Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

Apache Software Foundation — Vulnerabilities & Security Advisories 1663

Browse all 1663 CVE security advisories affecting Apache Software Foundation. AI-powered Chinese analysis, POCs, and references for each vulnerability.

CVE IDTitleCVSSSeverityPublished
CVE-2026-25747 Apache Camel LevelDB: Deserialization of Untrusted Data in Camel LevelDB — Apache Camel LevelDBCWE-502 8.8AIHighAI2026-02-23
CVE-2026-23552 Apache Camel: Camel-Keycloak: Cross-Realm Token Acceptance Bypass in KeycloakSecurityPolicy — Apache CamelCWE-346 5.3AIMediumAI2026-02-23
CVE-2025-65995 Apache Airflow: Disclosure of secrets to UI via kwargs — Apache AirflowCWE-209 6.5AIMediumAI2026-02-21
CVE-2026-24734 Apache Tomcat Native, Apache Tomcat: OCSP revocation bypass — Apache Tomcat NativeCWE-20 7.5AIHighAI2026-02-17
CVE-2026-24733 Apache Tomcat: Security constraint bypass with HTTP/0.9 — Apache TomcatCWE-20 7.5AIHighAI2026-02-17
CVE-2025-66614 Apache Tomcat: Client certificate verification bypass due to virtual host mapping — Apache TomcatCWE-20 9.8AICriticalAI2026-02-17
CVE-2026-25087 Apache Arrow: Potential use-after-free when reading IPC file with pre-buffering — Apache ArrowCWE-416 9.8AICriticalAI2026-02-17
CVE-2026-25903 Apache NiFi: Missing Authorization of Restricted Permissions for Component Updates — Apache NiFiCWE-862 6.5AIMediumAI2026-02-17
CVE-2025-33042 Apache Avro Java SDK: Code injection on Java generated code — Apache Avro Java SDKCWE-94 9.8 -2026-02-13
CVE-2026-24343 Apache HertzBeat: Uncontrolled Resource Consumption via Crafted XPath Expressions — Apache HertzBeatCWE-643 9.4AICriticalAI2026-02-10
CVE-2026-23906 Apache Druid: Authentication Bypass via LDAP Anonymous Bind — Apache DruidCWE-287 9.8AICriticalAI2026-02-10
CVE-2026-23901 Apache Shiro: Brute force attack possible to determine valid user names — Apache ShiroCWE-208 6.5 -2026-02-10
CVE-2026-22922 Apache Airflow: Airflow externalLogUrl Permission Bypass — Apache AirflowCWE-648 4.3AIMediumAI2026-02-09
CVE-2026-24098 Apache Airflow: Assigning single DAG permission leaked all DAGs Import Errors — Apache AirflowCWE-200 4.3AIMediumAI2026-02-09
CVE-2026-23903 Apache Shiro: Auth bypass when accessing static files only on case-insensitive filesystems — Apache ShiroCWE-289 7.5 -2026-02-09
CVE-2026-24735 Apache Answer: Revision API Improper Access Control leads to Information Disclosure — Apache AnswerCWE-359 5.3AIMediumAI2026-02-04
CVE-2026-23794 Apache Syncope: Reflected XSS on Enduser Login — Apache SyncopeCWE-79 6.1AIMediumAI2026-02-03
CVE-2026-23795 Apache Syncope: Console XXE on Keymaster parameters — Apache SyncopeCWE-611 4.9AIMediumAI2026-02-03
CVE-2016-15057 Apache Continuum: Command injection leading to RCE — Apache ContinuumCWE-77 8.8AIHighAI2026-01-26
CVE-2025-27821 HDFS native client: Out of bounds write in URI parser of native HDFS client — HDFS native clientCWE-787 9.8AICriticalAI2026-01-26
CVE-2026-24656 Apache Karaf: Decanter log-socket collector has deserialization vulnerability — Apache KarafCWE-502 9.1AICriticalAI2026-01-26
CVE-2026-22022 Apache Solr: Unauthorized bypass of certain "predefined permission" rules in the RuleBasedAuthorizationPlugin — Apache SolrCWE-285 9.8AICriticalAI2026-01-21
CVE-2026-22444 Apache Solr: Insufficient file-access checking in standalone core-creation requests — Apache SolrCWE-20 5.3AIMediumAI2026-01-21
CVE-2025-59355 Apache Linkis: Password Exposure — Apache LinkisCWE-532 7.5AIHighAI2026-01-19
CVE-2025-29847 Apache Linkis: Arbitrary File Read via Double URL Encoding Bypass — Apache LinkisCWE-20 7.5AIHighAI2026-01-19
CVE-2025-68675 Apache Airflow: proxy credentials for various providers might leak in task logs — Apache AirflowCWE-532 7.5 -2026-01-16
CVE-2025-68438 Apache Airflow: Secrets in rendered templates could contain parts of sensitive values when truncated — Apache AirflowCWE-200 7.5 -2026-01-16
CVE-2025-60021 Apache bRPC: Remote command injection vulnerability in heap builtin service — Apache bRPCCWE-77 9.8 -2026-01-16
CVE-2025-66169 Apache Camel Neo4j: Cypher injection vulnerability in Camel-Neo4j component — Apache Camel Neo4j 9.8AICriticalAI2026-01-14
CVE-2025-68493 Apache Struts, Apache Struts: XXE vulnerability in outdated XWork component — Apache StrutsCWE-611 7.5 -2026-01-11

This page lists every published CVE security advisory associated with Apache Software Foundation. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.