Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

Apache Software Foundation — Vulnerabilities & Security Advisories 1684

Browse all 1684 CVE security advisories affecting Apache Software Foundation. AI-powered Chinese analysis, POCs, and references for each vulnerability.

CVE IDTitleCVSSSeverityPublished
CVE-2025-29891 Apache Camel: Camel Message Header Injection through request parameters — Apache CamelCWE-164 8.2 -2025-03-12
CVE-2025-24813 Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT — Apache TomcatCWE-44 8.8 -2025-03-10
CVE-2025-26865 Apache OFBiz: Server-Side Template Injection affecting the ecommerce plugin leading to possible RCE — Apache OFBizCWE-1336 9.8 -2025-03-10
CVE-2025-27636 Apache Camel: Camel Message Header Injection via Improper Filtering — Apache Camel 7.5 -2025-03-09
CVE-2024-38311 Apache Traffic Server: Request smuggling via pipelining after a chunked message body — Apache Traffic ServerCWE-20 7.5 -2025-03-06
CVE-2024-56195 Apache Traffic Server: Intercept plugins are not access controlled — Apache Traffic ServerCWE-284--2025-03-06
CVE-2024-56196 Apache Traffic Server: ACL is not fully compatible with older versions — Apache Traffic ServerCWE-284--2025-03-06
CVE-2024-56202 Apache Traffic Server: Expect header field can unreasonably retain resource — Apache Traffic ServerCWE-440 9.1 -2025-03-06
CVE-2024-55532 Apache Ranger: Improper Neutralization of Formula Elements in a CSV File — Apache RangerCWE-1236 9.8 -2025-03-03
CVE-2024-24778 Apache StreamPipes: Resources Permission Escalation — Apache StreamPipesCWE-269 6.5 -2025-03-03
CVE-2024-56180 Apache EventMesh: raft Hessian Deserialization Vulnerability allowing remote code execution — Apache EventMeshCWE-502 9.8 -2025-02-14
CVE-2024-52577 Apache Ignite: Possible RCE when deserializing incoming messages by the server node — Apache IgniteCWE-502 8.1 -2025-02-14
CVE-2024-46910 Apache Atlas: An authenticated user can perform XSS and potentially impersonate another user — Apache AtlasCWE-80 5.4 -2025-02-13
CVE-2024-32838 Apache Fineract: SQL injection vulnerabilities in offices API endpoint — Apache FineractCWE-89 8.8 -2025-02-12
CVE-2025-25247 Apache Felix Webconsole: XSS in services console — Apache Felix WebconsoleCWE-79 6.1 -2025-02-10
CVE-2025-25069 Apache Kvrocks: Cross-Protocol Scripting Vulnerability — Apache KvrocksCWE-115 7.1 -2025-02-07
CVE-2022-31764 Apache ShardingSphere ElasticJob-UI allows RCE via event trace data source JDBC — Apache ShardingSphere ElasticJob-UICWE-913 9.8 -2025-02-06
CVE-2024-37358 Apache James: denial of service through the use of IMAP literals — Apache James serverCWE-770 8.6 High2025-02-06
CVE-2024-45626 Apache James: denial of service through JMAP HTML to text conversion — Apache James serverCWE-400 6.5 Medium2025-02-06
CVE-2024-48019 Apache Doris: allows admin users to read arbitrary files through the REST API — Apache DorisCWE-22 4.9 -2025-02-04
CVE-2024-27137 Apache Cassandra: unrestricted deserialization of JMX authentication credentials — Apache Cassandra 7.0 -2025-02-04
CVE-2025-24860 Apache Cassandra: CassandraNetworkAuthorizer and CassandraCIDRAuthorizer can be bypassed allowing access to different network regions — Apache CassandraCWE-863 6.5 -2025-02-04
CVE-2025-23015 Apache Cassandra: User with MODIFY permission on ALL KEYSPACES can escalate privileges to superuser via unsafe actions — Apache CassandraCWE-267 8.8 -2025-02-04
CVE-2024-29869 Apache Hive: Credentials file created with non restrictive permissions — Apache HiveCWE-732 6.5 -2025-01-28
CVE-2024-23953 Apache Hive: Timing Attack Against Signature in LLAP util — Apache HiveCWE-208 6.5 -2025-01-28
CVE-2025-24783 Apache Cocoon: continuations may not be private — Apache CocoonCWE-335 5.3 -2025-01-27
CVE-2025-24814 Apache Solr: Core-creation with "trusted" configset can use arbitrary untrusted files — Apache SolrCWE-250 9.8 -2025-01-27
CVE-2024-52012 Apache Solr: Configset upload on Windows allows arbitrary path write-access — Apache SolrCWE-23 7.7 -2025-01-27
CVE-2024-53299 Apache Wicket: An attacker can intentionally trigger a memory leak — Apache WicketCWE-400 7.5 -2025-01-23
CVE-2024-45479 Apache Ranger: SSRF in Edit Service page - Add logic to filter requests to localhost — Apache RangerCWE-918 5.3 -2025-01-21

This page lists every published CVE security advisory associated with Apache Software Foundation. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.