A Cross-Protocol Scripting vulnerability is found in Apache Kvrocks. Since Kvrocks didn't detect if "Host:" or "POST" appears in RESP requests, a valid HTTP request can also be s…

CVSS 6.5 · Medium
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2022-31764

Published Feb 6, 2025

The Lite UI of Apache ShardingSphere ElasticJob-UI allows an attacker to perform RCE by constructing a special JDBC URL of H2 database. This issue affects Apache ShardingSphere El…

CVSS 8.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-45626

Published Feb 6, 2025

Apache James server JMAP HTML to text plain implementation in versions below 3.8.2 and 3.7.6 is subject to unbounded memory consumption that can result in a denial of service. Us…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-37358

Published Feb 6, 2025

Similarly to CVE-2024-34055, Apache James is vulnerable to denial of service through the abuse of IMAP literals from both authenticated and unauthenticated users, which could be u…

CVSS 8.6 · High
Vendor/product tagsBeta · best-effort

CVE-2024-48019

Published Feb 4, 2025

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Files or Directories Accessible to External Parties vulnerability in Apache Doris. Application ad…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort
Showing 626-650 of 3,142 CVEsPage 26 of 126