Apache
2,731 tracked vulnerabilities.
CVE-2025-54057
MEDIUM
Apache Skywalking < 10.3.0 - Basic XSS
Nov 27, 2025
CVSS 6.1
EPSS 0.00
CVE-2025-62728
MEDIUM
Apache Hive < 4.2.0 - SQL Injection
Nov 26, 2025
CVSS 5.4
EPSS 0.00
CVE-2025-59390
CRITICAL
Apache Druid < 35.0.0 - Authentication Bypass
Nov 26, 2025
CVSS 9.8
EPSS 0.00
CVE-2025-65998
HIGH
Apache Syncope - Info Disclosure
Nov 24, 2025
CVSS 7.5
EPSS 0.00
CVE-2025-64408
MEDIUM
Apache Causeway < 3.5.0 - Insecure Deserialization
Nov 19, 2025
CVSS 6.3
EPSS 0.01
CVE-2025-64407
MEDIUM
Apache Openoffice < 4.1.16 - Missing Authorization
Nov 12, 2025
CVSS 5.3
EPSS 0.00
CVE-2025-61623
MEDIUM
Apache OFBiz <24.09.03 - XSS
Nov 12, 2025
CVSS 6.5
EPSS 0.00
CVE-2025-59118
HIGH
Apache Ofbiz < 24.09.03 - Unrestricted File Upload
Nov 12, 2025
CVSS 7.3
EPSS 0.00
CVE-2025-64406
MEDIUM
Apache Openoffice < 4.1.16 - Out-of-Bounds Write
Nov 12, 2025
CVSS 4.3
EPSS 0.00
CVE-2025-64405
HIGH
Apache Openoffice < 4.1.16 - Missing Authorization
Nov 12, 2025
CVSS 7.5
EPSS 0.00
CVE-2025-64404
HIGH
Apache Openoffice < 4.1.16 - Missing Authorization
Nov 12, 2025
CVSS 7.5
EPSS 0.00
CVE-2025-64403
HIGH
Apache Openoffice < 4.1.16 - Missing Authorization
Nov 12, 2025
CVSS 8.1
EPSS 0.00
CVE-2025-64402
MEDIUM
Apache Openoffice < 4.1.16 - Missing Authorization
Nov 12, 2025
CVSS 6.5
EPSS 0.00
CVE-2025-64401
HIGH
Apache Openoffice < 4.1.16 - Missing Authorization
Nov 12, 2025
CVSS 7.5
EPSS 0.00
CVE-2025-58337
MEDIUM
Doris MCP Server <0.6.0 - Auth Bypass
Nov 05, 2025
CVSS 5.4
EPSS 0.00
CVE-2025-62232
HIGH
Apache Apisix < 3.14.0 - Log Information Exposure
Oct 31, 2025
CVSS 7.5
EPSS 0.00
CVE-2025-62503
MEDIUM
Unknown - Privilege Escalation
Oct 30, 2025
CVSS 4.6
EPSS 0.00
CVE-2025-62402
MEDIUM
API <v2 - Code Injection
Oct 30, 2025
CVSS 5.4
EPSS 0.00
CVE-2025-54941
MEDIUM
Apache Airflow < 3.0.5 - OS Command Injection
Oct 30, 2025
CVSS 4.6
EPSS 0.00
CVE-2025-61795
MEDIUM
Apache Tomcat < 8.5.100 - Improper Resource Release
Oct 27, 2025
CVSS 5.3
EPSS 0.00
CVE-2025-55754
CRITICAL
Apache Tomcat - Info Disclosure
Oct 27, 2025
CVSS 9.6
EPSS 0.00
CVE-2025-55752
HIGH
Apache Tomcat - Path Traversal
Oct 27, 2025
CVSS 7.5
EPSS 0.00
CVE-2025-57738
HIGH
Apache Syncope - Code Injection
Oct 20, 2025
CVSS 7.2
EPSS 0.00
CVE-2025-47410
HIGH
Apache Geode < 1.15.2 - CSRF
Oct 18, 2025
CVSS 8.8
EPSS 0.00
CVE-2025-61581
HIGH
Apache Traffic Control - Info Disclosure
Oct 16, 2025
CVSS 7.5
EPSS 0.00
Products
http_server 306
tomcat 234
airflow 101
struts 90
traffic_server 80
superset 68
openoffice 60
ofbiz 57
activemq 51
subversion 47
solr 46
nifi 44
cxf 43
cloudstack 38
hadoop 37
inlong 32
camel 31
ambari 26
tika 25
openmeetings 25
dolphinscheduler 24
jspwiki 24
geode 23
zeppelin 22
ranger 21
spark 21
kylin 21
couchdb 20
fineract 20
hive 20
Quick Filters