🔍 Search Results

Searching CVE for "apache"

100 result(s)
CVE-2025-66168 MEDIUM 5.4

Apache ActiveMQ has an integer overflow vulnerability in MQTT packet handling that allows malformed packets to cause unexpected broker behavior. This affects ActiveMQ versions before 5.19.2, 6.0.0 to ...

Published: Mar 4, 2026

CVE-2026-27636 HIGH 8.8

This vulnerability allows authenticated users to upload .htaccess or .user.ini files to FreeScout help desk systems, enabling remote code execution on Apache servers with AllowOverride All configurati...

Published: Feb 25, 2026

CVE-2026-23983 MEDIUM 6.5

Authenticated users in Apache Superset can exploit a disabled-by-default tagging feature to retrieve sensitive user data including password hashes and email addresses. This affects all Apache Superset...

Published: Feb 24, 2026

CVE-2026-23980 MEDIUM 6.5

This SQL injection vulnerability in Apache Superset allows authenticated users with read access to execute arbitrary SQL commands through the sqlExpression or where parameters. The vulnerability enabl...

Published: Feb 24, 2026

CVE-2024-56373 HIGH 8.4

This vulnerability allows DAG authors with existing permissions to manipulate Airflow's database to execute arbitrary code in the web-server context when users view historical task information. This l...

Published: Feb 24, 2026

CVE-2026-23552 CRITICAL 9.1

The CVE-2026-23552 vulnerability allows attackers to bypass tenant isolation in Apache Camel Keycloak component by using JWT tokens from unauthorized Keycloak realms. This affects Apache Camel users r...

Published: Feb 23, 2026

CVE-2025-65995 MEDIUM 6.5

This vulnerability in Apache Airflow allows authenticated users with DAG view permissions to potentially see sensitive information like secrets when a DAG fails during parsing. The error-reporting UI ...

Published: Feb 21, 2026

CVE-2026-27134 HIGH 8.1

This vulnerability allows unauthorized authentication in Strimzi Kafka clusters when using custom CA certificates with multi-stage chains. Attackers with certificates signed by any CA in the chain can...

Published: Feb 21, 2026

CVE-2026-27133 MEDIUM 5.9

This vulnerability in Strimzi allows Kafka Connect or Kafka MirrorMaker 2 operands to incorrectly trust all certificates in a CA chain when connecting to Kafka brokers, rather than only trusting the f...

Published: Feb 20, 2026

CVE-2026-24734

This vulnerability in Apache Tomcat Native and Apache Tomcat allows attackers to bypass certificate revocation checks when using OCSP responders. Improper input validation means OCSP responses aren't ...

Published: Feb 17, 2026

CVE-2025-66614

This vulnerability allows attackers to bypass client certificate authentication in Apache Tomcat when multiple virtual hosts are configured with different TLS authentication requirements. By sending m...

Published: Feb 17, 2026

CVE-2026-25087 HIGH 7.0

A Use After Free vulnerability in Apache Arrow C++ allows memory corruption when reading Arrow IPC files with pre-buffering enabled. This affects C++ applications using Arrow versions 15.0.0 through 2...

Published: Feb 17, 2026

CVE-2025-33042 HIGH 7.3

This vulnerability allows remote code execution when Apache Avro Java SDK processes untrusted Avro schemas. Attackers can inject malicious code that gets executed during specific record generation. Al...

Published: Feb 13, 2026

CVE-2026-26214 HIGH 7.4

This vulnerability in the Galaxy FDS Android SDK disables TLS hostname verification, allowing man-in-the-middle attackers to intercept and modify communications between Android apps and Xiaomi's cloud...

Published: Feb 12, 2026

CVE-2026-25999 HIGH 7.1

CVE-2026-25999 is an improper access control vulnerability in Klaw (Apache Kafka management portal) that allows unauthorized users to reset or delete metadata for any tenant by sending crafted request...

Published: Feb 11, 2026

CVE-2026-23901 LOW 2.5

This CVE describes an observable timing discrepancy vulnerability in Apache Shiro authentication. Attackers can use timing differences to distinguish between non-existent users and incorrect passwords...

Published: Feb 10, 2026

CVE-2026-23906 CRITICAL 9.8

This authentication bypass vulnerability in Apache Druid allows attackers to gain unauthorized access by exploiting LDAP anonymous bind configurations. Organizations using Druid with basic security ex...

Published: Feb 10, 2026

CVE-2026-24343 HIGH 8.8

This XPath injection vulnerability in Apache HertzBeat allows attackers to manipulate XPath queries by injecting malicious data, potentially accessing or modifying sensitive information. It affects al...

Published: Feb 10, 2026

CVE-2026-24098 MEDIUM 6.5

This CVE describes an information disclosure vulnerability in Apache Airflow where authenticated users with access to specific DAGs can view import errors from other DAGs they shouldn't have access to...

Published: Feb 9, 2026

CVE-2026-22922 MEDIUM 6.5

Apache Airflow versions 3.1.0 through 3.1.6 contain an authorization flaw where authenticated users with custom permissions limited to task access can view task logs without proper authorization. This...

Published: Feb 9, 2026

CVE-2026-23903 MEDIUM 5.3

This CVE describes an authentication bypass vulnerability in Apache Shiro where attackers can access protected static files by changing the case of filenames in requests. It affects Apache Shiro versi...

Published: Feb 9, 2026

CVE-2026-24735 HIGH 7.5

An unauthenticated API endpoint in Apache Answer exposes full revision history for deleted content, allowing unauthorized users to retrieve sensitive information. This affects all Apache Answer instal...

Published: Feb 4, 2026

CVE-2026-23794 MEDIUM 6.8

This reflected XSS vulnerability in Apache Syncope's Enduser Login page allows attackers to steal user credentials by tricking legitimate users into clicking malicious links. It affects Apache Syncope...

Published: Feb 3, 2026

CVE-2026-23795 MEDIUM 4.9

This CVE describes an XXE vulnerability in Apache Syncope Console that allows administrators with Keymaster parameter privileges to inject malicious XML. Successful exploitation could lead to sensitiv...

Published: Feb 3, 2026

CVE-2026-24806

This CVE describes a code injection vulnerability in the quick-media library's SVG plugin when processing PNG files. Attackers can execute arbitrary code by crafting malicious PNG images. This affects...

Published: Jan 27, 2026

CVE-2026-24807

This vulnerability allows attackers to bypass cryptographic signature verification in the quick-media library's SVG processing module. Attackers could potentially inject malicious content into process...

Published: Jan 27, 2026

CVE-2026-1464

An integer overflow vulnerability in the Apache Commons Compress TarUtils module used by AppManager allows attackers to cause denial of service or potentially execute arbitrary code by crafting malici...

Published: Jan 27, 2026

CVE-2026-24656 LOW 3.7

Apache Karaf Decanter's log socket collector has a deserialization vulnerability on port 4560 without authentication. Attackers can bypass allowed classes configuration to send malicious data, potenti...

Published: Jan 26, 2026

CVE-2025-27821 HIGH 7.3

This CVE describes an out-of-bounds write vulnerability in Apache Hadoop HDFS native client that could allow attackers to execute arbitrary code or cause denial of service. It affects Hadoop installat...

Published: Jan 26, 2026

CVE-2026-22022 HIGH 8.2

Apache Solr deployments using RuleBasedAuthorizationPlugin with specific configurations are vulnerable to unauthorized API access. Attackers can bypass authorization controls to read sensitive configu...

Published: Jan 21, 2026

CVE-2026-22444 HIGH 7.1

This vulnerability in Apache Solr allows attackers to bypass path restrictions and read unauthorized files from the filesystem when creating new cores. On Windows systems, this can lead to NTLM hash d...

Published: Jan 21, 2026

CVE-2026-23529 HIGH 7.7

The Kafka Connect BigQuery Connector prior to version 2.11.0 has an arbitrary file read vulnerability in credential configuration processing. Attackers can exploit this by providing malicious credenti...

Published: Jan 16, 2026

CVE-2025-68438 HIGH 7.5

This vulnerability in Apache Airflow exposes sensitive values like passwords and API keys in cleartext in the Rendered Templates UI when template fields exceed maximum length. It affects Airflow users...

Published: Jan 16, 2026

CVE-2025-68675 HIGH 7.5

Apache Airflow versions before 3.1.6 expose proxy credentials in logs when connections contain proxy URLs with embedded authentication. This allows attackers with log access to steal credentials. All ...

Published: Jan 16, 2026

CVE-2025-60021 CRITICAL 9.8

This CVE describes a remote command injection vulnerability in Apache bRPC's heap profiler service. Attackers can execute arbitrary commands by injecting malicious parameters into the /pprof/heap endp...

Published: Jan 16, 2026

CVE-2026-22265 HIGH 7.5

CVE-2026-22265 is a command injection vulnerability in Roxy-WI web interface versions prior to 8.2.8.2 that allows authenticated users to execute arbitrary system commands through the log viewing func...

Published: Jan 15, 2026

CVE-2025-66169 MEDIUM 5.3

This CVE describes a Cypher Injection vulnerability in Apache Camel's camel-neo4j component, allowing attackers to execute arbitrary Cypher queries against Neo4j databases. Affected users are those ru...

Published: Jan 14, 2026

CVE-2025-68493 HIGH 8.1

This CVE describes a Missing XML Validation vulnerability in Apache Struts that allows attackers to inject malicious XML content. It affects Apache Struts versions from 2.0.0 through 6.1.0, potentiall...

Published: Jan 11, 2026

CVE-2025-52435 HIGH 7.5

This vulnerability in Apache NimBLE allows an attacker to downgrade encrypted Bluetooth Low Energy connections to unencrypted state after a Pause Encryption procedure, enabling eavesdropping on subseq...

Published: Jan 10, 2026

CVE-2025-53470 LOW 3.1

An out-of-bounds read vulnerability in Apache NimBLE's HCI H4 driver allows a malicious or malfunctioning Bluetooth controller to trigger invalid memory reads. This affects all Apache NimBLE versions ...

Published: Jan 10, 2026

CVE-2025-53477 HIGH 7.5

A NULL pointer dereference vulnerability in Apache NimBLE's Bluetooth stack occurs when HCI connection completion or command transmission buffers lack proper validation. This could cause crashes or in...

Published: Jan 10, 2026

CVE-2025-62235 HIGH 8.1

This vulnerability allows attackers to bypass authentication in Apache NimBLE by sending specially crafted Security Request packets. An attacker can remove existing secure bonds and force re-bonding w...

Published: Jan 10, 2026

CVE-2025-66518 HIGH 8.8

This vulnerability allows clients accessing Apache Kyuubi Server to bypass the server-side configuration that restricts which local directories can be accessed. Attackers can read arbitrary local file...

Published: Jan 5, 2026

CVE-2025-66524 HIGH 8.8

This vulnerability allows remote code execution on Apache NiFi systems through unsafe Java deserialization in the GetAsanaObject Processor. Attackers can exploit it by injecting malicious objects into...

Published: Dec 19, 2025

CVE-2025-68161 MEDIUM 4.8

This vulnerability in Apache Log4j Core allows man-in-the-middle attackers to intercept or redirect encrypted log traffic when TLS hostname verification fails, even when configured to verify. It affec...

Published: Dec 18, 2025

CVE-2025-66029 HIGH 7.6

Open OnDemand versions 4.0.8 and earlier have a vulnerability where the Apache proxy passes sensitive headers to origin servers. This allows malicious users to set up servers on compute nodes that can...

Published: Dec 17, 2025

CVE-2025-67895 CRITICAL 9.8

This vulnerability allows authenticated DAG authors in Apache Airflow 2 to perform remote code execution in the webserver context via an improperly exposed Edge3 provider API. Only systems running Air...

Published: Dec 17, 2025

CVE-2025-66388 MEDIUM 6.5

This vulnerability in Apache Airflow allows authenticated users with UI access to view secret values in rendered templates due to improper redaction. This exposes sensitive secrets like passwords, API...

Published: Dec 15, 2025

CVE-2025-53960 MEDIUM 5.9

Apache StreamPark versions 2.0.0 through 2.1.6 use user passwords as JWT signing keys, allowing attackers who capture tokens to brute-force passwords offline or forge tokens if passwords are known. Th...

Published: Dec 12, 2025

CVE-2025-54947 CRITICAL 9.8

Apache StreamPark versions 2.0.0 through 2.1.6 use a hard-coded encryption key, allowing attackers to decrypt sensitive data or forge encrypted information through reverse engineering. This affects al...

Published: Dec 12, 2025

CVE-2025-54981 HIGH 7.5

This vulnerability in Apache StreamPark uses weak encryption (AES-ECB mode) and a weak random number generator for encrypting sensitive data like JWT tokens. Attackers could potentially decrypt authen...

Published: Dec 12, 2025

CVE-2025-26866 HIGH 8.8

This CVE describes a remote code execution vulnerability in Apache HugeGraph's PD store where a malicious Raft node can exploit insecure Hessian deserialization. Attackers can execute arbitrary code o...

Published: Dec 12, 2025

CVE-2025-58130 CRITICAL 9.1

CVE-2025-58130 is an insufficiently protected credentials vulnerability in Apache Fineract that could allow attackers to access sensitive authentication data. This affects all Apache Fineract installa...

Published: Dec 12, 2025

CVE-2025-58137 HIGH 8.1

This CVE describes an authorization bypass vulnerability in Apache Fineract where attackers can manipulate user-controlled keys to access unauthorized resources. It affects all Apache Fineract install...

Published: Dec 12, 2025

CVE-2025-23408 MEDIUM 6.5

Apache Fineract versions through 1.10.1 have weak password requirements that allow attackers to set or maintain easily guessable passwords. This affects all organizations using vulnerable Fineract ins...

Published: Dec 12, 2025

CVE-2025-66675 HIGH 8.2

This CVE describes a Denial of Service vulnerability in Apache Struts where specially crafted multipart requests can cause file leaks leading to disk exhaustion. Attackers can exploit this to fill up ...

Published: Dec 10, 2025

CVE-2025-66623 HIGH 7.4

This vulnerability in Strimzi Kafka Operator versions 0.47.0 through 0.49.0 creates an overly permissive Kubernetes Role that grants Kafka Connect and Kafka MirrorMaker 2 pods GET access to all Secret...

Published: Dec 5, 2025

CVE-2025-58098 HIGH 8.3

This vulnerability in Apache HTTP Server allows remote code execution when Server Side Includes (SSI) is enabled with mod_cgid. Attackers can inject shell commands through improperly escaped query str...

Published: Dec 5, 2025

CVE-2025-59775 HIGH 7.5

This SSRF vulnerability in Apache HTTP Server on Windows allows attackers to force the server to make requests to malicious servers, potentially leaking NTLM authentication hashes. It affects Windows ...

Published: Dec 5, 2025

CVE-2025-65082 MEDIUM 6.5

This vulnerability allows attackers to manipulate CGI program behavior by injecting malicious environment variables through Apache configuration. It affects Apache HTTP Server versions 2.4.0 through 2...

Published: Dec 5, 2025

CVE-2025-66200 MEDIUM 5.4

This vulnerability allows users with htaccess file access to bypass mod_userdir+suexec restrictions via the RequestHeader directive, potentially causing CGI scripts to execute under unintended user ID...

Published: Dec 5, 2025

CVE-2025-55753 HIGH 7.5

An integer overflow in Apache HTTP Server's ACME certificate renewal process causes the backoff timer to reset to zero after approximately 30 days of consecutive renewal failures. This leads to immedi...

Published: Dec 5, 2025

CVE-2025-66516 HIGH 8.4

This critical XXE vulnerability in Apache Tika allows attackers to perform XML External Entity injection via crafted XFA files within PDF documents. It affects all platforms running vulnerable version...

Published: Dec 4, 2025

CVE-2025-13516 HIGH 8.1

The SureMail WordPress plugin allows unauthenticated attackers to upload malicious PHP files through public forms that email attachments, leading to remote code execution. This affects WordPress sites...

Published: Dec 2, 2025

CVE-2025-64775 HIGH 7.5

This vulnerability in Apache Struts allows attackers to cause a denial of service through disk exhaustion by exploiting a file leak in multipart request processing. It affects all Apache Struts instal...

Published: Dec 1, 2025

CVE-2025-59792 MEDIUM 5.3

The CVE-2025-59792 vulnerability in Apache Kvrocks allows attackers to obtain plaintext credentials through the MONITOR command. This affects all Apache Kvrocks deployments running versions 1.0.0 thro...

Published: Nov 28, 2025

CVE-2025-59790 MEDIUM 5.4

CVE-2025-59790 is an improper privilege management vulnerability in Apache Kvrocks that could allow authenticated users to escalate privileges beyond their intended permissions. This affects Apache Kv...

Published: Nov 28, 2025

CVE-2025-54057 MEDIUM 6.1

This CVE describes a cross-site scripting (XSS) vulnerability in Apache SkyWalking where malicious script tags can be injected into web pages. It affects all Apache SkyWalking installations running ve...

Published: Nov 27, 2025

CVE-2025-59302 MEDIUM 4.7

Apache CloudStack contains a code injection vulnerability in six administrative APIs that allows authenticated administrators to execute arbitrary JavaScript code. This affects CloudStack versions 4.1...

Published: Nov 27, 2025

CVE-2025-59454 MEDIUM 4.3

This CVE describes an information disclosure vulnerability in Apache CloudStack where authorized users could occasionally access data beyond their intended permissions through specific APIs. The vulne...

Published: Nov 27, 2025

CVE-2025-59390 CRITICAL 9.8

Apache Druid's Kerberos authenticator uses a weak random fallback secret when cookieSignatureSecret isn't explicitly configured, allowing attackers to potentially forge authentication cookies and bypa...

Published: Nov 26, 2025

CVE-2025-62728 MEDIUM 5.4

This SQL injection vulnerability in Apache Hive Metastore Server allows authorized users to execute arbitrary SQL commands when calling Thrift APIs to delete column statistics. It affects Hive version...

Published: Nov 26, 2025

CVE-2025-65998 HIGH 7.5

Apache Syncope versions before 3.0.15 and 4.0.3 use a hard-coded AES encryption key for password storage when configured to encrypt passwords in the database. This allows attackers who gain database a...

Published: Nov 24, 2025

CVE-2025-64407 MEDIUM 5.3

Apache OpenOffice versions through 4.1.15 have an authorization vulnerability where specially crafted documents can automatically load external links without user permission. This allows attackers to ...

Published: Nov 12, 2025

CVE-2025-59118 HIGH 7.3

This vulnerability allows attackers to upload malicious files to Apache OFBiz servers, potentially leading to remote code execution or server compromise. It affects all Apache OFBiz installations befo...

Published: Nov 12, 2025

CVE-2025-61623 MEDIUM 6.5

This CVE describes a reflected cross-site scripting (XSS) vulnerability in Apache OFBiz that allows attackers to inject malicious scripts into web pages. The vulnerability affects users of Apache OFBi...

Published: Nov 12, 2025

CVE-2025-64402 MEDIUM 6.5

Apache OpenOffice versions through 4.1.15 have a missing authorization vulnerability where documents containing OLE objects with external links can automatically load those external files without user...

Published: Nov 12, 2025

CVE-2025-64403 HIGH 8.1

Apache OpenOffice Calc has a missing authorization vulnerability that allows attackers to craft documents with external data source links that load without user prompts. This affects all Apache OpenOf...

Published: Nov 12, 2025

CVE-2025-64404 HIGH 7.5

Apache OpenOffice versions through 4.1.15 have a missing authorization vulnerability that allows attackers to craft documents that automatically load external files without user permission. This occur...

Published: Nov 12, 2025

CVE-2025-64405 HIGH 7.5

Apache OpenOffice versions through 4.1.15 have a missing authorization vulnerability where specially crafted Calc spreadsheets containing DDE links can automatically load external files without user c...

Published: Nov 12, 2025

CVE-2025-64406 MEDIUM 4.3

An out-of-bounds write vulnerability in Apache OpenOffice allows attackers to craft malicious documents that could crash the program or corrupt memory. This affects all users running Apache OpenOffice...

Published: Nov 12, 2025

CVE-2025-64401 HIGH 7.5

Apache OpenOffice versions through 4.1.15 contain a missing authorization vulnerability where documents with floating frames linked to external files can load those external resources without user con...

Published: Nov 12, 2025

CVE-2025-62232 HIGH 7.5

This vulnerability in Apache APISIX exposes basic authentication credentials (usernames and passwords) in plaintext within error logs when log levels are set to INFO or DEBUG. Any system using APISIX ...

Published: Oct 31, 2025

CVE-2024-58273 HIGH 7.8

Nagios Log Server versions before 2024R1.0.2 contain a local privilege escalation vulnerability. An attacker who can execute commands as the Apache web user or backend shell user can escalate privileg...

Published: Oct 30, 2025

CVE-2021-47700 HIGH 7.8

Nagios XI versions before 5.8.7 use insecure permissions on a temporary directory for Highcharts exports, allowing local or co-hosted processes to read, modify, or delete exported files. This vulnerab...

Published: Oct 30, 2025

CVE-2025-54941 MEDIUM 4.6

This CVE describes an OS command injection vulnerability in Apache Airflow's example_dag_decorator where unvalidated parameters could allow UI users to redirect to malicious servers and execute code o...

Published: Oct 30, 2025

CVE-2025-62402 MEDIUM 5.4

This vulnerability allows authenticated API users to execute arbitrary Dag code in the context of the api-server when deployed in environments where Dag files are accessible. It affects Apache Airflow...

Published: Oct 30, 2025

CVE-2025-62503 MEDIUM 4.6

This vulnerability allows authenticated users with CREATE privilege but no UPDATE privilege for Pools, Connections, and Variables to modify existing records through the bulk create API with overwrite ...

Published: Oct 30, 2025

CVE-2025-55752 HIGH 7.5

A path traversal vulnerability in Apache Tomcat allows attackers to bypass security constraints protecting sensitive directories like /WEB-INF/ and /META-INF/. This affects Tomcat versions 9.0.0.M11 t...

Published: Oct 27, 2025

CVE-2025-55754 CRITICAL 9.6

Apache Tomcat fails to escape ANSI escape sequences in log messages, allowing attackers to inject malicious sequences when Tomcat runs in a console supporting ANSI escape sequences (primarily Windows)...

Published: Oct 27, 2025

CVE-2025-47410 HIGH 8.8

Apache Geode's Management and Monitoring REST API is vulnerable to Cross-Site Request Forgery (CSRF) attacks via GET requests. An attacker who obtains a user's Geode session credentials can execute ma...

Published: Oct 18, 2025

CVE-2025-61581 HIGH 7.5

This CVE describes an Inefficient Regular Expression Complexity (ReDoS) vulnerability in Apache Traffic Control's Traffic Router management interface. Attackers with access to this interface can craft...

Published: Oct 16, 2025

CVE-2025-54539 CRITICAL 9.8

A deserialization vulnerability in Apache ActiveMQ NMS AMQP Client allows malicious AMQP servers to execute arbitrary code on client systems when connecting to untrusted servers. This affects all vers...

Published: Oct 16, 2025

CVE-2025-55039 MEDIUM 6.5

Apache Spark versions before 3.4.4, 3.5.2, and 4.0.0 use an insecure default cipher (AES/CTR/NoPadding) for RPC encryption when spark.network.crypto.enabled is true, allowing man-in-the-middle attacke...

Published: Oct 15, 2025

CVE-2025-46581 CRITICAL 9.8

ZTE's ZXCDN product has a critical Apache Struts vulnerability allowing unauthenticated remote code execution. Attackers can execute arbitrary commands with non-root privileges on affected systems. Th...

Published: Oct 14, 2025

CVE-2025-62228 HIGH 8.8

Apache Flink CDC 3.4.0 contains a SQL injection vulnerability that allows authenticated database users to execute arbitrary SQL commands by crafting malicious database or table names. This affects org...

Published: Oct 9, 2025

CVE-2025-61734 HIGH 7.5

This vulnerability in Apache Kylin allows unauthorized external parties to access sensitive files or directories if administrative access controls are insufficient. It affects Apache Kylin versions 4....

Published: Oct 2, 2025

CVE-2025-61735 HIGH 7.3

This CVE describes a Server-Side Request Forgery (SSRF) vulnerability in Apache Kylin that allows attackers to make unauthorized requests from the server to internal or external systems. It affects Ap...

Published: Oct 2, 2025

CVE-2025-61733 HIGH 7.5

This CVE describes an authentication bypass vulnerability in Apache Kylin that allows attackers to access protected functionality without proper credentials. It affects all Apache Kylin deployments ru...

Published: Oct 2, 2025

CVE-2025-59954 CRITICAL 9.8

This vulnerability allows remote attackers to execute arbitrary code on Knowage servers by exploiting unsafe JXPathContext usage in MetaService.java. It affects all Knowage deployments running version...

Published: Sep 30, 2025