Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

Apache Software Foundation — Vulnerabilities & Security Advisories 1725

Browse all 1725 CVE security advisories affecting Apache Software Foundation. AI-powered Chinese analysis, POCs, and references for each vulnerability.

The Apache Software Foundation develops and maintains open-source software, primarily known for the widely deployed Apache HTTP Server and foundational Java frameworks. Its extensive portfolio exposes a significant attack surface, evidenced by the 1717 recorded CVEs. Historically, vulnerabilities frequently involve remote code execution, cross-site scripting, and privilege escalation, often stemming from complex configuration errors or input validation failures in legacy components. While the foundation enforces rigorous security review processes, the sheer volume of projects increases the likelihood of undiscovered flaws. Notable incidents include critical flaws in Log4j, which allowed remote code execution via crafted log messages, highlighting risks in dependency management. The organization relies on community-driven patching, requiring administrators to promptly apply updates to mitigate exploitation. This model ensures transparency but demands active vigilance from users to maintain system integrity against evolving threat vectors.

Found 19 results / 1725Clear Filters
CVE IDTitleCVSSSeverityPublished
CVE-2025-48913 Apache CXF: Untrusted JMS configuration can lead to RCE — Apache CXFCWE-20 9.8 -2025-08-08
CVE-2025-48795 Apache CXF: Denial of Service and sensitive data exposure in logs — Apache CXFCWE-400 5.5 -2025-07-15
CVE-2025-23184 Apache CXF: Denial of Service vulnerability with temporary files — Apache CXFCWE-400 5.9 Medium2025-01-21
CVE-2024-41172 Apache CXF: Unrestricted memory consumption in CXF HTTP clients — Apache CXFCWE-401 7.5 -2024-07-19
CVE-2024-32007 Apache CXF Denial of Service vulnerability in JOSE — Apache CXFCWE-400 7.5 -2024-07-19
CVE-2024-29736 Apache CXF: SSRF vulnerability via WADL stylesheet parameter — Apache CXFCWE-918 9.1 -2024-07-19
CVE-2024-28752 Apache CXF SSRF Vulnerability using the Aegis databinding — Apache CXFCWE-918 9.1 -2024-03-15
CVE-2022-46364 Apache CXF SSRF Vulnerability — Apache CXFCWE-918 9.1 -2022-12-13
CVE-2022-46363 Apache CXF directory listing / code exfiltration — Apache CXFCWE-20 9.1 -2022-12-13
CVE-2021-30468 Apache CXF Denial of service vulnerability in parsing JSON via JsonMapObjectReaderWriter — Apache CXFCWE-400 7.5 -2021-06-16
CVE-2021-22696 OAuth 2 authorization service vulnerable to DDos attacks — Apache CXFCWE-918 9.1 -2021-04-02
CVE-2020-13954 Apache CXF Reflected XSS in the services listing page via the styleSheetPath — Apache CXFCWE-79 6.1 -2020-11-12
CVE-2018-8039 Apache CXF 安全特征问题漏洞 — Apache CXF 8.1 -2018-07-02
CVE-2017-12624 Apache CXF 安全漏洞 — Apache CXF 6.5 -2017-11-14
CVE-2017-3156 Apache CXF 信息泄露漏洞 — Apache CXF 7.5 -2017-08-10
CVE-2016-8739 Apache CXF JAX-RS 安全漏洞 — Apache CXF 9.1 -2017-08-10
CVE-2016-6812 Apache CXF 跨站脚本漏洞 — Apache CXF 7.1 -2017-08-10
CVE-2017-5656 Apache CXF 安全漏洞 — Apache CXF 7.5 -2017-04-18
CVE-2017-5653 Apache CXF JAX-RS XML Security streaming客户端安全漏洞 — Apache CXF 7.5 -2017-04-18

This page lists every published CVE security advisory associated with Apache Software Foundation. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.