目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1336

100%

Apache Software Foundation 厂商漏洞列表 / CVE 中文分析 2312

Apache Software Foundation 厂商相关 2312 条 CVE 漏洞,含 AI 中文分析、POC、CVSS 评分与受影响产品。

Apache Software Foundation 致力于开发和维护广泛使用的开源软件,涵盖 Web 服务器、数据库及中间件等核心领域。其项目历史上常暴露远程代码执行、跨站脚本及权限绕过等高危漏洞,多源于配置不当或代码逻辑缺陷。尽管拥有严格的代码审查机制,但部分组件仍因复杂性面临持续安全挑战。近期统计显示已收录 1717 条 CVE,凸显其生态规模与安全防护的持续重要性。

CVE ID 标题 CVSS 风险等级 Published
CVE-2026-82427 Apache Storm Nimbus 任意文件读取漏洞 — Apache Storm Nimbus CWE-22 - - 2026-09-14
CVE-2026-82428 Apache Storm 跨租户依赖Jar替换漏洞 — Apache Storm Client CWE-22 - - 2026-09-14
CVE-2026-82429 Apache Storm 本地权限提升漏洞 — Apache Storm Worker Launcher CWE-367 - - 2026-09-14
CVE-2026-82430 Apache Storm 容器命令文件本地提权至Root漏洞 — Apache Storm Worker Launcher CWE-367 - - 2026-09-14
CVE-2026-82431 Apache Storm Client 认证绕过漏洞 — Apache Storm Client CWE-863 - - 2026-09-14
CVE-2026-82433 Apache Storm 信息泄露漏洞 — Apache Storm Nimbus CWE-522 - - 2026-09-14
CVE-2026-82432 Apache Storm 配置覆盖导致的Blobstore权限绕过 — Apache Storm Nimbus CWE-863 - - 2026-09-14
CVE-2026-82434 Apache Storm 向只读用户及日志泄露ZK凭证 — Apache Storm Nimbus CWE-522 10.0 Critical 2026-09-14
CVE-2026-82435 Apache Storm Worker 远程内存耗尽漏洞 — Apache Storm Worker CWE-789 - - 2026-09-14
CVE-2026-82437 Apache Storm Logviewer 日志访问控制强制缺失漏洞 — Apache Storm Logviewer CWE-862 - - 2026-09-14
CVE-2026-82426 Apache Storm Nimbus 任意文件读取漏洞 — Apache Storm Nimbus CWE-22 - - 2026-09-14
CVE-2026-82438 Apache Storm Webapp 认证API响应暴露漏洞 — Apache Storm Webapp CWE-346 - - 2026-09-14
CVE-2026-82439 Apache Storm DRPC 未授权内存增长漏洞 — Apache Storm DRPC CWE-770 - - 2026-09-14
CVE-2026-82441 Apache Storm Nimbus 跨租户删除与拒绝服务漏洞 — Apache Storm Nimbus CWE-20 - - 2026-09-14
CVE-2026-84179 Apache Storm 拓扑页未脱敏守护进程配置泄露漏洞 — Apache Storm Nimbus CWE-522 - - 2026-09-14
CVE-2026-73191 Apache Syncope CAS服务URL注入漏洞 — Apache Syncope CWE-601 - - 2026-09-14
CVE-2026-73195 Apache Syncope CSV导出公式注入 — Apache Syncope CWE-116 - - 2026-09-14
CVE-2026-73236 Apache Syncope 委托管理跨域授权绕过漏洞 — Apache Syncope CWE-863 - - 2026-09-14
CVE-2026-73370 Apache Syncope 跨域边界协调绕过漏洞 — Apache Syncope CWE-863 - - 2026-09-14
CVE-2026-73178 Apache Syncope JWT访问令牌接管漏洞 — Apache Syncope CWE-200 - - 2026-09-14
CVE-2026-73470 Apache Syncope 非所有者角色授权越权漏洞 — Apache Syncope CWE-269 - - 2026-09-14
CVE-2026-73579 Apache Syncope 非递归Any搜索绕过Realm限制 — Apache Syncope CWE-863 - - 2026-09-14
CVE-2026-75015 Apache Syncope 嵌套密钥泄露明文的审计记录 — Apache Syncope CWE-522 - - 2026-09-14
CVE-2026-75030 Apache Syncope 组成员权限检查不完整漏洞 — Apache Syncope CWE-862 - - 2026-09-14
CVE-2026-77051 Apache Syncope SQL注入漏洞 — Apache Syncope CWE-89 - - 2026-09-14
CVE-2026-73668 Apache Syncope 机密ConnId配置跨域泄露 — Apache Syncope CWE-863 - - 2026-09-14
CVE-2026-77147 Apache Syncope Groovy沙箱逃逸漏洞 — Apache Syncope CWE-94 - - 2026-09-14
CVE-2026-77181 Apache Syncope 客户端应用更新权限失效 — Apache Syncope CWE-863 - - 2026-09-14
CVE-2026-77883 Apache Syncope JEXL导航致信息泄露 — Apache Syncope CWE-202 - - 2026-09-14
CVE-2026-78318 Apache Syncope 控制台反射型XSS漏洞 — Apache Syncope CWE-79 - - 2026-09-14

本页汇总了 Apache Software Foundation 厂商截至目前公开的全部 2312 条 CVE 漏洞。每条漏洞均包含 CVSS 评分、CWE 弱点分类、受影响产品与参考链接,并附带 AI 生成的中文分析以便快速判断风险。