Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

Apache Software Foundation — Vulnerabilities & Security Advisories 1676

Browse all 1676 CVE security advisories affecting Apache Software Foundation. AI-powered Chinese analysis, POCs, and references for each vulnerability.

CVE IDTitleCVSSSeverityPublished
CVE-2022-28730 Apache JSPWiki Cross-site scripting vulnerability on AJAXPreview.jsp — Apache JSPWiki 6.1 -2022-08-04
CVE-2022-27166 XSS vulnerability on XHRHtml2Markup.jsp in JSPWiki 2.11.2 — Apache JSPWiki 6.1 -2022-08-04
CVE-2022-36364 Apache Calcite Avatica JDBC driver `httpclient_impl` connection property can be used as an RCE vector — Apache Calcite AvaticaCWE-665 8.8 -2022-07-28
CVE-2022-24294 ReDoS in Apache MXNet RTC Module — Apache MXNetCWE-400 7.5 -2022-07-24
CVE-2022-34169 Apache Xalan Java XSLT library is vulnerable to an integer truncation issue when processing malicious XSLT stylesheets — Apache Xalan-J 7.5 -2022-07-19
CVE-2022-35741 Apache CloudStack SAML Single Sign-On XXE — Apache CloudStack 9.8 -2022-07-18
CVE-2022-36127 Service unavailability impact in NodeJS agent(version <= 0.5.0) — Apache SkyWalking NodeJS Agent 7.5 -2022-07-18
CVE-2022-33891 Apache Spark shell command injection vulnerability via Spark UI — Apache SparkCWE-78 8.8 -2022-07-18
CVE-2021-34538 Apache Hive Security vulnerability in Hive with UDFs — Apache HiveCWE-306 7.5 -2022-07-16
CVE-2022-31781 Regular Expression Denial of Service (ReDoS) in ContentType.java. (GHSL-2022-022) — Apache TapestryCWE-1333 7.5 -2022-07-13
CVE-2022-28889 Clickjacking in the web console — Apache DruidCWE-1021 4.3 -2022-07-07
CVE-2021-44791 Reflected XSS on certain HTTP endpoints — Apache DruidCWE-79 6.1 -2022-07-07
CVE-2021-37839 Improper access to dataset metadata information — Apache SupersetCWE-273 4.3 -2022-07-06
CVE-2022-32533 Apache Portals Jetspeed XSS, CSRF, SSRF, and XXE issues — Apache PortalsCWE-79 8.8 -2022-07-06
CVE-2022-33980 Apache Commons Configuration insecure interpolation defaults — Apache Commons Configuration 9.8 -2022-07-06
CVE-2022-32532 Authentication Bypass Vulnerability — Apache ShiroCWE-863 9.8 -2022-06-28
CVE-2022-33879 Incomplete fix and new regex DoS in StandardsExtractingContentHandler — Apache Tika 3.3 -2022-06-27
CVE-2022-26477 Denial of service in readExternal method — Apache SystemDSCWE-400 7.5 -2022-06-27
CVE-2022-34305 XSS in examples web application — Apache TomcatCWE-79 6.1 -2022-06-23
CVE-2022-32549 log injection in Sling logging — Apache SlingCWE-117 5.3 -2022-06-22
CVE-2022-33140 Improper Neutralization of Command Elements in Shell User Group Provider — Apache NiFiCWE-78 8.8 -2022-06-15
CVE-2021-33036 Apache Hadoop Privilege escalation vulnerability — Apache HadoopCWE-264 8.8 -2022-06-15
CVE-2022-25167 Apache Flume vulnerable to a JNDI RCE in JMSSource — Apache FlumeCWE-20 9.8 -2022-06-14
CVE-2021-37404 Heap buffer overflow in libhdfs native library — Apache HadoopCWE-787 9.8 -2022-06-13
CVE-2022-31813 mod_proxy X-Forwarded-For dropped by hop-by-hop mechanism — Apache HTTP ServerCWE-348 9.8 -2022-06-08
CVE-2022-30556 Information Disclosure in mod_lua with websockets — Apache HTTP ServerCWE-200--2022-06-08
CVE-2022-30522 mod_sed denial of service — Apache HTTP ServerCWE-789 7.5 -2022-06-08
CVE-2022-29404 Denial of service in mod_lua r:parsebody — Apache HTTP ServerCWE-770 7.5 -2022-06-08
CVE-2022-28615 Read beyond bounds in ap_strcmp_match() — Apache HTTP ServerCWE-190 9.1 -2022-06-08
CVE-2022-28614 read beyond bounds via ap_rwrite() — Apache HTTP ServerCWE-190 5.3 -2022-06-08

This page lists every published CVE security advisory associated with Apache Software Foundation. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.