Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

Apache Software Foundation — Vulnerabilities & Security Advisories 1676

Browse all 1676 CVE security advisories affecting Apache Software Foundation. AI-powered Chinese analysis, POCs, and references for each vulnerability.

CVE IDTitleCVSSSeverityPublished
CVE-2021-32566 Specific sequence of HTTP/2 frames can cause ATS to crash — Apache Traffic ServerCWE-20 7.5 -2021-06-30
CVE-2021-32565 HTTP Request Smuggling, content length with invalid charters — Apache Traffic ServerCWE-444 7.5 -2021-06-29
CVE-2021-27577 Incorrect handling of url fragment leads to cache poisoning — Apache Traffic ServerCWE-444 7.5 -2021-06-29
CVE-2021-26461 malloc, realloc and memalign implementations are vulnerable to integer wrap-arounds — Apache NuttXCWE-190 9.8 -2021-06-21
CVE-2021-30468 Apache CXF Denial of service vulnerability in parsing JSON via JsonMapObjectReaderWriter — Apache CXFCWE-400 7.5 -2021-06-16
CVE-2020-9493 Java deserialization in Chainsaw — Apache ChainsawCWE-502 9.8 -2021-06-16
CVE-2021-31618 NULL pointer dereference on specially crafted HTTP/2 request — Apache HTTP ServerCWE-476 7.5 -2021-06-15
CVE-2021-31811 A carefully crafted PDF file can trigger an OutOfMemory-Exception while loading a tiny file — Apache PDFBoxCWE-789 5.5 -2021-06-12
CVE-2021-31812 A carefully crafted PDF file can trigger an infinite loop while loading the file — Apache PDFBoxCWE-834 5.5 -2021-06-12
CVE-2021-30641 Unexpected URL matching with 'MergeSlashes OFF' — Apache HTTP Server 5.3 -2021-06-10
CVE-2021-26691 Apache HTTP Server mod_session response handling heap overflow — Apache HTTP ServerCWE-122 9.8 -2021-06-10
CVE-2021-26690 mod_session NULL pointer dereference — Apache HTTP Server 7.5 -2021-06-10
CVE-2020-13950 mod_proxy_http NULL pointer dereference — Apache HTTP Server 7.5 -2021-06-10
CVE-2020-35452 mod_auth_digest possible stack overflow by one nul byte — Apache HTTP Server 9.4 -2021-06-10
CVE-2020-13938 Improper Handling of Insufficient Privileges — Apache HTTP Server 5.5 -2021-06-10
CVE-2019-17567 mod_proxy_wstunnel tunneling of non Upgraded connections — Apache HTTP Server--2021-06-10
CVE-2021-33190 Bypass network access control — Apache APISIX DashboardCWE-307 5.3 -2021-06-08
CVE-2021-30180 Apache Dubbo RCE on customers via Condition route poisoning (Unsafe YAML unmarshaling) — Apache Dubbo 9.8 -2021-05-31
CVE-2021-30179 Apache Dubbo Pre-auth RCE via Java deserialization in the Generic filter — Apache Dubbo 9.8 -2021-05-31
CVE-2021-25640 Open Redirect or SSRF vulnerability usage of parseURL — Apache DubboCWE-918 8.2 -2021-05-31
CVE-2021-25641 Dubbo Zookeeper does not check serialization id — Apache Dubbo 9.8 -2021-05-29
CVE-2021-30181 Apache Dubbo RCE on customers via Script route poisoning (Nashorn script injection) — Apache Dubbo 9.8 -2021-05-29
CVE-2020-17514 disabled hostname verificiation — Apache Fineract 7.4 -2021-05-27
CVE-2021-22160 Authentication with JWT allows use of “none”-algorithm — Apache Pulsar 9.8 -2021-05-26
CVE-2021-23937 DNS proxy and possible amplification attack — Apache Wicket 7.5 -2021-05-25
CVE-2021-31164 Apache Unomi log injection — Apache UnomiCWE-93 9.1 -2021-05-04
CVE-2021-28359 Apache Airflow Reflected XSS via Origin Query Argument in URL — Apache Airflow 6.1 -2021-05-02
CVE-2021-30128 Unsafe deserialization in Apache OFBiz — Apache OFBiz 9.8 -2021-04-27
CVE-2021-29200 RCE vulnerability in latest Apache OFBiz due to Java serialisation using RMI — Apache OFBiz 9.8 -2021-04-27
CVE-2021-30638 An Information Disclosure due to insufficient input validation exists in Apache Tapestry 5.4.0 and later — Apache TapestryCWE-200 7.5 -2021-04-27

This page lists every published CVE security advisory associated with Apache Software Foundation. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.