Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

Apache Software Foundation — Vulnerabilities & Security Advisories 1684

Browse all 1684 CVE security advisories affecting Apache Software Foundation. AI-powered Chinese analysis, POCs, and references for each vulnerability.

CVE IDTitleCVSSSeverityPublished
CVE-2024-47248 Apache NimBLE: Buffer overflow in NimBLE MESH Bluetooth stack — Apache NimBLECWE-120 9.8AICriticalAI2024-11-26
CVE-2024-45719 Apache Answer: Predictable Authorization Token Using UUIDv1 — Apache AnswerCWE-326 7.5 -2024-11-22
CVE-2024-52067 Apache NiFi: Potential Insertion of Sensitive Parameter Values in Debug Log — Apache NiFiCWE-532 4.9AIMediumAI2024-11-21
CVE-2024-31141 Apache Kafka Clients: Privilege escalation to filesystem read-access via automatic ConfigProvider — Apache Kafka ClientsCWE-552 6.5AIMediumAI2024-11-19
CVE-2024-52318 Apache Tomcat: Incorrect JSP tag recycling leads to XSS — Apache Tomcat 8.2 -2024-11-18
CVE-2024-52317 Apache Tomcat: Request/response mix-up with HTTP/2 — Apache Tomcat 5.3AIMediumAI2024-11-18
CVE-2024-52316 Apache Tomcat: Authentication bypass when using Jakarta Authentication API — Apache TomcatCWE-391 9.1 -2024-11-18
CVE-2024-41151 Apache HertzBeat: RCE by notice template injection vulnerability — Apache HertzBeatCWE-502 8.8AIHighAI2024-11-18
CVE-2024-45791 Apache HertzBeat: Exposure sensitive token via http GET method with query string — Apache HertzBeatCWE-200 7.5AIHighAI2024-11-18
CVE-2024-45505 Apache HertzBeat: Exists Native Deser RCE and file writing vulnerabilities — Apache HertzBeatCWE-77 8.8AIHighAI2024-11-18
CVE-2024-47208 Apache OFBiz: URLs allowing remote use of Groovy expressions, leading to RCE — Apache OFBizCWE-918 9.8AICriticalAI2024-11-18
CVE-2024-48962 Apache OFBiz: Bypass SameSite restrictions with target redirection using URL parameters (SSTI and CSRF leading to RCE) — Apache OFBizCWE-94 8.8AIHighAI2024-11-18
CVE-2024-45784 Apache Airflow: Sensitive configuration values are not masked in the logs by default — Apache AirflowCWE-1295 6.5AIMediumAI2024-11-15
CVE-2024-50306 Apache Traffic Server: Server process can fail to drop privilege — Apache Traffic ServerCWE-252 9.8 -2024-11-14
CVE-2024-50305 Apache Traffic Server: Valid Host field value can cause crashes — Apache Traffic ServerCWE-20 6.5 -2024-11-14
CVE-2024-38479 Apache Traffic Server: Cache key plugin is vulnerable to cache poisoning attack — Apache Traffic ServerCWE-20 9.1 -2024-11-14
CVE-2024-50386 Apache CloudStack: Directly downloaded templates can be used to abuse KVM-based infrastructure — Apache CloudStackCWE-20 8.5 High2024-11-12
CVE-2024-50378 Apache Airflow: Secrets not masked in UI when sensitive variables are set via Airflow cli — Apache AirflowCWE-201 6.5 -2024-11-08
CVE-2024-51504 Apache ZooKeeper: Authentication bypass with IP-based authentication in Admin Server — Apache ZooKeeperCWE-290 9.1AICriticalAI2024-11-07
CVE-2024-38286 Apache Tomcat: Denial of Service — Apache TomcatCWE-770 8.6 High2024-11-07
CVE-2024-23590 Apache Kylin: Session fixation in web interface — Apache KylinCWE-384 9.8AICriticalAI2024-11-04
CVE-2024-43383 Apache Lucene.Net.Replicator: Remote Code Execution in Lucene.Net.Replicator — Apache Lucene.Net.ReplicatorCWE-502 8.0 High2024-10-31
CVE-2024-45477 Apache NiFi: Improper Neutralization of Input in Parameter Description — Apache NiFiCWE-79 4.6 Medium2024-10-29
CVE-2024-45031 Apache Syncope: Stored XSS in Console and Enduser — Apache SyncopeCWE-79 5.4AIMediumAI2024-10-24
CVE-2024-45219 Apache CloudStack: Uploaded and registered templates and volumes can be used to abuse KVM-based infrastructure — Apache CloudStackCWE-20 8.5 High2024-10-16
CVE-2024-45461 Apache CloudStack Quota plugin: Access checks not enforced in Quota — Apache CloudStack Quota pluginCWE-862 5.7 Medium2024-10-16
CVE-2024-45462 Apache CloudStack: Incomplete session invalidation on web interface logout — Apache CloudStackCWE-613 6.3 Medium2024-10-16
CVE-2024-45693 Apache CloudStack: Request origin validation bypass makes account takeover possible — Apache CloudStackCWE-352 8.0 High2024-10-16
CVE-2024-45217 Apache Solr: ConfigSets created during a backup restore command are trusted implicitly — Apache SolrCWE-1188 8.8 -2024-10-16
CVE-2024-45216 Apache Solr: Authentication bypass possible using a fake URL Path ending — Apache SolrCWE-287 9.8 -2024-10-16

This page lists every published CVE security advisory associated with Apache Software Foundation. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.