Loading HuntDB...

Apache Software Foundation

284 Products 1321 CVEs

CVE Severity Distribution (All Time)

Critical
41
High
68
Medium
95
Low
6

Timeline Overview

Last 30 Days 0 CVEs
Last 6 Months 0 CVEs
Last Year 98 CVEs

Recent CVEs

View all
CVE-2024-45627 UNKNOWN 6 months, 1 week ago

In Apache Linkis <1.7.0, due to the lack of effective filtering of parameters, an attacker configuring malicious Mysql JDBC parameters in the DataSou…

CVE-2025-22828 MEDIUM 6 months, 1 week ago

CloudStack users can add and read comments (annotations) on resources they are authorised to access.  Due to an access validation issue that affects…

CVE-2024-45033 HIGH 6 months, 2 weeks ago

Insufficient Session Expiration vulnerability in Apache Airflow Fab Provider. This issue affects Apache Airflow Fab Provider: before 1.5.2. When us…

CVE-2024-54676 UNKNOWN 6 months, 2 weeks ago

Vendor: The Apache Software Foundation Versions Affected: Apache OpenMeetings from 2.1.0 before 8.0.0 Description: Default clustering instructions …

CVE-2024-56512 UNKNOWN 6 months, 3 weeks ago

Apache NiFi 1.10.0 through 2.0.0 are missing fine-grained authorization checking for Parameter Contexts, referenced Controller Services, and referenc…

CVE-2024-52046 UNKNOWN 6 months, 4 weeks ago

The ObjectSerializationDecoder in Apache MINA uses Java’s native deserialization protocol to process incoming serialized data but lacks the necessary…

CVE-2024-43441 UNKNOWN 7 months ago

Authentication Bypass by Assumed-Immutable Data vulnerability in Apache HugeGraph-Server. This issue affects Apache HugeGraph-Server: from 1.0.0 bef…

CVE-2024-45387 CRITICAL 7 months ago

An SQL injection vulnerability in Traffic Ops in Apache Traffic Control <= 8.0.1, >= 8.0.0 allows a privileged user with role "admin", "federation", …

CVE-2024-23945 UNKNOWN 7 months ago

Signing cookies is an application security feature that adds a digital signature to cookie data to verify its authenticity and integrity. The signatu…

CVE-2024-56337 CRITICAL 7 months ago

Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.1, f…

Related Security News

Hackers Exploit Apache HTTP Server Flaw to Deploy Linuxsys Cryptocurrency Miner
2025-07-17 14:11 Internet

Cybersecurity researchers have discovered a new campaign that exploits a known security flaw impacting Apache HTTP Server to deliver a cryptocurrency miner called Linuxsys. The vulnerability in quest…

SonicWall Exploit Chain Exposes Admin Hijack Risk via CVE-2023-44221 and CVE-2024-38475
2025-05-05 00:28 SecurityOnline.info

A newly exploit chain targeting SonicWall’s Secure Mobile Access (SMA) appliances has been released. Published by watchTowr Labs, The post SonicWall Exploit Chain Exposes Admin Hijack Risk via CVE-20…

watchTowr Warns of Active Exploitation of SonicWall SMA 100 Devices
2025-05-03 21:26 HackRead

watchTowr reveals active exploitation of SonicWall SMA 100 vulnerabilities (CVE-2024-38475 & CVE-2023-44221) potentially leading to full system takeover…

Attackers exploited old flaws to breach SonicWall SMA appliances (CVE-2024-38475, CVE-2023-44221)
2025-05-02 13:16 Help Net Security

Attackers have been using two previously known vulnerabilities (CVE-2024-38475, CVE-2023-44221) to compromise SonicWall secure mobile access devices, the vendor has confirmed by updating the associat…

CISA Adds Two Known Exploited Vulnerabilities to Catalog
2025-05-01 12:00 Cisa.gov

CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. CVE-2024-38475 Apache HTTP Server Improper Escaping of Output Vulnerab…