← Back

Apache

apache

3,377 CVEs • 392 products

Products (392)

Click to collapse
Toggle
Http Server
http_server
Tomcat
tomcat
Airflow
airflow
Struts
struts
Camel
camel
Ofbiz
ofbiz
Activemq
activemq
Superset
superset
Cxf
cxf
Cloudstack
cloudstack
Openoffice
openoffice
Nifi
nifi
Subversion
subversion
Solr
solr
Inlong
inlong
Hadoop
hadoop
Wicket
wicket
Thrift
thrift
Ranger
ranger
Openmeetings
openmeetings
Jspwiki
jspwiki
Apisix
apisix
Tika
tika
Ambari
ambari
Zeppelin
zeppelin
Shiro
shiro
Syncope
syncope
Kylin
kylin
Answer
answer
Hive
hive
Geode
geode
Spark
spark
Fineract
fineract
Couchdb
couchdb
Archiva
archiva
Log4j
log4j
Iotdb
iotdb
Pulsar
pulsar
Dubbo
dubbo
Cordova
cordova
Linkis
linkis
Kafka
kafka
Streampark
streampark
Qpid
qpid
Cassandra
cassandra
Hertzbeat
hertzbeat
Qpid Broker J
qpid_broker-j
Atlas
atlas
Nimble
nimble
Artemis
artemis
James
james
Roller
roller
Storm
storm
Jmeter
jmeter
Spamassassin
spamassassin
Guacamole
guacamole
Karaf
karaf
Allura
allura
Druid
druid
Xerces C++
xerces-c++
Apr Util
apr-util
Tapestry
tapestry
Zookeeper
zookeeper
Impala
impala
Ozone
ozone
Fory
fory
Batik
batik
Geronimo
geronimo
Httpclient
httpclient
Poi
poi
Pdfbox
pdfbox
Tomee
tomee
Ignite
ignite
Mesos
mesos
Nuttx
nuttx
Shenyu
shenyu
Derby
derby
Mina
mina
Axis
axis
Bookkeeper
bookkeeper
Qpid Proton J
qpid_proton-j
Mina Sshd
mina_sshd
Avro
avro
Doris
doris
Streampipes
streampipes
Mod Python
mod_python
Jackrabbit
jackrabbit
Axis2
axis2
Hbase
hbase
Drill
drill

CVEs (3,377)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Apache
1Airflow
Jun 17, 2026
Jan 14, 2020
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
In Apache Airflow before 1.10.5 when running with the "classic" UI, a malicious admin user could edit the state of objects in the Airflow metadata database to execute arbitrary javascript on certain page views. The new "...Show more
In Apache Airflow before 1.10.5 when running with the "classic" UI, a malicious admin user could edit the state of objects in the Airflow metadata database to execute arbitrary javascript on certain page views. The new "RBAC" UI is unaffected.Show less
2Apache
Oracle
13Banking Corporate Lending Process Management
Banking Credit Facilities Process ManagementBanking Liquidity Management+10 more
Jun 17, 2026
Jan 14, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
When Connect workers in Apache Kafka 2.0.0, 2.0.1, 2.1.0, 2.1.1, 2.2.0, 2.2.1, or 2.3.0 are configured with one or more config providers, and a connector is created/updated on that Connect cluster to use an externalized...Show more
When Connect workers in Apache Kafka 2.0.0, 2.0.1, 2.1.0, 2.1.1, 2.2.0, 2.2.1, or 2.3.0 are configured with one or more config providers, and a connector is created/updated on that Connect cluster to use an externalized secret variable in a substring of a connector configuration property value, then any client can issue a request to the same Connect cluster to obtain the connector's task configuration and the response will contain the plaintext secret rather than the externalized secrets variables.Show less
2Apache
Oracle
3Cordova Inappbrowser
Instantis EnterprisetrackRetail Xstore Point Of Service
Jun 17, 2026
Jan 14, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A website running in the InAppBrowser webview on Android could execute arbitrary JavaScript in the main application's webview using a specially crafted gap-iab: URI.
1Apache
1Olingo
Jun 17, 2026
Jan 9, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Apache Olingo versions 4.0.0 to 4.7.0 provide the AsyncRequestWrapperImpl class which reads a URL from the Location header, and then sends a GET or DELETE request to this URL. It may allow to implement a SSRF attack. If...Show more
Apache Olingo versions 4.0.0 to 4.7.0 provide the AsyncRequestWrapperImpl class which reads a URL from the Location header, and then sends a GET or DELETE request to this URL. It may allow to implement a SSRF attack. If an attacker tricks a client to connect to a malicious server, the server can make the client call any URL including internal resources which are not directly accessible by the attacker.Show less
1Apache
1Rust Sgx Sdk
Jun 17, 2026
Jan 4, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Baidu Rust SGX SDK through 1.0.8 has an enclave ID race. There are non-deterministic results in which, sometimes, two global IDs are the same.
2Apache
Docker
2Docker
Geode
Nov 21, 2024
Jan 2, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An issue was found in Docker before 1.6.0. Some programs and scripts in Docker are downloaded via HTTP and then executed or used in unsafe ways.
2Apache
Oracle
2Primavera Unifier
Solr
Jun 17, 2026
Dec 30, 2019
N/A· v4
7.5 HIGH· v3
4.6 MEDIUM· v2
Apache Solr 5.0.0 to Apache Solr 8.3.1 are vulnerable to a Remote Code Execution through the VelocityResponseWriter. A Velocity template can be provided through Velocity templates in a configset `velocity/` directory or...Show more
Apache Solr 5.0.0 to Apache Solr 8.3.1 are vulnerable to a Remote Code Execution through the VelocityResponseWriter. A Velocity template can be provided through Velocity templates in a configset `velocity/` directory or as a parameter. A user defined configset could contain renderable, potentially malicious, templates. Parameter provided templates are disabled by default, but can be enabled by setting `params.resource.loader.enabled` by defining a response writer with that setting set to `true`. Defining a response writer requires configuration API access. Solr 8.4 removed the params resource loader entirely, and only enables the configset-provided template rendering when the configset is `trusted` (has been uploaded by an authenticated user).Show less
5Apache
NetappOracle+2 more
5Bookkeeper
Cloud BackupMysql Workbench+2 more
Jun 17, 2026
Dec 24, 2019
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
SQLite 3.30.1 mishandles certain parser-tree rewriting, related to expr.c, vdbeaux.c, and window.c. This is caused by incorrect sqlite3WindowRewrite() error handling.
6Apache
CanonicalDebian+3 more
6Debian Linux
LeapOncommand System Manager+3 more
Jun 17, 2026
Dec 23, 2019
N/A· v4
7.0 HIGH· v3
4.4 MEDIUM· v2
When Apache Tomcat 9.0.0.M1 to 9.0.28, 8.5.0 to 8.5.47, 7.0.0 and 7.0.97 is configured with the JMX Remote Lifecycle Listener, a local attacker without access to the Tomcat process or configuration files is able to manip...Show more
When Apache Tomcat 9.0.0.M1 to 9.0.28, 8.5.0 to 8.5.47, 7.0.0 and 7.0.97 is configured with the JMX Remote Lifecycle Listener, a local attacker without access to the Tomcat process or configuration files is able to manipulate the RMI registry to perform a man-in-the-middle attack to capture user names and passwords used to access the JMX interface. The attacker can then use these credentials to access the JMX interface and gain complete control over the Tomcat instance.Show less
5Apache
CanonicalDebian+2 more
11Agile Engineering Data Management
Debian LinuxHyperion Infrastructure Technology+8 more
Jun 17, 2026
Dec 23, 2019
N/A· v4
7.5 HIGH· v3
5.1 MEDIUM· v2
When using FORM authentication with Apache Tomcat 9.0.0.M1 to 9.0.29, 8.5.0 to 8.5.49 and 7.0.0 to 7.0.98 there was a narrow window where an attacker could perform a session fixation attack. The window was considered too...Show more
When using FORM authentication with Apache Tomcat 9.0.0.M1 to 9.0.29, 8.5.0 to 8.5.49 and 7.0.0 to 7.0.98 there was a narrow window where an attacker could perform a session fixation attack. The window was considered too narrow for an exploit to be practical but, erring on the side of caution, this issue has been treated as a security vulnerability.Show less
6Apache
CanonicalDebian+3 more
17Application Testing Suite
BookkeeperCommunications Network Integrity+14 more
Jun 17, 2026
Dec 20, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Included in Log4j 1.2 is a SocketServer class that is vulnerable to deserialization of untrusted data which can be exploited to remotely execute arbitrary code when combined with a deserialization gadget when listening t...Show more
Included in Log4j 1.2 is a SocketServer class that is vulnerable to deserialization of untrusted data which can be exploited to remotely execute arbitrary code when combined with a deserialization gadget when listening to untrusted network traffic for log data. This affects Log4j versions up to 1.2 up to 1.2.17.Show less
3Apache
DebianLibreoffice
3Debian Linux
LibreofficeOpenoffice
Nov 21, 2024
Dec 20, 2019
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
LibreOffice and OpenOffice automatically open embedded content
7Apache
AppleCanonical+4 more
19Bookkeeper
Cyrus SaslDebian Linux+16 more
Jun 17, 2026
Dec 19, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
cyrus-sasl (aka Cyrus SASL) 2.1.27 has an out-of-bounds write leading to unauthenticated remote denial-of-service in OpenLDAP via a malformed LDAP packet. The OpenLDAP crash is ultimately caused by an off-by-one error in...Show more
cyrus-sasl (aka Cyrus SASL) 2.1.27 has an out-of-bounds write leading to unauthenticated remote denial-of-service in OpenLDAP via a malformed LDAP packet. The OpenLDAP crash is ultimately caused by an off-by-one error in _sasl_add_string in common.c in cyrus-sasl.Show less
5Apache
DebianFedoraproject+2 more
10Debian Linux
Enterprise Linux DesktopEnterprise Linux Eus+7 more
Nov 4, 2025
Dec 18, 2019
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
The Apache Xerces-C 3.0.0 to 3.2.3 XML parser contains a use-after-free error triggered during the scanning of external DTDs. This flaw has not been addressed in the maintained version of the library and has no current m...Show more
The Apache Xerces-C 3.0.0 to 3.2.3 XML parser contains a use-after-free error triggered during the scanning of external DTDs. This flaw has not been addressed in the maintained version of the library and has no current mitigation other than to disable DTD processing. This can be accomplished via the DOM using a standard parser feature, or via SAX using the XERCES_DISABLE_DTD environment variable.Show less
1Apache
1Superset
Jun 17, 2026
Dec 16, 2019
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
In Apache Incubator Superset before 0.32, a user can view database names that he has no access to on a dropdown list in SQLLab
1Apache
1Superset
Jun 17, 2026
Dec 16, 2019
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
In Apache Incubator Superset before 0.31 user could query database metadata information from a database he has no access to, by using a specially crafted complex query.
1Apache
1Qpid Cpp
Nov 21, 2024
Dec 13, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
qpid-cpp: ACL policies only loaded if the acl-file option specified enabling DoS by consuming all available file descriptors
2Apache
Debian
2Debian Linux
Spamassassin
Jun 17, 2026
Dec 12, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
In Apache SpamAssassin before 3.4.3, a message can be crafted in a way to use excessive resources. Upgrading to SA 3.4.3 as soon as possible is the recommended fix but details will not be shared publicly.
2Apache
Debian
2Debian Linux
Spamassassin
Nov 21, 2024
Dec 12, 2019
N/A· v4
6.7 MEDIUM· v3
7.2 HIGH· v2
In Apache SpamAssassin before 3.4.3, nefarious CF files can be configured to run system commands without any output or errors. With this, exploits can be injected in a number of scenarios. In addition to upgrading to SA...Show more
In Apache SpamAssassin before 3.4.3, nefarious CF files can be configured to run system commands without any output or errors. With this, exploits can be injected in a number of scenarios. In addition to upgrading to SA 3.4.3, we recommend that users should only use update channels or 3rd party .cf files from trusted places.Show less
5Apache
NetappOracle+2 more
6Cloud Backup
GuacamoleMysql Workbench+3 more
Jun 17, 2026
Dec 9, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
SQLite 3.30.1 mishandles certain SELECT statements with a nonexistent VIEW, leading to an application crash.