Loading HuntDB...

Apache

134 Products 297 CVEs

CVE Severity Distribution (All Time)

Critical
25
High
44
Medium
15
Low
2

Timeline Overview

Last 30 Days 0 CVEs
Last 6 Months 0 CVEs
Last Year 35 CVEs

Recent CVEs

View all
CVE-2024-53949 UNKNOWN 7 months, 2 weeks ago

Improper Authorization vulnerability in Apache Superset when FAB_ADD_SECURITY_API is enabled (disabled by default). Allows for lower privilege users …

CVE-2022-41137 UNKNOWN 7 months, 2 weeks ago

Apache Hive Metastore (HMS) uses SerializationUtilities#deserializeObjectWithTypeInformation method when filtering and fetching partitions that is un…

CVE-2024-45106 UNKNOWN 7 months, 3 weeks ago

Improper authentication of an HTTP endpoint in the S3 Gateway of Apache Ozone 1.4.0 allows any authenticated Kerberos user to revoke and regenerate t…

CVE-2024-51569 UNKNOWN 7 months, 4 weeks ago

Out-of-bounds Read vulnerability in Apache NimBLE. Missing proper validation of HCI Number Of Completed Packets could lead to out-of-bound access wh…

CVE-2024-52317 MEDIUM 8 months ago

Incorrect object re-cycling and re-use vulnerability in Apache Tomcat. Incorrect recycling of the request and response used by HTTP/2 requests could…

CVE-2024-52316 CRITICAL 8 months ago

Unchecked Error Condition vulnerability in Apache Tomcat. If Tomcat is configured to use a custom Jakarta Authentication (formerly JASPIC) ServerAuth…

CVE-2024-41151 UNKNOWN 8 months ago

Deserialization of Untrusted Data vulnerability in Apache HertzBeat. This vulnerability can only be exploited by authorized attackers. This issue …

CVE-2024-45791 UNKNOWN 8 months ago

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache HertzBeat. This issue affects Apache HertzBeat: before 1.6.1. Us…

CVE-2024-45505 UNKNOWN 8 months ago

Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Apache HertzBeat (incubating). This vulnerabili…

CVE-2024-48962 UNKNOWN 8 months ago

Improper Control of Generation of Code ('Code Injection'), Cross-Site Request Forgery (CSRF), : Improper Neutralization of Special Elements Used in a…

Related Security News

SonicWall Exploit Chain Exposes Admin Hijack Risk via CVE-2023-44221 and CVE-2024-38475
2025-05-05 00:28 SecurityOnline.info

A newly exploit chain targeting SonicWall’s Secure Mobile Access (SMA) appliances has been released. Published by watchTowr Labs, The post SonicWall Exploit Chain Exposes Admin Hijack Risk via CVE-20…

watchTowr Warns of Active Exploitation of SonicWall SMA 100 Devices
2025-05-03 21:26 HackRead

watchTowr reveals active exploitation of SonicWall SMA 100 vulnerabilities (CVE-2024-38475 & CVE-2023-44221) potentially leading to full system takeover…

Attackers exploited old flaws to breach SonicWall SMA appliances (CVE-2024-38475, CVE-2023-44221)
2025-05-02 13:16 Help Net Security

Attackers have been using two previously known vulnerabilities (CVE-2024-38475, CVE-2023-44221) to compromise SonicWall secure mobile access devices, the vendor has confirmed by updating the associat…

CISA Adds Two Known Exploited Vulnerabilities to Catalog
2025-05-01 12:00 Cisa.gov

CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. CVE-2024-38475 Apache HTTP Server Improper Escaping of Output Vulnerab…

F5 Products Multiple Vulnerabilities
2025-04-16 02:52 Hkcert.org

Multiple vulnerabilities were identified in F5 Products, attacker can exploit this vulnerability to trigger sensitive information disclosure and denial of service condition on the targeted system. No…