Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

Apache Software Foundation — Vulnerabilities & Security Advisories 1676

Browse all 1676 CVE security advisories affecting Apache Software Foundation. AI-powered Chinese analysis, POCs, and references for each vulnerability.

CVE IDTitleCVSSSeverityPublished
CVE-2025-30677 Apache Pulsar IO Kafka Connector, Apache Pulsar IO Kafka Connect Adaptor: Sensitive information logged in Pulsar's Apache Kafka Connectors — Apache Pulsar IO Kafka ConnectorCWE-532 8.1AIHighAI2025-04-09
CVE-2025-30473 Apache Airflow Common SQL Provider: Remote Code Execution via Sql Injection — Apache Airflow Common SQL ProviderCWE-89 8.8AIHighAI2025-04-07
CVE-2024-53868 Apache Traffic Server: Malformed chunked message body allows request smuggling — Apache Traffic ServerCWE-444 7.5AIHighAI2025-04-03
CVE-2025-30676 Apache OFBiz: Stored XSS Vulnerability — Apache OFBizCWE-80 6.1 -2025-04-01
CVE-2025-30177 Apache Camel: Camel-Undertow Message Header Injection via Improper Filtering — Apache Camel 7.5 -2025-04-01
CVE-2024-56325 Apache Pinot: Authentication bypass issue. If the path does not contain / and contain . authentication is not required — Apache PinotCWE-288 9.8AICriticalAI2025-04-01
CVE-2025-29868 Apache Answer: Using externally referenced images can leak user privacy. — Apache AnswerCWE-495 6.5 -2025-04-01
CVE-2025-30065 Apache Parquet Java: Arbitrary code execution in the parquet-avro module when reading an Avro schema from a Parquet file metadata — Apache Parquet JavaCWE-502 9.8AICriticalAI2025-04-01
CVE-2025-27427 Apache ActiveMQ Artemis: Address routing-type can be updated by user without the createAddress permission — Apache ActiveMQ ArtemisCWE-863 6.5 -2025-04-01
CVE-2025-30067 Apache Kylin: The remote code execution via jdbc url — Apache KylinCWE-94 9.8AICriticalAI2025-03-27
CVE-2024-48944 Apache Kylin: SSRF vulnerability in the diagnosis api — Apache KylinCWE-918 4.4AIMediumAI2025-03-27
CVE-2024-53679 Apache VCL: XSS vulnerability in User Lookup impacting user privileges — Apache VCLCWE-79 5.4AIMediumAI2025-03-25
CVE-2024-53678 Apache VCL: SQL injection vulnerability in New Block Allocation form — Apache VCLCWE-89 5.3AIMediumAI2025-03-25
CVE-2025-27553 Apache Commons VFS: Possible path traversal issue when using NameScope.DESCENDENT — Apache Commons VFSCWE-23--2025-03-23
CVE-2025-30474 Apache Commons VFS: Failing to find an FTP file can reveal the URI's password in an error message — Apache Commons VFSCWE-200 7.5 -2025-03-23
CVE-2025-26796 Apache Oozie: XSS in Oozie Web Console — Apache OozieCWE-79 6.1 -2025-03-22
CVE-2025-27888 Apache Druid: Server-Side Request Forgery and Cross-Site Scripting — Apache DruidCWE-918 5.4 -2025-03-20
CVE-2024-54016 compression bomb attack in Apache Seata Server — Apache Seata (incubating)CWE-409 9.1 -2025-03-20
CVE-2024-47552 Apache Seata (incubating): Deserialization of untrusted Data in jraft mode in Apache Seata Server — Apache Seata (incubating)CWE-502 9.8 -2025-03-20
CVE-2025-27018 Apache Airflow MySQL Provider: SQL injection in MySQL provider core function — Apache Airflow MySQL ProviderCWE-89 8.8 -2025-03-19
CVE-2025-27017 Apache NiFi: Potential Insertion of MongoDB Password in Provenance Record — Apache NiFiCWE-538 6.5 -2025-03-12
CVE-2025-27867 Apache Felix HTTP Webconsole Plugin: XSS in HTTP Webconsole Plugin — Apache Felix HTTP Webconsole PluginCWE-79 6.1 -2025-03-12
CVE-2025-29891 Apache Camel: Camel Message Header Injection through request parameters — Apache CamelCWE-164 8.2 -2025-03-12
CVE-2025-24813 Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT — Apache TomcatCWE-44 8.8 -2025-03-10
CVE-2025-26865 Apache OFBiz: Server-Side Template Injection affecting the ecommerce plugin leading to possible RCE — Apache OFBizCWE-1336 9.8 -2025-03-10
CVE-2025-27636 Apache Camel: Camel Message Header Injection via Improper Filtering — Apache Camel 7.5 -2025-03-09
CVE-2024-38311 Apache Traffic Server: Request smuggling via pipelining after a chunked message body — Apache Traffic ServerCWE-20 7.5 -2025-03-06
CVE-2024-56195 Apache Traffic Server: Intercept plugins are not access controlled — Apache Traffic ServerCWE-284--2025-03-06
CVE-2024-56196 Apache Traffic Server: ACL is not fully compatible with older versions — Apache Traffic ServerCWE-284--2025-03-06
CVE-2024-56202 Apache Traffic Server: Expect header field can unreasonably retain resource — Apache Traffic ServerCWE-440 9.1 -2025-03-06

This page lists every published CVE security advisory associated with Apache Software Foundation. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.