Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

Apache Software Foundation — Vulnerabilities & Security Advisories 1663

Browse all 1663 CVE security advisories affecting Apache Software Foundation. AI-powered Chinese analysis, POCs, and references for each vulnerability.

CVE IDTitleCVSSSeverityPublished
CVE-2025-55039 Apache Spark, Apache Spark: RPC encryption defaults to unauthenticated AES-CTR mode, enabling man-in-the-middle ciphertext modification attacks — Apache SparkCWE-347 5.9AIMediumAI2025-10-15
CVE-2024-44088 Apache Geode: Reflected XSS — Apache GeodeCWE-79 6.1AIMediumAI2025-10-14
CVE-2025-30001 Apache StreamPark: Authenticated users can trigger remote command execution — Apache StreamParkCWE-279 8.1AIHighAI2025-10-10
CVE-2025-62228 Apache Flink CDC, Apache Flink CDC, Apache Flink CDC, Apache Flink CDC, Apache Flink CDC: SQL injection via maliciously crafted identifiers — Apache Flink CDCCWE-89 8.8AIHighAI2025-10-09
CVE-2025-61735 Apache Kylin: Server-Side Request Forgery — Apache KylinCWE-918 9.1AICriticalAI2025-10-02
CVE-2025-61733 Apache Kylin: Authentication bypass — Apache KylinCWE-288 9.8AICriticalAI2025-10-02
CVE-2025-61734 Apache Kylin: improper restriction of file read — Apache KylinCWE-552 9.1AICriticalAI2025-10-02
CVE-2025-61622 Apache Fory, Apache Fory: Python RCE via unguarded pickle fallback serializer in pyfory — Apache ForyCWE-502 9.8AICriticalAI2025-10-01
CVE-2025-54831 Apache Airflow: Connection sensitive details exposed to users with READ permissions — Apache AirflowCWE-213 6.5 -2025-09-26
CVE-2025-58457 Apache ZooKeeper: Insufficient Permission Check in AdminServer Snapshot/Restore Commands — Apache ZooKeeperCWE-280 8.8AIHighAI2025-09-24
CVE-2025-48392 Apache IoTDB: DoS Vulnerability — Apache IoTDB 9.8AICriticalAI2025-09-24
CVE-2025-48459 Apache IoTDB: Deserialization of untrusted Data — Apache IoTDBCWE-502 9.8AICriticalAI2025-09-24
CVE-2025-59328 Apache Fory: Denial of Service (DoS) due to Deserialization of Untrusted malicious large Data — Apache ForyCWE-502 7.5AIHighAI2025-09-15
CVE-2025-48208 Apache HertzBeat (incubating): Jmx JNDI injection vulnerability — Apache HertzBeat (incubating)CWE-90 8.8AIHighAI2025-09-09
CVE-2025-24404 Apache HertzBeat (incubating): RCE by parse http sitemap xml response — Apache HertzBeat (incubating)CWE-91 8.8AIHighAI2025-09-09
CVE-2025-58782 Apache Jackrabbit Core, Apache Jackrabbit JCR Commons: JNDI injection risk with JndiRepositoryFactory — Apache Jackrabbit CoreCWE-502 9.8AICriticalAI2025-09-08
CVE-2024-43166 Apache DolphinScheduler 安全漏洞 — Apache DolphinSchedulerCWE-276 9.8AICriticalAI2025-09-03
CVE-2024-43115 Apache DolphinScheduler: Alert Script Attack — Apache DolphinSchedulerCWE-20 8.8AIHighAI2025-09-03
CVE-2025-26467 Apache Cassandra: User with MODIFY permission on ALL KEYSPACES can escalate privileges to superuser via unsafe actions (4.0.16 only) — Apache CassandraCWE-267 8.8 -2025-08-25
CVE-2025-54812 Apache Log4cxx: Improper HTML escaping in HTMLLayout — Apache Log4cxxCWE-117 6.1AIMediumAI2025-08-22
CVE-2025-54813 Apache Log4cxx: Improper escaping with JSONLayout — Apache Log4cxxCWE-117 5.3AIMediumAI2025-08-22
CVE-2024-48988 Apache StreamPark: SQL injection vulnerability — Apache StreamParkCWE-564 9.8 -2025-08-22
CVE-2025-54988 Apache Tika PDF parser module: XXE vulnerability in PDFParser's handling of XFA — Apache Tika PDF parser moduleCWE-611 8.4 High2025-08-20
CVE-2024-39954 Apache EventMesh Runtime: SSRF — Apache EventMesh RuntimeCWE-918 9.1 -2025-08-20
CVE-2025-53192 Apache Commons OGNL: Expression Injection leading to RCE — Apache Commons OGNLCWE-146 9.8 -2025-08-18
CVE-2025-54466 Apache OFBiz: RCE Vulnerability in scrum plugin — Apache OFBizCWE-94 9.8AICriticalAI2025-08-15
CVE-2025-55675 Apache Superset: Incorrect datasource authorization on REST API — Apache SupersetCWE-285 4.3AIMediumAI2025-08-14
CVE-2025-55674 Apache Superset: Improper SQL authorisation, parse not checking for specific engine functions — Apache SupersetCWE-89 6.5AIMediumAI2025-08-14
CVE-2025-55672 Apache Superset: Stored XSS on charts metadata — Apache SupersetCWE-80 5.4AIMediumAI2025-08-14
CVE-2025-55673 Apache Superset: Metadata exposure in embedded charts — Apache SupersetCWE-200 3.5AILowAI2025-08-14

This page lists every published CVE security advisory associated with Apache Software Foundation. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.