Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

Apache Software Foundation — Vulnerabilities & Security Advisories 1725

Browse all 1725 CVE security advisories affecting Apache Software Foundation. AI-powered Chinese analysis, POCs, and references for each vulnerability.

The Apache Software Foundation develops and maintains open-source software, primarily known for the widely deployed Apache HTTP Server and foundational Java frameworks. Its extensive portfolio exposes a significant attack surface, evidenced by the 1717 recorded CVEs. Historically, vulnerabilities frequently involve remote code execution, cross-site scripting, and privilege escalation, often stemming from complex configuration errors or input validation failures in legacy components. While the foundation enforces rigorous security review processes, the sheer volume of projects increases the likelihood of undiscovered flaws. Notable incidents include critical flaws in Log4j, which allowed remote code execution via crafted log messages, highlighting risks in dependency management. The organization relies on community-driven patching, requiring administrators to promptly apply updates to mitigate exploitation. This model ensures transparency but demands active vigilance from users to maintain system integrity against evolving threat vectors.

Found 31 results / 1725Clear Filters
CVE IDTitleCVSSSeverityPublished
CVE-2025-27531 Apache InLong: An arbitrary file read vulnerability for JDBC — Apache InLongCWE-502 6.5AIMediumAI2025-06-06
CVE-2025-27528 Apache InLong: JDBC Vulnerability for Invisible Character Bypass Leading to Arbitrary File Read — Apache InLongCWE-502 7.5AIHighAI2025-05-28
CVE-2025-27526 Apache InLong: JDBC Vulnerability For URLEncode and backspace bypass — Apache InLongCWE-502 9.8AICriticalAI2025-05-28
CVE-2025-27522 Apache InLong: JDBC Vulnerability during verification processing — Apache InLongCWE-502 8.1AIHighAI2025-05-28
CVE-2024-26579 Apache Inlong JDBC Vulnerability — Apache InLongCWE-502 9.8AICriticalAI2024-05-08
CVE-2024-26580 Apache InLong: Logged-in user could exploit an arbitrary file read vulnerability — Apache InLongCWE-502 9.1AICriticalAI2024-03-06
CVE-2023-51784 Apache InLong: Remote Code Execution vulnerability in Apache InLong Manager — Apache InLongCWE-94 9.8AICriticalAI2024-01-03
CVE-2023-51785 Apache InLong: Arbitrary File Read Vulnerability in Apache InLong Manager — Apache InLongCWE-502 7.5AIHighAI2024-01-03
CVE-2023-46227 Apache inlong has an Arbitrary File Read Vulnerability — Apache InLongCWE-502 9.8 -2023-10-19
CVE-2023-43666 Apache InLong: General user Unauthorized access User Management — Apache InLongCWE-345 6.5 -2023-10-16
CVE-2023-43667 Apache InLong: Log Injection in Global functions — Apache InLongCWE-74 5.3 -2023-10-16
CVE-2023-43668 Apache InLong: Jdbc Connection Security Bypass in InLong — Apache InLongCWE-639 9.8 -2023-10-16
CVE-2023-35088 Apache InLong: SQL injection in audit endpoint — Apache InLongCWE-89 9.8 -2023-07-25
CVE-2023-34434 Apache InLong: JDBC URL bypassing by allowLoadLocalInfileInPath param — Apache InLongCWE-502 7.5 -2023-07-25
CVE-2023-34189 Apache InLong: General user can delete and update process — Apache InLongCWE-668 9.1 -2023-07-25
CVE-2023-31062 Apache InLong: Privilege escalation vulnerability for InLong — Apache InLongCWE-269 8.8 -2023-05-22
CVE-2023-31064 Apache InLong: Insecurity direct object references cancelling applications — Apache InLongCWE-552 6.5 -2023-05-22
CVE-2023-31065 Apache InLong: Insufficient Session Expiration in InLong — Apache InLongCWE-613 9.8 -2023-05-22
CVE-2023-31066 Apache InLong: Insecure direct object references for inlong sources — Apache InLongCWE-552 8.1 -2023-05-22
CVE-2023-31098 Apache InLong: Weak Password Implementation in InLong — Apache InLongCWE-521 7.4 -2023-05-22
CVE-2023-31101 Apache InLong: Users who joined later can see the data of deleted users — Apache InLongCWE-1188 5.3 -2023-05-22
CVE-2023-31103 Apache InLong: Attackers can change the immutable name and type of cluster — Apache InLongCWE-668 8.2 -2023-05-22
CVE-2023-31206 Apache InLong: Attackers can change the immutable name and type of nodes — Apache InLongCWE-668 8.2 -2023-05-22
CVE-2023-31453 Apache InLong: IDOR make users can delete others' subscription — Apache InLongCWE-732 7.5 -2023-05-22
CVE-2023-31454 Apache InLong: IDOR make users can bind any cluster — Apache InLongCWE-732 9.8 -2023-05-22
CVE-2023-31058 Apache InLong: JDBC URL bypassing by adding blanks — Apache InLongCWE-502 9.8 -2023-05-22
CVE-2023-30465 Apache InLong: SQL injection in apache inLong 1.5.0 — Apache InLongCWE-89 5.3 -2023-04-11
CVE-2023-27296 Apache InLong: JDBC Deserialization Vulnerability in InLong — Apache InLongCWE-502 8.8 -2023-03-27
CVE-2023-24997 Apache InLong: Jdbc Connection Security Bypass — Apache InLongCWE-502 9.8 -2023-02-01
CVE-2023-24977 Apache InLong: Jdbc Connection causes arbitrary file reading in InLong — Apache InLongCWE-125 7.5 -2023-02-01

This page lists every published CVE security advisory associated with Apache Software Foundation. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.