Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1310 CNY

100%

Apache Software Foundation — Vulnerabilities & Security Advisories 1771

Browse all 1771 CVE security advisories affecting Apache Software Foundation. AI-powered Chinese analysis, POCs, and references for each vulnerability.

The Apache Software Foundation develops and maintains open-source software, primarily known for the widely deployed Apache HTTP Server and foundational Java frameworks. Its extensive portfolio exposes a significant attack surface, evidenced by the 1717 recorded CVEs. Historically, vulnerabilities frequently involve remote code execution, cross-site scripting, and privilege escalation, often stemming from complex configuration errors or input validation failures in legacy components. While the foundation enforces rigorous security review processes, the sheer volume of projects increases the likelihood of undiscovered flaws. Notable incidents include critical flaws in Log4j, which allowed remote code execution via crafted log messages, highlighting risks in dependency management. The organization relies on community-driven patching, requiring administrators to promptly apply updates to mitigate exploitation. This model ensures transparency but demands active vigilance from users to maintain system integrity against evolving threat vectors.

CVE IDTitleCVSSSeverityPublished
CVE-2025-47868 Apache NuttX RTOS: tools/bdf-converter.: tools/bdf-converter: Fix loop termination condition. — Apache NuttX RTOS: tools/bdf-converter.CWE-787 9.8AICriticalAI2025-06-16
CVE-2025-30675 Apache CloudStack: Unauthorised template/ISO list access to the domain/resource admins — Apache CloudStackCWE-200 4.7 Medium2025-06-10
CVE-2025-22829 Apache CloudStack: Unauthorised access to dedicated resources in Quota plugin — Apache CloudStackCWE-269 4.3AIMediumAI2025-06-10
CVE-2025-26521 Apache CloudStack: CKS cluster in project exposes user API keys — Apache CloudStackCWE-200 7.5AIHighAI2025-06-10
CVE-2025-47849 Apache CloudStack: Insecure access of user's API/Secret Keys in the same domain — Apache CloudStackCWE-269 7.2AIHighAI2025-06-10
CVE-2025-47713 Apache CloudStack: Domain Admin can reset Admin password in Root Domain — Apache CloudStackCWE-269 7.2AIHighAI2025-06-10
CVE-2025-27817 Apache Kafka Client: Arbitrary file read and SSRF vulnerability — Apache Kafka Client 7.5 -2025-06-10
CVE-2025-27819 Apache Kafka: Possible RCE/Denial of service attack via SASL JAAS JndiLoginModule configuration — Apache KafkaCWE-502 8.1 -2025-06-10
CVE-2025-27818 Apache Kafka: Possible RCE attack via SASL JAAS LdapLoginModule configuration — Apache KafkaCWE-502 8.1 -2025-06-10
CVE-2025-27531 Apache InLong: An arbitrary file read vulnerability for JDBC — Apache InLongCWE-502 6.5AIMediumAI2025-06-06
CVE-2025-46548 Apache Pekko Management, Apache Pekko Management, Apache Pekko Management, Akka Management, Akka Management, Akka Management: management API basic authentication is not effective — Apache Pekko ManagementCWE-287 9.8AICriticalAI2025-06-03
CVE-2025-48912 Apache Superset: Improper authorization bypass on row level security via SQL Injection — Apache SupersetCWE-89 6.5AIMediumAI2025-05-30
CVE-2025-46701 Apache Tomcat: Security constraint bypass for CGI scripts — Apache TomcatCWE-178 9.1AICriticalAI2025-05-29
CVE-2025-48734 Apache Commons BeanUtils: PropertyUtilsBean does not suppresses an enum's declaredClass property by default — Apache Commons BeanUtils 1.xCWE-284 9.8AICriticalAI2025-05-28
CVE-2025-27528 Apache InLong: JDBC Vulnerability for Invisible Character Bypass Leading to Arbitrary File Read — Apache InLongCWE-502 7.5AIHighAI2025-05-28
CVE-2025-27526 Apache InLong: JDBC Vulnerability For URLEncode and backspace bypass — Apache InLongCWE-502 9.8AICriticalAI2025-05-28
CVE-2025-27522 Apache InLong: JDBC Vulnerability during verification processing — Apache InLongCWE-502 8.1AIHighAI2025-05-28
CVE-2025-35003 Apache NuttX RTOS: NuttX Bluetooth Stack HCI and UART DoS/RCE Vulnerabilities. — Apache NuttX RTOSCWE-119 8.8AIHighAI2025-05-26
CVE-2025-47436 Apache ORC: Potential Heap Buffer Overflow during C++ LZO Decompression — Apache ORCCWE-122 7.8AIHighAI2025-05-14
CVE-2025-26864 Apache IoTDB: Exposure of Sensitive Information in IoTDB OpenID Authentication — Apache IoTDBCWE-200 7.5AIHighAI2025-05-14
CVE-2025-26795 Apache IoTDB JDBC driver: Exposure of Sensitive Information in IoTDB JDBC driver — Apache IoTDB JDBC driverCWE-200 7.5AIHighAI2025-05-14
CVE-2024-24780 Apache IoTDB: Remote Code Execution with untrusted URI of User-defined function — Apache IoTDB 8.8AIHighAI2025-05-14
CVE-2025-27696 Apache Superset: Incorrect authorization leading to resource ownership takeover — Apache SupersetCWE-863 6.5AIMediumAI2025-05-13
CVE-2025-46392 Apache Commons Configuration: Uncontrolled Resource Consumption when loading untrusted configurations in 1.x — Apache Commons ConfigurationCWE-400 7.5AIHighAI2025-05-09
CVE-2025-27533 Apache ActiveMQ: Unchecked buffer length can cause excessive memory allocation — Apache ActiveMQCWE-789 7.5AIHighAI2025-05-07
CVE-2025-46762 Apache Parquet Java: Potential malicious code execution from trusted packages in the parquet-avro module when reading an Avro schema from a Parquet file metadata — Apache Parquet JavaCWE-73 9.8AICriticalAI2025-05-06
CVE-2025-31651 Apache Tomcat: Bypass of rules in Rewrite Valve — Apache TomcatCWE-116 9.1AICriticalAI2025-04-28
CVE-2025-31650 Apache Tomcat: DoS via malformed HTTP/2 PRIORITY_UPDATE frame — Apache TomcatCWE-459 7.5AIHighAI2025-04-28
CVE-2025-27820 Apache HttpComponents: PSL (Public Suffix List) validation bypass — Apache HttpComponents--2025-04-24
CVE-2025-26413 Apache Kvrocks: The server was crashed by the negative offset — Apache KvrocksCWE-20 7.5 -2025-04-22

This page lists every published CVE security advisory associated with Apache Software Foundation. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.