Apache Security Vulnerabilities (CVEs)
Track 559 security vulnerabilities affecting Apache products and software. Get instant email alerts when new CVEs are discovered, automated security monitoring, and patch guidance.
The CVE-2025-59792 vulnerability in Apache Kvrocks allows attackers to obtain plaintext credentials through the MONITOR command. This affects all Apac...
Nov 28, 2025CVE-2025-59790 is an improper privilege management vulnerability in Apache Kvrocks that could allow authenticated users to escalate privileges beyond ...
Nov 28, 2025This CVE describes a cross-site scripting (XSS) vulnerability in Apache SkyWalking where malicious script tags can be injected into web pages. It affe...
Nov 27, 2025Apache CloudStack contains a code injection vulnerability in six administrative APIs that allows authenticated administrators to execute arbitrary Jav...
Nov 27, 2025This CVE describes an information disclosure vulnerability in Apache CloudStack where authorized users could occasionally access data beyond their int...
Nov 27, 2025Apache Druid's Kerberos authenticator uses a weak random fallback secret when cookieSignatureSecret isn't explicitly configured, allowing attackers to...
Nov 26, 2025This SQL injection vulnerability in Apache Hive Metastore Server allows authorized users to execute arbitrary SQL commands when calling Thrift APIs to...
Nov 26, 2025Apache Syncope versions before 3.0.15 and 4.0.3 use a hard-coded AES encryption key for password storage when configured to encrypt passwords in the d...
Nov 24, 2025Apache OpenOffice versions through 4.1.15 have an authorization vulnerability where specially crafted documents can automatically load external links ...
Nov 12, 2025This vulnerability allows attackers to upload malicious files to Apache OFBiz servers, potentially leading to remote code execution or server compromi...
Nov 12, 2025This CVE describes a reflected cross-site scripting (XSS) vulnerability in Apache OFBiz that allows attackers to inject malicious scripts into web pag...
Nov 12, 2025Apache OpenOffice versions through 4.1.15 have a missing authorization vulnerability where documents containing OLE objects with external links can au...
Nov 12, 2025Apache OpenOffice Calc has a missing authorization vulnerability that allows attackers to craft documents with external data source links that load wi...
Nov 12, 2025Apache OpenOffice versions through 4.1.15 have a missing authorization vulnerability that allows attackers to craft documents that automatically load ...
Nov 12, 2025Apache OpenOffice versions through 4.1.15 have a missing authorization vulnerability where specially crafted Calc spreadsheets containing DDE links ca...
Nov 12, 2025An out-of-bounds write vulnerability in Apache OpenOffice allows attackers to craft malicious documents that could crash the program or corrupt memory...
Nov 12, 2025Apache OpenOffice versions through 4.1.15 contain a missing authorization vulnerability where documents with floating frames linked to external files ...
Nov 12, 2025This vulnerability allows attackers with valid read-only accounts to bypass access controls in Doris MCP Server, enabling unauthorized modifications t...
Nov 5, 2025This vulnerability in Apache APISIX exposes basic authentication credentials (usernames and passwords) in plaintext within error logs when log levels ...
Oct 31, 2025This CVE describes an OS command injection vulnerability in Apache Airflow's example_dag_decorator where unvalidated parameters could allow UI users t...
Oct 30, 2025This vulnerability allows authenticated API users to execute arbitrary Dag code in the context of the api-server when deployed in environments where D...
Oct 30, 2025This vulnerability allows authenticated users with CREATE privilege but no UPDATE privilege for Pools, Connections, and Variables to modify existing r...
Oct 30, 2025A path traversal vulnerability in Apache Tomcat allows attackers to bypass security constraints protecting sensitive directories like /WEB-INF/ and /M...
Oct 27, 2025Apache Tomcat fails to escape ANSI escape sequences in log messages, allowing attackers to inject malicious sequences when Tomcat runs in a console su...
Oct 27, 2025Apache Geode's Management and Monitoring REST API is vulnerable to Cross-Site Request Forgery (CSRF) attacks via GET requests. An attacker who obtains...
Oct 18, 2025This CVE describes an Inefficient Regular Expression Complexity (ReDoS) vulnerability in Apache Traffic Control's Traffic Router management interface....
Oct 16, 2025A deserialization vulnerability in Apache ActiveMQ NMS AMQP Client allows malicious AMQP servers to execute arbitrary code on client systems when conn...
Oct 16, 2025Apache Spark versions before 3.4.4, 3.5.2, and 4.0.0 use an insecure default cipher (AES/CTR/NoPadding) for RPC encryption when spark.network.crypto.e...
Oct 15, 2025Apache Flink CDC 3.4.0 contains a SQL injection vulnerability that allows authenticated database users to execute arbitrary SQL commands by crafting m...
Oct 9, 2025This vulnerability in Apache Kylin allows unauthorized external parties to access sensitive files or directories if administrative access controls are...
Oct 2, 2025This CVE describes a Server-Side Request Forgery (SSRF) vulnerability in Apache Kylin that allows attackers to make unauthorized requests from the ser...
Oct 2, 2025This CVE describes an authentication bypass vulnerability in Apache Kylin that allows attackers to access protected functionality without proper crede...
Oct 2, 2025This vulnerability allows arbitrary code execution through deserialization of untrusted data in pyfory/pyfury libraries. Applications are affected if ...
Oct 1, 2025Apache Airflow 3.0.3 has a security flaw where users with READ permissions can view sensitive connection information through both API and UI interface...
Sep 26, 2025This vulnerability allows authorized ZooKeeper clients to execute snapshot and restore commands without proper permission checks. It affects Apache Zo...
Sep 24, 2025This vulnerability in Apache IoTDB is an uncontrolled resource consumption issue (CWE-400) that could allow attackers to cause denial of service. It a...
Sep 24, 2025This CVE describes a denial-of-service vulnerability in Apache Fory caused by insecure deserialization of untrusted data. Remote attackers can send sp...
Sep 15, 2025This vulnerability allows authenticated attackers to execute arbitrary code on Apache HertzBeat servers by injecting malicious XML into HTTP sitemap r...
Sep 9, 2025Apache DolphinScheduler versions before 3.2.2 have incorrect default permissions that could allow unauthorized access to sensitive functionality or da...
Sep 3, 2025An authenticated user in Apache DolphinScheduler can exploit improper input validation in alert script functionality to execute arbitrary shell comman...
Sep 3, 2025This CVE describes a privilege escalation vulnerability in Apache Cassandra where a user with MODIFY permission on all keyspaces can gain superuser pr...
Aug 25, 2025This vulnerability in Apache Log4cxx's JSONLayout allows attackers to inject non-printable characters into log messages, which aren't properly escaped...
Aug 22, 2025This CVE describes an SQL injection vulnerability in Apache StreamPark's SpringBoot distribution package that allows authenticated attackers to execut...
Aug 22, 2025This CVE describes a Server-Side Request Forgery (SSRF) vulnerability in the eventmesh-runtime module's WebhookUtil.java component. Attackers can expl...
Aug 20, 2025This vulnerability in Apache Commons OGNL allows attackers to bypass security restrictions and potentially execute arbitrary code by exploiting incomp...
Aug 18, 2025This CVE describes a critical code injection vulnerability in Apache OFBiz's scrum plugin, allowing unauthenticated attackers to execute arbitrary cod...
Aug 15, 2025This vulnerability allows guest users in Apache Superset to access database schema information through the /chart/data endpoint. The API response impr...
Aug 14, 2025This vulnerability allows attackers to bypass Apache Superset's DISALLOWED_SQL_FUNCTIONS security feature using a special inline block technique. User...
Aug 14, 2025Apache Superset has an improper access control vulnerability where authenticated users can enumerate protected datasources they shouldn't access. By m...
Aug 14, 2025This CVE describes a session fixation vulnerability in Apache Tomcat's rewrite valve that allows attackers to hijack user sessions. Attackers can fixa...
Aug 13, 2025Why Monitor Apache Security Vulnerabilities?
Real-time CVE tracking: Our automated system monitors 559+ known vulnerabilities affecting Apache products and software packages. Stay ahead of emerging threats with instant email notifications when new security issues are discovered.
Automated security monitoring: Unlike manual CVE checking, FixTheCVE automatically scans your servers and detects vulnerable Apache packages in under 60 seconds. No agents required - completely agentless scanning that works across Apache deployments.
Free vulnerability database: Access detailed information about every Apache CVE including CVSS scores, severity ratings, affected versions, and actionable patch guidance. Filter by critical, high, medium, or low severity to prioritize your security remediation efforts.
🚀 Get Started in 60 Seconds
- Register free account & add your servers
- Run one-time scan or schedule automatic monitoring (every 1-24 hours)
- Receive instant alerts when new Apache CVEs affect your systems
- Access dashboard with severity breakdown & fix instructions