Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

Apache Software Foundation — Vulnerabilities & Security Advisories 1725

Browse all 1725 CVE security advisories affecting Apache Software Foundation. AI-powered Chinese analysis, POCs, and references for each vulnerability.

The Apache Software Foundation develops and maintains open-source software, primarily known for the widely deployed Apache HTTP Server and foundational Java frameworks. Its extensive portfolio exposes a significant attack surface, evidenced by the 1717 recorded CVEs. Historically, vulnerabilities frequently involve remote code execution, cross-site scripting, and privilege escalation, often stemming from complex configuration errors or input validation failures in legacy components. While the foundation enforces rigorous security review processes, the sheer volume of projects increases the likelihood of undiscovered flaws. Notable incidents include critical flaws in Log4j, which allowed remote code execution via crafted log messages, highlighting risks in dependency management. The organization relies on community-driven patching, requiring administrators to promptly apply updates to mitigate exploitation. This model ensures transparency but demands active vigilance from users to maintain system integrity against evolving threat vectors.

CVE IDTitleCVSSSeverityPublished
CVE-2024-53679 Apache VCL: XSS vulnerability in User Lookup impacting user privileges — Apache VCLCWE-79 5.4AIMediumAI2025-03-25
CVE-2024-53678 Apache VCL: SQL injection vulnerability in New Block Allocation form — Apache VCLCWE-89 5.3AIMediumAI2025-03-25
CVE-2025-27553 Apache Commons VFS: Possible path traversal issue when using NameScope.DESCENDENT — Apache Commons VFSCWE-23--2025-03-23
CVE-2025-30474 Apache Commons VFS: Failing to find an FTP file can reveal the URI's password in an error message — Apache Commons VFSCWE-200 7.5 -2025-03-23
CVE-2025-26796 Apache Oozie: XSS in Oozie Web Console — Apache OozieCWE-79 6.1 -2025-03-22
CVE-2025-27888 Apache Druid: Server-Side Request Forgery and Cross-Site Scripting — Apache DruidCWE-918 5.4 -2025-03-20
CVE-2024-54016 compression bomb attack in Apache Seata Server — Apache Seata (incubating)CWE-409 9.1 -2025-03-20
CVE-2024-47552 Apache Seata (incubating): Deserialization of untrusted Data in jraft mode in Apache Seata Server — Apache Seata (incubating)CWE-502 9.8 -2025-03-20
CVE-2025-27018 Apache Airflow MySQL Provider: SQL injection in MySQL provider core function — Apache Airflow MySQL ProviderCWE-89 8.8 -2025-03-19
CVE-2025-27017 Apache NiFi: Potential Insertion of MongoDB Password in Provenance Record — Apache NiFiCWE-538 6.5 -2025-03-12
CVE-2025-27867 Apache Felix HTTP Webconsole Plugin: XSS in HTTP Webconsole Plugin — Apache Felix HTTP Webconsole PluginCWE-79 6.1 -2025-03-12
CVE-2025-29891 Apache Camel: Camel Message Header Injection through request parameters — Apache CamelCWE-164 8.2 -2025-03-12
CVE-2025-24813 Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT — Apache TomcatCWE-44 8.8 -2025-03-10
CVE-2025-26865 Apache OFBiz: Server-Side Template Injection affecting the ecommerce plugin leading to possible RCE — Apache OFBizCWE-1336 9.8 -2025-03-10
CVE-2025-27636 Apache Camel: Camel Message Header Injection via Improper Filtering — Apache Camel 7.5 -2025-03-09
CVE-2024-38311 Apache Traffic Server: Request smuggling via pipelining after a chunked message body — Apache Traffic ServerCWE-20 7.5 -2025-03-06
CVE-2024-56195 Apache Traffic Server: Intercept plugins are not access controlled — Apache Traffic ServerCWE-284--2025-03-06
CVE-2024-56196 Apache Traffic Server: ACL is not fully compatible with older versions — Apache Traffic ServerCWE-284--2025-03-06
CVE-2024-56202 Apache Traffic Server: Expect header field can unreasonably retain resource — Apache Traffic ServerCWE-440 9.1 -2025-03-06
CVE-2024-55532 Apache Ranger: Improper Neutralization of Formula Elements in a CSV File — Apache RangerCWE-1236 9.8 -2025-03-03
CVE-2024-24778 Apache StreamPipes: Resources Permission Escalation — Apache StreamPipesCWE-269 6.5 -2025-03-03
CVE-2024-56180 Apache EventMesh: raft Hessian Deserialization Vulnerability allowing remote code execution — Apache EventMeshCWE-502 9.8 -2025-02-14
CVE-2024-52577 Apache Ignite: Possible RCE when deserializing incoming messages by the server node — Apache IgniteCWE-502 8.1 -2025-02-14
CVE-2024-46910 Apache Atlas: An authenticated user can perform XSS and potentially impersonate another user — Apache AtlasCWE-80 5.4 -2025-02-13
CVE-2024-32838 Apache Fineract: SQL injection vulnerabilities in offices API endpoint — Apache FineractCWE-89 8.8 -2025-02-12
CVE-2025-25247 Apache Felix Webconsole: XSS in services console — Apache Felix WebconsoleCWE-79 6.1 -2025-02-10
CVE-2025-25069 Apache Kvrocks: Cross-Protocol Scripting Vulnerability — Apache KvrocksCWE-115 7.1 -2025-02-07
CVE-2022-31764 Apache ShardingSphere ElasticJob-UI allows RCE via event trace data source JDBC — Apache ShardingSphere ElasticJob-UICWE-913 9.8 -2025-02-06
CVE-2024-37358 Apache James: denial of service through the use of IMAP literals — Apache James serverCWE-770 8.6 High2025-02-06
CVE-2024-45626 Apache James: denial of service through JMAP HTML to text conversion — Apache James serverCWE-400 6.5 Medium2025-02-06

This page lists every published CVE security advisory associated with Apache Software Foundation. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.