Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Apache Software Foundation — Vulnerabilities & Security Advisories 2175

Browse all 2175 CVE security advisories affecting Apache Software Foundation. AI-powered Chinese analysis, POCs, and references for each vulnerability.

The Apache Software Foundation develops and maintains open-source software, primarily known for the widely deployed Apache HTTP Server and foundational Java frameworks. Its extensive portfolio exposes a significant attack surface, evidenced by the 1717 recorded CVEs. Historically, vulnerabilities frequently involve remote code execution, cross-site scripting, and privilege escalation, often stemming from complex configuration errors or input validation failures in legacy components. While the foundation enforces rigorous security review processes, the sheer volume of projects increases the likelihood of undiscovered flaws. Notable incidents include critical flaws in Log4j, which allowed remote code execution via crafted log messages, highlighting risks in dependency management. The organization relies on community-driven patching, requiring administrators to promptly apply updates to mitigate exploitation. This model ensures transparency but demands active vigilance from users to maintain system integrity against evolving threat vectors.

Found 23 results / 2175Clear Filters
CVE IDTitleCVSSSeverityPublished
CVE-2026-28672 Apache Ranger: OS Command Injection via Username in UnixUserGroupBuilder — Apache RangerCWE-77--2026-08-10
CVE-2026-32227 Apache Ranger: SQL Injection vulnerability in lookup functionality — Apache RangerCWE-89--2026-08-10
CVE-2026-40920 Apache Ranger: Privilege Escalation via URL Parameter — Apache RangerCWE-269--2026-08-10
CVE-2026-42537 Apache Ranger: Remote Code Execution via JDBC URL Injection — Apache RangerCWE-94--2026-08-10
CVE-2026-44416 Apache Ranger: Remote Code Execution via Arbitrary Class Instantiation — Apache RangerCWE-94--2026-08-10
CVE-2026-55799 Apache Ranger: Remote Code Execution Vulnerability in GraalScriptEngineCreator — Apache RangerCWE-94--2026-08-10
CVE-2026-55814 Apache Ranger: Download APIs expose plugin data without authentication — Apache RangerCWE-306--2026-08-10
CVE-2026-65942 Apache Ranger: Clients accept TLS certificates issued for other hostnames — Apache RangerCWE-297--2026-08-10
CVE-2026-65945 Apache Ranger: Logs contain replayable JWT bearer tokens — Apache RangerCWE-532--2026-08-10
CVE-2026-65948 Apache Ranger: UnixAuth lacks brute-force protection — Apache RangerCWE-307--2026-08-10
CVE-2025-59060 Apache Ranger: Hostname verification bypass in NiFiRegistryClient and NifiClient — Apache RangerCWE-297 5.3AIMediumAI2026-03-03
CVE-2025-59059 Apache Ranger: Remote Code Execution Vulnerability in NashornScriptEngineCreator — Apache RangerCWE-94 9.8AICriticalAI2026-03-03
CVE-2024-55532 Apache Ranger: Improper Neutralization of Formula Elements in a CSV File — Apache RangerCWE-1236 9.8 -2025-03-03
CVE-2024-45479 Apache Ranger: SSRF in Edit Service page - Add logic to filter requests to localhost — Apache RangerCWE-918 5.3 -2025-01-21
CVE-2024-45478 Apache Ranger: Stored XSS in Edit Service page - Add logic to validate user input — Apache RangerCWE-79 5.4 -2025-01-21
CVE-2022-45048 Apache Ranger: code execution vulnerability in policy expressions — Apache RangerCWE-74 8.4 High2023-05-05
CVE-2019-12397 Apache Ranger 跨站脚本漏洞 — Apache Ranger 6.1 -2019-08-08
CVE-2018-11778 Apache Ranger 缓冲区错误漏洞 — Apache Ranger 8.8 -2018-10-05
CVE-2016-6815 Apache Ranger 信任管理漏洞 — Apache Ranger 6.5 -2017-10-13
CVE-2017-7677 Apache Ranger Hive Authorizer 安全漏洞 — Apache Ranger 7.5 -2017-06-14
CVE-2017-7676 Apache Ranger Policy resource matcher 输入验证漏洞 — Apache Ranger 9.1 -2017-06-14
CVE-2016-8751 Apache Ranger 跨站脚本漏洞 — Apache Ranger 4.8 -2017-06-14
CVE-2016-8746 Apache Ranger 安全漏洞 — Apache Ranger 5.9 -2017-06-14

This page lists every published CVE security advisory associated with Apache Software Foundation. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.