Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

Apache Software Foundation — Vulnerabilities & Security Advisories 1676

Browse all 1676 CVE security advisories affecting Apache Software Foundation. AI-powered Chinese analysis, POCs, and references for each vulnerability.

CVE IDTitleCVSSSeverityPublished
CVE-2024-55532 Apache Ranger: Improper Neutralization of Formula Elements in a CSV File — Apache RangerCWE-1236 9.8 -2025-03-03
CVE-2024-24778 Apache StreamPipes: Resources Permission Escalation — Apache StreamPipesCWE-269 6.5 -2025-03-03
CVE-2024-56180 Apache EventMesh: raft Hessian Deserialization Vulnerability allowing remote code execution — Apache EventMeshCWE-502 9.8 -2025-02-14
CVE-2024-52577 Apache Ignite: Possible RCE when deserializing incoming messages by the server node — Apache IgniteCWE-502 8.1 -2025-02-14
CVE-2024-46910 Apache Atlas: An authenticated user can perform XSS and potentially impersonate another user — Apache AtlasCWE-80 5.4 -2025-02-13
CVE-2024-32838 Apache Fineract: SQL injection vulnerabilities in offices API endpoint — Apache FineractCWE-89 8.8 -2025-02-12
CVE-2025-25247 Apache Felix Webconsole: XSS in services console — Apache Felix WebconsoleCWE-79 6.1 -2025-02-10
CVE-2025-25069 Apache Kvrocks: Cross-Protocol Scripting Vulnerability — Apache KvrocksCWE-115 7.1 -2025-02-07
CVE-2022-31764 Apache ShardingSphere ElasticJob-UI allows RCE via event trace data source JDBC — Apache ShardingSphere ElasticJob-UICWE-913 9.8 -2025-02-06
CVE-2024-37358 Apache James: denial of service through the use of IMAP literals — Apache James serverCWE-770 8.6 High2025-02-06
CVE-2024-45626 Apache James: denial of service through JMAP HTML to text conversion — Apache James serverCWE-400 6.5 Medium2025-02-06
CVE-2024-48019 Apache Doris: allows admin users to read arbitrary files through the REST API — Apache DorisCWE-22 4.9 -2025-02-04
CVE-2024-27137 Apache Cassandra: unrestricted deserialization of JMX authentication credentials — Apache Cassandra 7.0 -2025-02-04
CVE-2025-24860 Apache Cassandra: CassandraNetworkAuthorizer and CassandraCIDRAuthorizer can be bypassed allowing access to different network regions — Apache CassandraCWE-863 6.5 -2025-02-04
CVE-2025-23015 Apache Cassandra: User with MODIFY permission on ALL KEYSPACES can escalate privileges to superuser via unsafe actions — Apache CassandraCWE-267 8.8 -2025-02-04
CVE-2024-29869 Apache Hive: Credentials file created with non restrictive permissions — Apache HiveCWE-732 6.5 -2025-01-28
CVE-2024-23953 Apache Hive: Timing Attack Against Signature in LLAP util — Apache HiveCWE-208 6.5 -2025-01-28
CVE-2025-24783 Apache Cocoon: continuations may not be private — Apache CocoonCWE-335 5.3 -2025-01-27
CVE-2025-24814 Apache Solr: Core-creation with "trusted" configset can use arbitrary untrusted files — Apache SolrCWE-250 9.8 -2025-01-27
CVE-2024-52012 Apache Solr: Configset upload on Windows allows arbitrary path write-access — Apache SolrCWE-23 7.7 -2025-01-27
CVE-2024-53299 Apache Wicket: An attacker can intentionally trigger a memory leak — Apache WicketCWE-400 7.5 -2025-01-23
CVE-2024-45479 Apache Ranger: SSRF in Edit Service page - Add logic to filter requests to localhost — Apache RangerCWE-918 5.3 -2025-01-21
CVE-2024-45478 Apache Ranger: Stored XSS in Edit Service page - Add logic to validate user input — Apache RangerCWE-79 5.4 -2025-01-21
CVE-2024-51941 Apache Ambari: Remote Code Injection in Ambari Metrics and AMS Alerts — Apache AmbariCWE-94 8.8 -2025-01-21
CVE-2025-23196 Apache Ambari: Code Injection Vulnerability in Ambari Alert Definition — Apache AmbariCWE-77 8.8 -2025-01-21
CVE-2025-23195 Apache Ambari: XML External Entity (XXE) Vulnerability in Ambari/Oozie — Apache AmbariCWE-611 7.5 -2025-01-21
CVE-2025-23184 Apache CXF: Denial of Service vulnerability with temporary files — Apache CXFCWE-400 5.9 Medium2025-01-21
CVE-2024-45627 Apache Linkis Metadata Query Service JDBC: JDBC Datasource Module with Mysql has file read vulnerability — Apache Linkis Metadata Query Service JDBCCWE-552 6.5 -2025-01-14
CVE-2025-22828 Apache CloudStack: Unauthorised access to annotations — Apache CloudStackCWE-200 4.2 -2025-01-13
CVE-2024-45033 Apache Airflow Fab Provider: Application does not invalidate session after password change via Airflow cli — Apache Airflow Fab ProviderCWE-613 8.8 -2025-01-08

This page lists every published CVE security advisory associated with Apache Software Foundation. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.