Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

Apache Software Foundation — Vulnerabilities & Security Advisories 1685

Browse all 1685 CVE security advisories affecting Apache Software Foundation. AI-powered Chinese analysis, POCs, and references for each vulnerability.

CVE IDTitleCVSSSeverityPublished
CVE-2023-27296 Apache InLong: JDBC Deserialization Vulnerability in InLong — Apache InLongCWE-502 8.8 -2023-03-27
CVE-2022-47502 Apache OpenOffice: Macro URL arbitrary script execution — Apache OpenOfficeCWE-20 7.3 -2023-03-24
CVE-2022-38745 Apache OpenOffice: Empty entry in Java class path — Apache OpenOfficeCWE-94 9.8 -2023-03-24
CVE-2023-28708 Apache Tomcat: JSESSIONID Cookie missing secure attribute in some configurations — Apache TomcatCWE-523 6.5 -2023-03-22
CVE-2023-26513 Apache Sling Resource Merger: Requests to certain paths managed by the Apache Sling Resource Merger can lead to DoS — Apache Sling Resource MergerCWE-834 7.5 High2023-03-20
CVE-2023-25695 Information disclosure in Apache Airflow — Apache AirflowCWE-209 5.3 -2023-03-15
CVE-2023-26464 Apache Log4j 1.x (EOL) allows DoS in Chainsaw and SocketAppender — Apache Log4jCWE-502 7.5 -2023-03-10
CVE-2023-23638 Apache Dubbo Deserialization Vulnerability Gadgets Bypass — Apache DubboCWE-502 5.0 Medium2023-03-08
CVE-2023-27522 Apache HTTP Server: mod_proxy_uwsgi HTTP response splitting — Apache HTTP ServerCWE-444 5.3 -2023-03-07
CVE-2023-25690 Apache HTTP Server: HTTP request splitting with mod_rewrite and mod_proxy — Apache HTTP ServerCWE-444 6.5 -2023-03-07
CVE-2023-25956 Apache Airflow AWS Provider: Arbitrary file read via AWS provider — Apache Airflow AWS ProviderCWE-209 5.3 -2023-02-24
CVE-2023-25696 Apache Airflow Hive Provider Beeline RCE — Apache Airflow Hive ProviderCWE-20 7.5 -2023-02-24
CVE-2023-25693 Sqoop Apache Airflow Provider Remote Code Execution Vulnerability — Apache Airflow Sqoop ProviderCWE-20 9.1 -2023-02-24
CVE-2023-25692 Apache Airflow Google Provider: Google Cloud Sql Provider Denial Of Service — Apache Airflow Google ProviderCWE-20 9.1 -2023-02-24
CVE-2023-25691 Apache Airflow Google Provider: Google Cloud Sql Provider Remote Command Execution — Apache Airflow Google ProviderCWE-20 9.1 -2023-02-24
CVE-2023-25621 Apache Sling does not allow to handle i18n content in a secure way — Apache Sling 6.5 -2023-02-23
CVE-2023-24998 Apache Commons FileUpload, Apache Tomcat: FileUpload DoS with excessive parts — Apache Commons FileUploadCWE-770 7.5 -2023-02-20
CVE-2023-25613 LDAP Injection Vulnerability in Apache Kerby — Apache Kerby LDAP BackendCWE-74 9.8 -2023-02-20
CVE-2022-42735 Apache ShenYu Admin ultra vires — Apache ShenYuCWE-269 8.8 -2023-02-15
CVE-2023-25141 JNDI injection into Apache sling-org-apache-sling-jcr-base — Apache Sling JCR BaseCWE-74 9.1 -2023-02-14
CVE-2023-22832 Apache NiFi: Improper Restriction of XML External Entity References in ExtractCCDAAttributes — Apache NiFiCWE-611 7.5 -2023-02-10
CVE-2023-25194 Apache Kafka Connect API: Possible RCE/Denial of service attack via SASL JAAS JndiLoginModule configuration using Kafka Connect — Apache Kafka Connect APICWE-502 8.8 -2023-02-07
CVE-2022-45786 Apache AGE: Python and Golang drivers allow data manipulation and exposure due to SQL injection — Apache AGECWE-89 7.5 -2023-02-04
CVE-2023-22849 Apache Sling App CMS: XSS in CMS Reference / UI Components — Apache Sling App CMSCWE-79 5.4 -2023-02-04
CVE-2023-24997 Apache InLong: Jdbc Connection Security Bypass — Apache InLongCWE-502 9.8 -2023-02-01
CVE-2023-24977 Apache InLong: Jdbc Connection causes arbitrary file reading in InLong — Apache InLongCWE-125 7.5 -2023-02-01
CVE-2022-28331 Apache Portable Runtime (APR): Windows out-of-bounds write in apr_socket_sendv function — Apache Portable Runtime (APR)CWE-190 9.8 -2023-01-31
CVE-2022-25147 Apache Portable Runtime Utility (APR-util): out-of-bounds writes in the apr_base64 family of functions — Apache Portable Runtime Utility (APR-util)CWE-190 9.8 -2023-01-31
CVE-2022-24963 Apache Portable Runtime (APR): out-of-bound writes in the apr_encode family of functions — Apache Portable Runtime (APR)CWE-190 9.8 -2023-01-31
CVE-2022-44644 Apache Linkis (incubating): The DatasourceManager module has a Local File Read Vulnerability — Apache Linkis (incubating)CWE-20 6.5 -2023-01-31

This page lists every published CVE security advisory associated with Apache Software Foundation. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.