Apache

2,731 tracked vulnerabilities.

CVE-2025-54057 MEDIUM
Apache Skywalking < 10.3.0 - Basic XSS
Nov 27, 2025
CVSS 6.1
EPSS 0.00
CVE-2025-62728 MEDIUM
Apache Hive < 4.2.0 - SQL Injection
Nov 26, 2025
CVSS 5.4
EPSS 0.00
CVE-2025-59390 CRITICAL
Apache Druid < 35.0.0 - Authentication Bypass
Nov 26, 2025
CVSS 9.8
EPSS 0.00
CVE-2025-65998 HIGH
Apache Syncope - Info Disclosure
Nov 24, 2025
CVSS 7.5
EPSS 0.00
CVE-2025-64408 MEDIUM
Apache Causeway < 3.5.0 - Insecure Deserialization
Nov 19, 2025
CVSS 6.3
EPSS 0.01
CVE-2025-64407 MEDIUM
Apache Openoffice < 4.1.16 - Missing Authorization
Nov 12, 2025
CVSS 5.3
EPSS 0.00
CVE-2025-61623 MEDIUM
Apache OFBiz <24.09.03 - XSS
Nov 12, 2025
CVSS 6.5
EPSS 0.00
CVE-2025-59118 HIGH
Apache Ofbiz < 24.09.03 - Unrestricted File Upload
Nov 12, 2025
CVSS 7.3
EPSS 0.00
CVE-2025-64406 MEDIUM
Apache Openoffice < 4.1.16 - Out-of-Bounds Write
Nov 12, 2025
CVSS 4.3
EPSS 0.00
CVE-2025-64405 HIGH
Apache Openoffice < 4.1.16 - Missing Authorization
Nov 12, 2025
CVSS 7.5
EPSS 0.00
CVE-2025-64404 HIGH
Apache Openoffice < 4.1.16 - Missing Authorization
Nov 12, 2025
CVSS 7.5
EPSS 0.00
CVE-2025-64403 HIGH
Apache Openoffice < 4.1.16 - Missing Authorization
Nov 12, 2025
CVSS 8.1
EPSS 0.00
CVE-2025-64402 MEDIUM
Apache Openoffice < 4.1.16 - Missing Authorization
Nov 12, 2025
CVSS 6.5
EPSS 0.00
CVE-2025-64401 HIGH
Apache Openoffice < 4.1.16 - Missing Authorization
Nov 12, 2025
CVSS 7.5
EPSS 0.00
CVE-2025-58337 MEDIUM
Doris MCP Server <0.6.0 - Auth Bypass
Nov 05, 2025
CVSS 5.4
EPSS 0.00
CVE-2025-62232 HIGH
Apache Apisix < 3.14.0 - Log Information Exposure
Oct 31, 2025
CVSS 7.5
EPSS 0.00
CVE-2025-62503 MEDIUM
Unknown - Privilege Escalation
Oct 30, 2025
CVSS 4.6
EPSS 0.00
CVE-2025-62402 MEDIUM
API <v2 - Code Injection
Oct 30, 2025
CVSS 5.4
EPSS 0.00
CVE-2025-54941 MEDIUM
Apache Airflow < 3.0.5 - OS Command Injection
Oct 30, 2025
CVSS 4.6
EPSS 0.00
CVE-2025-61795 MEDIUM
Apache Tomcat < 8.5.100 - Improper Resource Release
Oct 27, 2025
CVSS 5.3
EPSS 0.00
CVE-2025-55754 CRITICAL
Apache Tomcat - Info Disclosure
Oct 27, 2025
CVSS 9.6
EPSS 0.00
CVE-2025-55752 HIGH
Apache Tomcat - Path Traversal
Oct 27, 2025
CVSS 7.5
EPSS 0.00
CVE-2025-57738 HIGH
Apache Syncope - Code Injection
Oct 20, 2025
CVSS 7.2
EPSS 0.00
CVE-2025-47410 HIGH
Apache Geode < 1.15.2 - CSRF
Oct 18, 2025
CVSS 8.8
EPSS 0.00
CVE-2025-61581 HIGH
Apache Traffic Control - Info Disclosure
Oct 16, 2025
CVSS 7.5
EPSS 0.00