Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

Apache Software Foundation — Vulnerabilities & Security Advisories 1725

Browse all 1725 CVE security advisories affecting Apache Software Foundation. AI-powered Chinese analysis, POCs, and references for each vulnerability.

The Apache Software Foundation develops and maintains open-source software, primarily known for the widely deployed Apache HTTP Server and foundational Java frameworks. Its extensive portfolio exposes a significant attack surface, evidenced by the 1717 recorded CVEs. Historically, vulnerabilities frequently involve remote code execution, cross-site scripting, and privilege escalation, often stemming from complex configuration errors or input validation failures in legacy components. While the foundation enforces rigorous security review processes, the sheer volume of projects increases the likelihood of undiscovered flaws. Notable incidents include critical flaws in Log4j, which allowed remote code execution via crafted log messages, highlighting risks in dependency management. The organization relies on community-driven patching, requiring administrators to promptly apply updates to mitigate exploitation. This model ensures transparency but demands active vigilance from users to maintain system integrity against evolving threat vectors.

Found 17 results / 1725Clear Filters
CVE IDTitleCVSSSeverityPublished
CVE-2025-47410 Apache Geode: CSRF attacks through GET requests to the Management and Monitoring REST API that can execute gfsh commands on the target system — Apache GeodeCWE-352 8.8AIHighAI2025-10-18
CVE-2024-44088 Apache Geode: Reflected XSS — Apache GeodeCWE-79 6.1AIMediumAI2025-10-14
CVE-2022-34870 Apache Geode stored Cross-Site Scripting (XSS) via data injection vulnerability in Pulse web application — Apache Geode 5.4 -2022-10-25
CVE-2022-37023 Apache Geode deserialization of untrusted data flaw when using REST API on Java 8 or Java 11 — Apache GeodeCWE-502 8.8 -2022-08-31
CVE-2022-37022 Apache Geode deserialization of untrusted data flaw when using JMX over RMI on Java 11 — Apache GeodeCWE-502 9.8 -2022-08-31
CVE-2022-37021 Apache Geode deserialization of untrusted data flaw when using JMX over RMI on Java 8. — Apache GeodeCWE-502 9.8 -2022-08-31
CVE-2021-34797 Apache Geode project log file redaction of sensitive information vulnerability — Apache GeodeCWE-532 7.5 -2022-01-04
CVE-2017-15695 Apache Geode server 权限许可和访问控制问题漏洞 — Apache Geode 8.8 -2018-06-13
CVE-2017-15692 Apache Geode 安全漏洞 — Apache Geode 9.8 -2018-02-27
CVE-2017-15693 Apache Geode 安全漏洞 — Apache Geode 7.5 -2018-02-27
CVE-2017-15696 Apache Geode cluster 安全漏洞 — Apache Geode 7.5 -2018-02-26
CVE-2017-9796 Apache Geode cluster 安全漏洞 — Apache Geode 5.3 -2018-01-10
CVE-2017-9795 Apache Geode cluster 安全漏洞 — Apache Geode 7.5 -2018-01-10
CVE-2017-12622 Apache Geode cluster 安全漏洞 — Apache Geode 8.1 -2018-01-10
CVE-2017-9797 Apache Geode cluster 安全漏洞 — Apache Geode 6.5 -2017-10-02
CVE-2017-9794 Apache Geode 信息泄露漏洞 — Apache Geode 4.3 -2017-09-29
CVE-2017-5649 Apache Geode 安全漏洞 — Apache Geode 6.5 -2017-04-04

This page lists every published CVE security advisory associated with Apache Software Foundation. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.