Known Vulnerabilities for Apache POI by Apache Software Foundation
Listed below are 10 of the newest known vulnerabilities associated with "Apache POI" by "Apache Software Foundation".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-78329 json | Improper input validation vulnerability in Apache Camel Undertow component. This issue affects Apache Camel: from 4.11.0 b... | Not Provided | 2026-08-24 | 2026-08-26 |
| CVE-2026-75099 json | Unauthenticated REST disclosure of certain content items in Apache Allura. This issue affects Apache Allura: through 1.19... | Not Provided | 2026-08-24 | 2026-08-24 |
| CVE-2026-75020 json | Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection') vulnerability in Apache APISIX. A calle... | Not Provided | 2026-08-27 | 2026-08-27 |
| CVE-2026-75005 json | Inefficient Algorithmic Complexity vulnerability in Apache APISIX. A single small request can pin a gateway worker at 100% ... | Not Provided | 2026-08-27 | 2026-08-27 |
| CVE-2026-74848 json | Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in Apache APISIX. An attacker... | Not Provided | 2026-08-27 | 2026-08-27 |
| CVE-2026-73649 json | Velocity.js is a JavaScript implementation of the Apache Velocity template engine. Prior to 2.1.7, the earlier fix for CVE-20... | Not Provided | 2026-08-13 | 2026-08-14 |
| CVE-2026-73635 json | Allocation of resources without limits or throttling vulnerability in Apache Struts. When no fixed locale is configured, the ... | Not Provided | 2026-08-15 | 2026-08-17 |
| CVE-2026-73634 json | Uncontrolled resource consumption vulnerability in Apache Struts. An application that exposes an endpoint collecting Content ... | Not Provided | 2026-08-15 | 2026-08-17 |
| CVE-2026-73633 json | Uncontrolled resource consumption vulnerability in the JSON plugin of Apache Struts. When an application is configured to pop... | Not Provided | 2026-08-14 | 2026-08-14 |
| CVE-2026-73632 json | Exposure of data element to wrong session vulnerability in the JSON plugin of Apache Struts. Per-response serialization state... | Not Provided | 2026-08-15 | 2026-08-17 |