Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Apache — Vulnerabilities & Security Advisories 91

Browse all 91 CVE security advisories affecting Apache. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Apache software projects serve as foundational infrastructure for the modern internet, primarily powering web servers and application frameworks. With 91 recorded CVEs, these components frequently exhibit vulnerabilities in input validation and configuration management. Historically, common flaw classes include remote code execution, cross-site scripting, and privilege escalation, often stemming from complex codebases and extensive plugin ecosystems. Security characteristics vary significantly across individual projects, though many rely on community-driven patching rather than centralized corporate support. Major incidents have occasionally exposed critical weaknesses in default configurations, allowing unauthorized access or data exfiltration. The sheer volume of deployments amplifies the impact of any single vulnerability, making timely updates essential. While not inherently insecure, the diversity of implementations requires rigorous auditing. Organizations must prioritize vulnerability management strategies to mitigate risks associated with these widely used, yet complex, open-source tools.

CriticalCVE-2024-238972026-08-07
Apache ActiveMQ CVE-2024-23897远程代码执行漏洞分析及POC
UnknownCVE-2024-238972026-08-05
Apache HTTP Server mod_proxy绕过漏洞(CVE-2024-23897)分析
CriticalCVE-2024-238972026-08-04
Apache ActiveMQ CVE-2024-23897 RCE漏洞及POC
High2026-08-03
SAML断言签名与完整性验证绕过漏洞修复方案
Medium2026-08-02
Tomcat 7.x Base64解码拒绝服务漏洞分析
CriticalCVE-2024-238972026-08-02
Apache ActiveMQ CVE-2024-23897远程代码执行漏洞及POC
CriticalCVE-2024-238972026-08-01
Apache HTTP Server CVE-2024-23897 RCE漏洞公告及POC
High2026-07-31
[MINOR] Reject traversal segments in note and folder paths by jongyoul · Pull Request #5227 · apache/zeppelin · GitHub
Low2026-07-31
[MINOR] Reject traversal segments in note and folder paths by jongyoul · Pull Request #5248 · apache/zeppelin · GitHub
MediumGHSA-mw6x-5p78-w6332026-07-31
[MINOR] Tighten origin and content-type handling in REST/WebSocket layer by jongyoul · Pull Request #5229 · apache/zeppe
High2026-07-31
Apache Xerces-J Base64解码漏洞(RCE/DoS)及补丁说明
CriticalCVE-2024-238972026-07-30
Apache ActiveMQ CVE-2024-23897 RCE漏洞分析
HighCVE-2024-238972026-07-30
Apache HTTP Server CVE-2024-23897 拒绝服务漏洞及POC
High2026-07-29
Verify Azure AD OAuth id_token signatures by default in FAB auth manager by potiuk · Pull Request #69374 · apache/airflo
CriticalCVE-2023-466042026-07-25
Apache ActiveMQ CVE-2023-46604 远程代码执行漏洞及POC
High2026-07-24
nimble/host: Refactor GATT Read Multiple Variable Char Value response · apache/mynewt-nimble@fae6a48 · GitHub
CriticalCVE-2023-466042026-07-24
Apache ActiveMQ CVE-2023-46604 远程代码执行漏洞分析及POC
HighCVE-2024-238972026-07-23
Apache HTTP Server CVE-2024-23897 DoS漏洞及PoC分析
UnknownUSN-8589-12026-07-22
USN-8589-1: Apache HTTP Server vulnerabilities | Ubuntu security notices | Ubuntu
HighUSN-8571-12026-07-20
USN-8571-1: Apache HTTP Server vulnerabilities | Ubuntu security notices | Ubuntu

Showing up to 20 recent security advisories. View all →

This page lists every published CVE security advisory associated with Apache. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.