Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

Apache Software Foundation — Vulnerabilities & Security Advisories 1684

Browse all 1684 CVE security advisories affecting Apache Software Foundation. AI-powered Chinese analysis, POCs, and references for each vulnerability.

CVE IDTitleCVSSSeverityPublished
CVE-2023-50780 Apache ActiveMQ Artemis: Authenticated users could perform RCE via Jolokia MBeans — Apache ActiveMQ ArtemisCWE-285 8.8AIHighAI2024-10-14
CVE-2024-46911 Apache Roller: Weakness in CSRF protection allows privilege escalation — Apache RollerCWE-352 8.8AIHighAI2024-10-14
CVE-2024-45720 Apache Subversion: Command line argument injection on Windows platforms — Apache SubversionCWE-78 8.2 High2024-10-09
CVE-2024-28168 Apache XML Graphics FOP: XML External Entity (XXE) Processing — Apache XML Graphics FOPCWE-611 7.5AIHighAI2024-10-09
CVE-2024-47554 Apache Commons IO: Possible denial of service attack on untrusted input to XmlStreamReader — Apache Commons IOCWE-400 7.5 -2024-10-03
CVE-2024-47561 Apache Avro Java SDK: Arbitrary Code Execution when reading Avro schema (Java SDK) — Apache Avro Java SDKCWE-502 9.8 -2024-10-03
CVE-2024-45772 Apache Lucene Replicator: Security Vulnerability in Lucene Replicator - Deserialization Issue — Apache Lucene ReplicatorCWE-502 5.1 Medium2024-09-30
CVE-2024-47197 Maven Archetype Plugin: Maven Archetype integration-test may package local settings into the published artifact, possibly containing credentials — Maven Archetype PluginCWE-200 7.5AIHighAI2024-09-26
CVE-2024-23454 Apache Hadoop: Temporary File Local Information Disclosure — Apache HadoopCWE-378 5.5AIMediumAI2024-09-25
CVE-2024-40761 Apache Answer: Avatar URL leaked user email addresses — Apache AnswerCWE-326 7.5AIHighAI2024-09-25
CVE-2024-39928 Apache Linkis Spark EngineConn: Commons Lang's RandomStringUtils Random string security vulnerability — Apache Linkis Spark EngineConnCWE-326 5.3AIMediumAI2024-09-24
CVE-2024-46544 Apache Tomcat Connectors: mod_jk: local users can view and modify configuration — Apache Tomcat ConnectorsCWE-276 7.8AIHighAI2024-09-23
CVE-2024-42323 Apache HertzBeat: RCE by snakeYaml deser load malicious xml — Apache HertzBeatCWE-502 8.8 -2024-09-21
CVE-2024-45537 Apache Druid: Users can provide MySQL JDBC properties not on allow list — Apache DruidCWE-20 6.5 -2024-09-17
CVE-2024-45384 Apache Druid: Padding oracle in druid-pac4j extension that allows an attacker to manipulate a pac4j session cookie via Padding Oracle Attack — Apache Druid 7.5 -2024-09-17
CVE-2024-22399 Apache Seata: Remote Code Execution vulnerability via Hessian Deserialization in Apache Seata Server — Apache SeataCWE-502 9.8 -2024-09-16
CVE-2024-45034 Apache Airflow: Authenticated DAG authors could execute code on scheduler nodes — Apache AirflowCWE-250 7.8 -2024-09-07
CVE-2024-45498 Apache Airflow: Command Injection in an example DAG — Apache AirflowCWE-116 8.8 -2024-09-07
CVE-2024-45195 Apache OFBiz: Confused controller-view authorization logic (forced browsing) — Apache OFBizCWE-425 9.1AICriticalAI2024-09-04
CVE-2024-45507 Apache OFBiz: Prevent use of URLs in files when loading them from Java or Groovy, leading to a RCE — Apache OFBizCWE-918 9.8AICriticalAI2024-09-04
CVE-2023-49582 Apache Portable Runtime (APR): Unexpected lax shared memory permissions — Apache Portable Runtime (APR)CWE-732 3.3AILowAI2024-08-26
CVE-2024-41937 Apache Airflow: Stored XSS Vulnerability on provider link — Apache AirflowCWE-79 6.1AIMediumAI2024-08-21
CVE-2023-49198 Apache SeaTunnel Web: Arbitrary file read vulnerability — Apache SeaTunnel WebCWE-552 7.5AIHighAI2024-08-21
CVE-2024-22281 Apache Helix Front (UI): Helix front hard-coded secret in the express-session — Apache Helix Front (UI)CWE-668 9.1AICriticalAI2024-08-20
CVE-2024-43202 Apache DolphinScheduler: Remote Code Execution Vulnerability — Apache DolphinSchedulerCWE-94 9.8AICriticalAI2024-08-20
CVE-2024-41909 Apache MINA SSHD: integrity check bypass — Apache MINA SSHDCWE-354--AI2024-08-12
CVE-2024-41888 Apache Answer: The link for resetting user password is not Single-Use — Apache AnswerCWE-772 7.5AIHighAI2024-08-09
CVE-2024-41890 Apache Answer: The link to reset the user's password will remain valid after sending a new link — Apache AnswerCWE-772 7.5AIHighAI2024-08-09
CVE-2024-30188 Apache DolphinScheduler: Resource File Read And Write Vulnerability — Apache DolphinSchedulerCWE-20 8.1AIHighAI2024-08-09
CVE-2024-29831 Apache DolphinScheduler: RCE by arbitrary js execution — Apache DolphinSchedulerCWE-20 8.2AIHighAI2024-08-09

This page lists every published CVE security advisory associated with Apache Software Foundation. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.