Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Apache Software Foundation — Vulnerabilities & Security Advisories 2370

Browse all 2370 CVE security advisories affecting Apache Software Foundation. AI-powered Chinese analysis, POCs, and references for each vulnerability.

The Apache Software Foundation develops and maintains open-source software, primarily known for the widely deployed Apache HTTP Server and foundational Java frameworks. Its extensive portfolio exposes a significant attack surface, evidenced by the 1717 recorded CVEs. Historically, vulnerabilities frequently involve remote code execution, cross-site scripting, and privilege escalation, often stemming from complex configuration errors or input validation failures in legacy components. While the foundation enforces rigorous security review processes, the sheer volume of projects increases the likelihood of undiscovered flaws. Notable incidents include critical flaws in Log4j, which allowed remote code execution via crafted log messages, highlighting risks in dependency management. The organization relies on community-driven patching, requiring administrators to promptly apply updates to mitigate exploitation. This model ensures transparency but demands active vigilance from users to maintain system integrity against evolving threat vectors.

CVE ID Title CVSS Severity Published
CVE-2025-30675 Apache CloudStack: Unauthorised template/ISO list access to the domain/resource admins — Apache CloudStack CWE-200 4.7 Medium 2025-06-10
CVE-2025-22829 Apache CloudStack: Unauthorised access to dedicated resources in Quota plugin — Apache CloudStack CWE-269 4.3AI Medium AI 2025-06-10
CVE-2025-26521 Apache CloudStack: CKS cluster in project exposes user API keys — Apache CloudStack CWE-200 7.5AI High AI 2025-06-10
CVE-2025-47849 Apache CloudStack: Insecure access of user's API/Secret Keys in the same domain — Apache CloudStack CWE-269 7.2AI High AI 2025-06-10
CVE-2025-47713 Apache CloudStack: Domain Admin can reset Admin password in Root Domain — Apache CloudStack CWE-269 7.2AI High AI 2025-06-10
CVE-2025-27817 Apache Kafka Client: Arbitrary file read and SSRF vulnerability — Apache Kafka Client 7.5 - 2025-06-10
CVE-2025-27819 Apache Kafka: Possible RCE/Denial of service attack via SASL JAAS JndiLoginModule configuration — Apache Kafka CWE-502 8.1 - 2025-06-10
CVE-2025-27818 Apache Kafka: Possible RCE attack via SASL JAAS LdapLoginModule configuration — Apache Kafka CWE-502 8.1 - 2025-06-10
CVE-2025-27531 Apache InLong: An arbitrary file read vulnerability for JDBC — Apache InLong CWE-502 6.5AI Medium AI 2025-06-06
CVE-2025-46548 Apache Pekko Management, Apache Pekko Management, Apache Pekko Management, Akka Management, Akka Management, Akka Management: management API basic authentication is not effective — Apache Pekko Management CWE-287 9.8AI Critical AI 2025-06-03
CVE-2025-48912 Apache Superset: Improper authorization bypass on row level security via SQL Injection — Apache Superset CWE-89 6.5AI Medium AI 2025-05-30
CVE-2025-46701 Apache Tomcat: Security constraint bypass for CGI scripts — Apache Tomcat CWE-178 9.1AI Critical AI 2025-05-29
CVE-2025-48734 Apache Commons BeanUtils: PropertyUtilsBean does not suppresses an enum's declaredClass property by default — Apache Commons BeanUtils 1.x CWE-284 9.8AI Critical AI 2025-05-28
CVE-2025-27528 Apache InLong: JDBC Vulnerability for Invisible Character Bypass Leading to Arbitrary File Read — Apache InLong CWE-502 7.5AI High AI 2025-05-28
CVE-2025-27526 Apache InLong: JDBC Vulnerability For URLEncode and backspace bypass — Apache InLong CWE-502 9.8AI Critical AI 2025-05-28
CVE-2025-27522 Apache InLong: JDBC Vulnerability during verification processing — Apache InLong CWE-502 8.1AI High AI 2025-05-28
CVE-2025-35003 Apache NuttX RTOS: NuttX Bluetooth Stack HCI and UART DoS/RCE Vulnerabilities. — Apache NuttX RTOS CWE-119 8.8AI High AI 2025-05-26
CVE-2025-47436 Apache ORC: Potential Heap Buffer Overflow during C++ LZO Decompression — Apache ORC CWE-122 7.8AI High AI 2025-05-14
CVE-2025-26864 Apache IoTDB: Exposure of Sensitive Information in IoTDB OpenID Authentication — Apache IoTDB CWE-200 7.5AI High AI 2025-05-14
CVE-2025-26795 Apache IoTDB JDBC driver: Exposure of Sensitive Information in IoTDB JDBC driver — Apache IoTDB JDBC driver CWE-200 7.5AI High AI 2025-05-14
CVE-2024-24780 Apache IoTDB: Remote Code Execution with untrusted URI of User-defined function — Apache IoTDB 8.8AI High AI 2025-05-14
CVE-2025-27696 Apache Superset: Incorrect authorization leading to resource ownership takeover — Apache Superset CWE-863 6.5AI Medium AI 2025-05-13
CVE-2025-46392 Apache Commons Configuration: Uncontrolled Resource Consumption when loading untrusted configurations in 1.x — Apache Commons Configuration CWE-400 7.5AI High AI 2025-05-09
CVE-2025-27533 Apache ActiveMQ: Unchecked buffer length can cause excessive memory allocation — Apache ActiveMQ CWE-789 7.5AI High AI 2025-05-07
CVE-2025-46762 Apache Parquet Java: Potential malicious code execution from trusted packages in the parquet-avro module when reading an Avro schema from a Parquet file metadata — Apache Parquet Java CWE-73 9.8AI Critical AI 2025-05-06
CVE-2025-31651 Apache Tomcat: Bypass of rules in Rewrite Valve — Apache Tomcat CWE-116 9.1AI Critical AI 2025-04-28
CVE-2025-31650 Apache Tomcat: DoS via malformed HTTP/2 PRIORITY_UPDATE frame — Apache Tomcat CWE-459 7.5AI High AI 2025-04-28
CVE-2025-27820 Apache HttpComponents: PSL (Public Suffix List) validation bypass — Apache HttpComponents - - 2025-04-24
CVE-2025-26413 Apache Kvrocks: The server was crashed by the negative offset — Apache Kvrocks CWE-20 7.5 - 2025-04-22
CVE-2025-29953 Apache ActiveMQ NMS OpenWire Client: deserialization allowlist bypass — Apache ActiveMQ NMS OpenWire Client CWE-502 9.8 - 2025-04-18

This page lists every published CVE security advisory associated with Apache Software Foundation. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.