Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

Apache Software Foundation — Vulnerabilities & Security Advisories 1725

Browse all 1725 CVE security advisories affecting Apache Software Foundation. AI-powered Chinese analysis, POCs, and references for each vulnerability.

The Apache Software Foundation develops and maintains open-source software, primarily known for the widely deployed Apache HTTP Server and foundational Java frameworks. Its extensive portfolio exposes a significant attack surface, evidenced by the 1717 recorded CVEs. Historically, vulnerabilities frequently involve remote code execution, cross-site scripting, and privilege escalation, often stemming from complex configuration errors or input validation failures in legacy components. While the foundation enforces rigorous security review processes, the sheer volume of projects increases the likelihood of undiscovered flaws. Notable incidents include critical flaws in Log4j, which allowed remote code execution via crafted log messages, highlighting risks in dependency management. The organization relies on community-driven patching, requiring administrators to promptly apply updates to mitigate exploitation. This model ensures transparency but demands active vigilance from users to maintain system integrity against evolving threat vectors.

CVE IDTitleCVSSSeverityPublished
CVE-2025-64775 Apache Struts: File leak in multipart request processing causes disk exhaustion (DoS) — Apache StrutsCWE-459 7.5 -2025-12-01
CVE-2025-59789 Apache bRPC: Stack Exhaustion via Unbounded Recursion in JSON Parser — Apache bRPCCWE-674 7.5AIHighAI2025-12-01
CVE-2025-59792 Apache Kvrocks: MONITOR command reveals plaintext credentials to non-admins — Apache Kvrocks 9.1 -2025-11-28
CVE-2025-59790 Apache Kvrocks: RESET command grants admin privileges — Apache KvrocksCWE-269 8.8 -2025-11-28
CVE-2025-54057 Apache SkyWalking: Stored XSS vulnerability — Apache SkyWalkingCWE-80 6.1 -2025-11-27
CVE-2025-59302 Apache CloudStack: Potential remote code execution on Javascript engine defined rules — Apache CloudStackCWE-94 7.2 -2025-11-27
CVE-2025-59454 Apache CloudStack: Lack of user permission validation leading to data leak for few APIs — Apache CloudStackCWE-200 4.3 -2025-11-27
CVE-2025-59390 Apache Druid: Kerberos authenticaton chooses a cryptographically unsecure secret if not configured explicitly. — Apache DruidCWE-338 9.8AICriticalAI2025-11-26
CVE-2025-62728 Apache Hive: SQL injection vulnerability when processing delete column statistics requests via the HMS Thrift APIs — Apache HiveCWE-89 8.8AIHighAI2025-11-26
CVE-2025-65998 Apache Syncope: Default AES key used for internal password encryption — Apache SyncopeCWE-321 6.5AIMediumAI2025-11-24
CVE-2025-64408 Apache Causeway: Java deserialization vulnerability to authenticated attackers — Apache CausewayCWE-502 8.8AIHighAI2025-11-19
CVE-2025-61623 Apache OFBiz: Reflected Cross-site Scripting — Apache OFBizCWE-79 6.1 -2025-11-12
CVE-2025-59118 Apache OFBiz: Critical Remote Command Execution via Unrestricted File Upload — Apache OFBizCWE-434 9.8 -2025-11-12
CVE-2025-64407 Apache OpenOffice: URL fetching can be used to exfiltrate arbitrary INI file values and environment variables — Apache OpenOfficeCWE-862 4.0 -2025-11-12
CVE-2025-64406 Apache OpenOffice: Possible memory corruption during CSV import — Apache OpenOfficeCWE-787 7.7 -2025-11-12
CVE-2025-64405 Apache OpenOffice: Remote documents loaded without prompt via DDE function — Apache OpenOfficeCWE-862 6.2 -2025-11-12
CVE-2025-64404 Apache OpenOffice: Remote documents loaded without prompt via background and bullet images — Apache OpenOfficeCWE-862 6.8 -2025-11-12
CVE-2025-64403 Apache OpenOffice: Remote documents loaded without prompt via "external data sources" in Calc — Apache OpenOfficeCWE-862 4.0 -2025-11-12
CVE-2025-64402 Apache OpenOffice: Remote documents loaded without prompt via OLE objects — Apache OpenOfficeCWE-862 6.2 -2025-11-12
CVE-2025-64401 Apache OpenOffice: Remote documents loaded without prompt via IFrame — Apache OpenOfficeCWE-862 7.7 -2025-11-12
CVE-2025-58337 Apache Doris-MCP-Server: Improper Access Control results in bypassing a "read-only" mode for doris-mcp-server MCP Server — Apache Doris-MCP-ServerCWE-284 4.3 -2025-11-05
CVE-2025-62232 Apache APISIX: basic-auth logs plaintext credentials at info level — Apache APISIXCWE-532 6.5 -2025-10-31
CVE-2025-54941 Apache Airflow: Command injection in "example_dag_decorator" — Apache AirflowCWE-78 8.8AIHighAI2025-10-30
CVE-2025-62402 Apache Airflow: Airflow 3 API: /api/v2/dagReports executes DAG Python in API — Apache AirflowCWE-250 8.0AIHighAI2025-10-30
CVE-2025-62503 Apache Airflow: Privilege boundary bypass in bulk APIs (create action can upsert existing Pools/Connections/Variables) — Apache AirflowCWE-250 6.5AIMediumAI2025-10-30
CVE-2025-61795 Apache Tomcat: Delayed cleaning of multi-part upload temporary files may lead to DoS — Apache TomcatCWE-404 7.5 -2025-10-27
CVE-2025-55752 Apache Tomcat: Directory traversal via rewrite with possible RCE if PUT is enabled — Apache TomcatCWE-23 9.8AICriticalAI2025-10-27
CVE-2025-55754 Apache Tomcat: console manipulation via escape sequences in log messages — Apache TomcatCWE-150 8.8 -2025-10-27
CVE-2025-57738 Apache Syncope: Remote Code Execution by delegated administrators — Apache SyncopeCWE-653 7.2AIHighAI2025-10-20
CVE-2025-47410 Apache Geode: CSRF attacks through GET requests to the Management and Monitoring REST API that can execute gfsh commands on the target system — Apache GeodeCWE-352 8.8AIHighAI2025-10-18

This page lists every published CVE security advisory associated with Apache Software Foundation. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.