Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

Apache Software Foundation — Vulnerabilities & Security Advisories 1685

Browse all 1685 CVE security advisories affecting Apache Software Foundation. AI-powered Chinese analysis, POCs, and references for each vulnerability.

CVE IDTitleCVSSSeverityPublished
CVE-2021-35515 Apache Commons Compress 1.6 to 1.20 denial of service vulnerability — Apache Commons CompressCWE-834 7.5 -2021-07-13
CVE-2021-33037 Incorrect Transfer-Encoding handling with HTTP/1.0 — Apache TomcatCWE-444 5.3 -2021-07-12
CVE-2021-30640 Auth weakness in JNDIRealm — Apache Tomcat 6.5 -2021-07-12
CVE-2021-30639 DoS after non-blocking IO error — Apache Tomcat 6.5 -2021-07-12
CVE-2021-30129 DoS/OOM leak vulnerability in Apache Mina SSHD Server — Apache Mina SSHD 9.1 -2021-07-12
CVE-2021-33192 Display information UI XSS — Apache Jena FusekiCWE-79 6.1 -2021-07-05
CVE-2021-26920 Apache Druid: The HTTP inputSource allows authenticated users to read data from other sources than intended — Apache Druid 6.5 -2021-07-02
CVE-2021-35474 Dynamic stack buffer overflow in cachekey plugin — Apache Traffic ServerCWE-121 9.8 -2021-06-30
CVE-2021-32567 Reading HTTP/2 frames too many times — Apache Traffic ServerCWE-20 7.5 -2021-06-30
CVE-2021-32566 Specific sequence of HTTP/2 frames can cause ATS to crash — Apache Traffic ServerCWE-20 7.5 -2021-06-30
CVE-2021-32565 HTTP Request Smuggling, content length with invalid charters — Apache Traffic ServerCWE-444 7.5 -2021-06-29
CVE-2021-27577 Incorrect handling of url fragment leads to cache poisoning — Apache Traffic ServerCWE-444 7.5 -2021-06-29
CVE-2021-26461 malloc, realloc and memalign implementations are vulnerable to integer wrap-arounds — Apache NuttXCWE-190 9.8 -2021-06-21
CVE-2021-30468 Apache CXF Denial of service vulnerability in parsing JSON via JsonMapObjectReaderWriter — Apache CXFCWE-400 7.5 -2021-06-16
CVE-2020-9493 Java deserialization in Chainsaw — Apache ChainsawCWE-502 9.8 -2021-06-16
CVE-2021-31618 NULL pointer dereference on specially crafted HTTP/2 request — Apache HTTP ServerCWE-476 7.5 -2021-06-15
CVE-2021-31811 A carefully crafted PDF file can trigger an OutOfMemory-Exception while loading a tiny file — Apache PDFBoxCWE-789 5.5 -2021-06-12
CVE-2021-31812 A carefully crafted PDF file can trigger an infinite loop while loading the file — Apache PDFBoxCWE-834 5.5 -2021-06-12
CVE-2021-30641 Unexpected URL matching with 'MergeSlashes OFF' — Apache HTTP Server 5.3 -2021-06-10
CVE-2021-26691 Apache HTTP Server mod_session response handling heap overflow — Apache HTTP ServerCWE-122 9.8 -2021-06-10
CVE-2021-26690 mod_session NULL pointer dereference — Apache HTTP Server 7.5 -2021-06-10
CVE-2020-13950 mod_proxy_http NULL pointer dereference — Apache HTTP Server 7.5 -2021-06-10
CVE-2020-35452 mod_auth_digest possible stack overflow by one nul byte — Apache HTTP Server 9.4 -2021-06-10
CVE-2020-13938 Improper Handling of Insufficient Privileges — Apache HTTP Server 5.5 -2021-06-10
CVE-2019-17567 mod_proxy_wstunnel tunneling of non Upgraded connections — Apache HTTP Server--2021-06-10
CVE-2021-33190 Bypass network access control — Apache APISIX DashboardCWE-307 5.3 -2021-06-08
CVE-2021-30180 Apache Dubbo RCE on customers via Condition route poisoning (Unsafe YAML unmarshaling) — Apache Dubbo 9.8 -2021-05-31
CVE-2021-30179 Apache Dubbo Pre-auth RCE via Java deserialization in the Generic filter — Apache Dubbo 9.8 -2021-05-31
CVE-2021-25640 Open Redirect or SSRF vulnerability usage of parseURL — Apache DubboCWE-918 8.2 -2021-05-31
CVE-2021-25641 Dubbo Zookeeper does not check serialization id — Apache Dubbo 9.8 -2021-05-29

This page lists every published CVE security advisory associated with Apache Software Foundation. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.