Apache Security Vulnerabilities (CVEs)

Track 561 security vulnerabilities affecting Apache products and software. Get instant email alerts when new CVEs are discovered, automated security monitoring, and patch guidance.

200 Critical
263 High
95 Medium
3 Low
🔔 Get Alerts for Apache
CVE-2025-48989 7.5

This CVE describes an Improper Resource Shutdown or Release vulnerability in Apache Tomcat that enables a 'made you reset' attack. Attackers can explo...

Aug 13, 2025
CVE-2025-48913 9.8

This vulnerability in Apache CXF allows untrusted users who can configure JMS endpoints to use RMI or LDAP URLs, potentially leading to remote code ex...

Aug 8, 2025
CVE-2024-51775 5.3

This CVE describes a missing origin validation vulnerability in Apache Zeppelin's WebSocket implementation. Attackers can bypass same-origin policy re...

Aug 3, 2025
CVE-2024-41177 6.1

Apache Zeppelin versions before 0.12.0 have an incomplete blacklist that fails to properly sanitize user input, allowing attackers to inject malicious...

Aug 3, 2025
CVE-2024-52279 5.3

This vulnerability allows attackers to bypass JDBC URL validation in Apache Zeppelin by using URL-encoded input, potentially enabling unauthorized dat...

Aug 3, 2025
CVE-2025-24853 7.5

CVE-2025-24853 is a cross-site scripting (XSS) vulnerability in Apache JSPWiki that allows attackers to inject malicious JavaScript via wiki markup sy...

Jul 31, 2025
CVE-2025-54090 6.3

A bug in Apache HTTP Server 2.4.64 causes all RewriteCond expression tests to evaluate as true, potentially allowing attackers to bypass URL rewrite r...

Jul 23, 2025
CVE-2025-49656 7.5

This vulnerability allows administrators in Apache Jena Fuseki to create database files outside the designated files area, potentially enabling path t...

Jul 21, 2025
CVE-2025-53506 7.5

This vulnerability allows an attacker to cause a denial-of-service (DoS) condition in Apache Tomcat by exploiting an HTTP/2 protocol flaw. An uncooper...

Jul 10, 2025
CVE-2025-52434 7.5

A race condition vulnerability in Apache Tomcat's APR/Native connector when handling HTTP/2 connection closures can lead to crashes or denial of servi...

Jul 10, 2025
CVE-2025-52520 7.5

An integer overflow vulnerability in Apache Tomcat's multipart upload handling allows attackers to bypass configured size limits, potentially causing ...

Jul 10, 2025
CVE-2025-49630 7.5

This vulnerability allows untrusted clients to trigger a denial of service attack against Apache HTTP Server by causing an assertion failure in the mo...

Jul 10, 2025
CVE-2025-53020 7.5

This vulnerability in Apache HTTP Server involves improper memory management where memory is released later than intended after its effective lifetime...

Jul 10, 2025
CVE-2024-43394 7.5

This CVE describes a Server-Side Request Forgery (SSRF) vulnerability in Apache HTTP Server on Windows that allows attackers to leak NTLM hashes to ma...

Jul 10, 2025
CVE-2025-23048 9.1

This CVE describes an access control bypass vulnerability in Apache HTTP Server's mod_ssl module when using TLS 1.3 session resumption. Organizations ...

Jul 10, 2025
CVE-2024-42516 7.5

This HTTP response splitting vulnerability in Apache HTTP Server allows attackers to manipulate Content-Type headers to split HTTP responses, potentia...

Jul 10, 2025
CVE-2025-27446 7.8

This vulnerability allows a local attacker to exploit incorrect file permissions in Apache APISIX's Java plugin runner to elevate privileges. It affec...

Jul 6, 2025
CVE-2024-35164 6.8

This vulnerability in Apache Guacamole allows authenticated attackers with access to text-based connections (like SSH) to execute arbitrary code on th...

Jul 2, 2025
CVE-2025-32897 9.8

This vulnerability allows attackers to execute arbitrary code by sending malicious serialized data to Apache Seata servers. It affects all Apache Seat...

Jun 28, 2025
CVE-2025-50213 9.8

This CVE describes a SQL injection vulnerability in Apache Airflow's Snowflake provider where unsanitized table and stage parameters in the CopyFromEx...

Jun 24, 2025
CVE-2025-32896 6.5

Unauthorized attackers can exploit Apache SeaTunnel's REST API to read arbitrary files and perform deserialization attacks by submitting malicious job...

Jun 19, 2025
CVE-2025-31698 7.5

Apache Traffic Server versions 9.0.0-9.2.10 and 10.0.0-10.0.6 have an ACL bypass vulnerability when using PROXY protocol. The access control lists in ...

Jun 19, 2025
CVE-2025-48988 7.5

This CVE describes an allocation of resources without limits or throttling vulnerability in Apache Tomcat. Attackers can exploit this to cause denial ...

Jun 16, 2025
CVE-2025-49125 7.5

This CVE describes an authentication bypass vulnerability in Apache Tomcat where PreResources or PostResources mounted at non-root paths can be access...

Jun 16, 2025
CVE-2025-47869 9.8

A buffer overflow vulnerability exists in Apache NuttX RTOS's XMLRPC example application due to hardcoded buffer sizes in device stats structures. Thi...

Jun 16, 2025
CVE-2025-30675 4.7

This vulnerability allows malicious Domain Admins or Resource Admins in Apache CloudStack to bypass domain isolation by exploiting flawed access contr...

Jun 11, 2025
CVE-2025-47713 8.8

A privilege escalation vulnerability in Apache CloudStack allows malicious Domain Admin users in the ROOT domain to reset passwords of Admin role acco...

Jun 10, 2025
CVE-2025-26521 8.1

This vulnerability in Apache CloudStack allows project members with access to CKS-based Kubernetes clusters to steal the API and secret keys of the cl...

Jun 10, 2025
CVE-2025-27818 8.8

This CVE describes a Java deserialization vulnerability in Apache Kafka Connect that allows authenticated operators with configuration privileges to e...

Jun 10, 2025
CVE-2025-27531 9.8

This vulnerability allows authenticated attackers to read arbitrary files on Apache InLong servers through a deserialization flaw. It affects Apache I...

Jun 6, 2025
CVE-2025-46548 6.5

This vulnerability allows attackers to bypass Basic Authentication in Pekko Management when configured via Java DSL, potentially exposing management A...

Jun 3, 2025
CVE-2025-46701 7.3

This vulnerability in Apache Tomcat's CGI servlet allows attackers to bypass security constraints by exploiting improper case sensitivity handling in ...

May 29, 2025
CVE-2025-27526 6.5

This CVE describes a deserialization vulnerability in Apache InLong that allows attackers to bypass security controls through JDBC URL encoding and ba...

May 28, 2025
CVE-2025-27528 9.1

This vulnerability allows attackers to exploit insecure deserialization in Apache InLong's JDBC component, enabling arbitrary file reading on affected...

May 28, 2025
CVE-2025-35003 9.8

This CVE describes memory buffer and stack-based buffer overflow vulnerabilities in Apache NuttX RTOS's Bluetooth HCI and UART components. Attackers c...

May 26, 2025
CVE-2025-47436 9.8

A heap-based buffer overflow vulnerability in Apache ORC's C++ LZO decompression logic allows attackers to cause memory corruption by providing specia...

May 14, 2025
CVE-2025-26864 7.5

Apache IoTDB's OpenIdAuthorizer component logs sensitive authentication information, potentially exposing credentials or tokens to unauthorized actors...

May 14, 2025
CVE-2024-24780 9.8

This vulnerability allows attackers with UDF creation privileges in Apache IoTDB to execute arbitrary code by registering malicious functions from unt...

May 14, 2025
CVE-2025-27696 8.8

This vulnerability allows authenticated users with read-only permissions in Apache Superset to take ownership of dashboards, charts, or datasets. This...

May 13, 2025
CVE-2025-27533 7.5

This vulnerability in Apache ActiveMQ allows attackers to cause denial of service by sending specially crafted OpenWire commands that trigger excessiv...

May 7, 2025
CVE-2025-46762 8.1

This vulnerability in Apache Parquet's parquet-avro module allows attackers to execute arbitrary code by exploiting schema parsing when reading malici...

May 6, 2025
CVE-2025-31651 9.8

This vulnerability in Apache Tomcat allows attackers to bypass security constraints by crafting requests that evade specific rewrite rules. It affects...

Apr 28, 2025
CVE-2025-26413 7.5

An improper input validation vulnerability in Apache Kvrocks allows attackers to crash the server by sending a negative offset value to the SETRANGE c...

Apr 22, 2025
CVE-2025-29953 9.8

This vulnerability allows malicious Apache ActiveMQ servers to send specially crafted responses to NMS OpenWire clients, leading to arbitrary code exe...

Apr 18, 2025
CVE-2025-24859 8.8

Apache Roller versions up to 6.1.4 have a session management vulnerability where active user sessions remain valid after password changes. This allows...

Apr 14, 2025
CVE-2025-27391 6.5

Apache ActiveMQ Artemis versions 1.5.1 through 2.39.0 log sensitive broker configuration properties when debug logging is enabled. This exposes creden...

Apr 9, 2025
CVE-2025-31672 5.3

This vulnerability allows attackers to create malicious OOXML files (like Excel, Word, or PowerPoint documents) with duplicate zip entries that can ca...

Apr 9, 2025
CVE-2025-30473 8.8

This SQL injection vulnerability in Apache Airflow Common SQL Provider allows authenticated UI users to inject arbitrary SQL commands via the partitio...

Apr 7, 2025
CVE-2024-53868 7.5

Apache Traffic Server is vulnerable to HTTP request smuggling when processing malformed chunked messages. This allows attackers to bypass security con...

Apr 3, 2025
CVE-2025-30065 9.8

This vulnerability in Apache Parquet's parquet-avro module allows attackers to execute arbitrary code by exploiting schema parsing flaws. It affects a...

Apr 1, 2025

Why Monitor Apache Security Vulnerabilities?

Real-time CVE tracking: Our automated system monitors 561+ known vulnerabilities affecting Apache products and software packages. Stay ahead of emerging threats with instant email notifications when new security issues are discovered.

Automated security monitoring: Unlike manual CVE checking, FixTheCVE automatically scans your servers and detects vulnerable Apache packages in under 60 seconds. No agents required - completely agentless scanning that works across Apache deployments.

Free vulnerability database: Access detailed information about every Apache CVE including CVSS scores, severity ratings, affected versions, and actionable patch guidance. Filter by critical, high, medium, or low severity to prioritize your security remediation efforts.

🚀 Get Started in 60 Seconds

  • Register free account & add your servers
  • Run one-time scan or schedule automatic monitoring (every 1-24 hours)
  • Receive instant alerts when new Apache CVEs affect your systems
  • Access dashboard with severity breakdown & fix instructions
Start Monitoring Apache CVEs Free