Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Apache Software Foundation — Vulnerabilities & Security Advisories 2370

Browse all 2370 CVE security advisories affecting Apache Software Foundation. AI-powered Chinese analysis, POCs, and references for each vulnerability.

The Apache Software Foundation develops and maintains open-source software, primarily known for the widely deployed Apache HTTP Server and foundational Java frameworks. Its extensive portfolio exposes a significant attack surface, evidenced by the 1717 recorded CVEs. Historically, vulnerabilities frequently involve remote code execution, cross-site scripting, and privilege escalation, often stemming from complex configuration errors or input validation failures in legacy components. While the foundation enforces rigorous security review processes, the sheer volume of projects increases the likelihood of undiscovered flaws. Notable incidents include critical flaws in Log4j, which allowed remote code execution via crafted log messages, highlighting risks in dependency management. The organization relies on community-driven patching, requiring administrators to promptly apply updates to mitigate exploitation. This model ensures transparency but demands active vigilance from users to maintain system integrity against evolving threat vectors.

CVE ID Title CVSS Severity Published
CVE-2025-48208 Apache HertzBeat (incubating): Jmx JNDI injection vulnerability — Apache HertzBeat (incubating) CWE-90 8.8AI High AI 2025-09-09
CVE-2025-24404 Apache HertzBeat (incubating): RCE by parse http sitemap xml response — Apache HertzBeat (incubating) CWE-91 8.8AI High AI 2025-09-09
CVE-2025-58782 Apache Jackrabbit Core, Apache Jackrabbit JCR Commons: JNDI injection risk with JndiRepositoryFactory — Apache Jackrabbit Core CWE-502 9.8AI Critical AI 2025-09-08
CVE-2024-43166 Apache DolphinScheduler 安全漏洞 — Apache DolphinScheduler CWE-276 9.8AI Critical AI 2025-09-03
CVE-2024-43115 Apache DolphinScheduler: Alert Script Attack — Apache DolphinScheduler CWE-20 8.8AI High AI 2025-09-03
CVE-2025-26467 Apache Cassandra: User with MODIFY permission on ALL KEYSPACES can escalate privileges to superuser via unsafe actions (4.0.16 only) — Apache Cassandra CWE-267 8.8 - 2025-08-25
CVE-2025-54812 Apache Log4cxx: Improper HTML escaping in HTMLLayout — Apache Log4cxx CWE-117 6.1AI Medium AI 2025-08-22
CVE-2025-54813 Apache Log4cxx: Improper escaping with JSONLayout — Apache Log4cxx CWE-117 5.3AI Medium AI 2025-08-22
CVE-2024-48988 Apache StreamPark: SQL injection vulnerability — Apache StreamPark CWE-564 9.8 - 2025-08-22
CVE-2025-54988 Apache Tika PDF parser module: XXE vulnerability in PDFParser's handling of XFA — Apache Tika PDF parser module CWE-611 8.4 High 2025-08-20
CVE-2024-39954 Apache EventMesh Runtime: SSRF — Apache EventMesh Runtime CWE-918 9.1 - 2025-08-20
CVE-2025-53192 Apache Commons OGNL: Expression Injection leading to RCE — Apache Commons OGNL CWE-146 9.8 - 2025-08-18
CVE-2025-54466 Apache OFBiz: RCE Vulnerability in scrum plugin — Apache OFBiz CWE-94 9.8AI Critical AI 2025-08-15
CVE-2025-55675 Apache Superset: Incorrect datasource authorization on REST API — Apache Superset CWE-285 4.3AI Medium AI 2025-08-14
CVE-2025-55674 Apache Superset: Improper SQL authorisation, parse not checking for specific engine functions — Apache Superset CWE-89 6.5AI Medium AI 2025-08-14
CVE-2025-55672 Apache Superset: Stored XSS on charts metadata — Apache Superset CWE-80 5.4AI Medium AI 2025-08-14
CVE-2025-55673 Apache Superset: Metadata exposure in embedded charts — Apache Superset CWE-200 3.5AI Low AI 2025-08-14
CVE-2025-54472 Apache bRPC: Redis Parser Remote Denial of Service — Apache bRPC CWE-400 7.5AI High AI 2025-08-14
CVE-2025-55668 Apache Tomcat: session fixation via rewrite valve — Apache Tomcat CWE-384 9.8 - 2025-08-13
CVE-2025-48989 Apache Tomcat: h2 DoS - Made You Reset — Apache Tomcat CWE-404 7.5AI High AI 2025-08-13
CVE-2025-53606 Apache Seata (incubating): Deserialization of untrusted Data in Apache Seata Server — Apache Seata (incubating) CWE-502 9.8 - 2025-08-08
CVE-2025-48913 Apache CXF: Untrusted JMS configuration can lead to RCE — Apache CXF CWE-20 9.8 - 2025-08-08
CVE-2024-51775 Apache Zeppelin: Command Injection via CSWSH — Apache Zeppelin CWE-1385 5.3 - 2025-08-03
CVE-2024-41177 Apache Zeppelin: XSS in the Helium module — Apache Zeppelin CWE-79 6.1 - 2025-08-03
CVE-2024-52279 Apache Zeppelin: Arbitrary file read by adding malicious JDBC connection string — Apache Zeppelin CWE-20 9.1 - 2025-08-03
CVE-2025-24854 Apache JSPWiki: Cross-Site Scripting (XSS) in JSPWiki Image plugin — Apache JSPWiki CWE-79 6.1AI Medium AI 2025-07-31
CVE-2025-24853 Apache JSPWiki: Cross-Site Scripting (XSS) in JSPWiki Header Link processing — Apache JSPWiki CWE-79 4.7AI Medium AI 2025-07-31
CVE-2025-54656 Apache Struts Extras: Improper Output Neutralization for Logs — Apache Struts Extras CWE-117 5.3AI Medium AI 2025-07-30
CVE-2025-54090 Apache HTTP Server: 'RewriteCond expr' always evaluates to true in 2.4.64 — Apache HTTP Server CWE-253 7.5 - 2025-07-23
CVE-2025-50151 Apache Jena: Configuration files uploaded by administrative users are not check properly — Apache Jena CWE-20 7.2 - 2025-07-21

This page lists every published CVE security advisory associated with Apache Software Foundation. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.