Apache bRPC, a widely used open-source Remote Procedure Call (RPC) framework, contains a critical remote command-injection vulnerability in its built-in heap profiler service, allowing...
A newly disclosed vulnerability in Apache Struts 2's XWork component poses a significant threat to Java web applications worldwide.
The flaw, tracked as CVE-2025-68493...
The Apache Software Foundation has released a security advisory addressing a critical memory corruption vulnerability in the Apache NuttX Real-Time Operating System (RTOS).
Tracked...
A critical XML External Entity (XXE) injection vulnerability in Apache Tika has exposed over 500 public-facing servers worldwide to potential exploitation.
CVE-2025-66516, carrying the...
A critical XML External Entity (XXE) injection vulnerability in Apache Tika has been formally catalogued as CVE-2025-66516, significantly expanding the scope of affected systems...