Vulnerabilities in Apache Software Foundation

1,884 results
Vexday analysis

O portfólio da Apache Software Foundation acumula 1.872 CVEs catalogadas, das quais 215 são de severidade crítica e 83 contam com prova de conceito pública — fatores que ampliam a superfície de risco operacional para equipes de segurança. A taxa de exploração ativa é especialmente preocupante: 28 vulnerabilidades constam no catálogo KEV da CISA, representando uma proporção 3,3 vezes acima da média geral do catálogo, o que indica atenção consistente de agentes maliciosos ao ecossistema Apache. A falha mais comum é CWE-20 (validação inadequada de entrada), padrão estrutural que tende a se manifestar em múltiplos produtos e versões, exigindo revisão ampla e não pontual. Destaque para CVE-2021-40438, a vulnerabilidade de maior risco ativo no momento, com EPSS máximo de 1,0 — probabilidade de exploração na prática praticamente certa —, o que a torna prioridade imediata de remediação para qualquer organização que opere componentes Apache afetados.

CVE-2025-52434HIGHApache Tomcat: APR/Native Connector crash leading to DoSEPSS 1.8%CVE-2022-37865CRITICALApache Ivy allows creating/overwriting any file on the systemEPSS 1.8%CVE-2021-38296Apache Spark Key Negotiation VulnerabilityEPSS 1.8%CVE-2022-38054Session FixationEPSS 1.8%CVE-2017-3155Apache Atlas versions 0.6.0-incubating and 0.7.0-incubating were found vulnerable to cross frame scripting.EPSS 1.8%CVE-2023-27603CRITICALApache Linkis Mangaer module engineConn material upload exists Zip Slip issueEPSS 1.8%CVE-2017-7680Apache OpenMeetings 1.0.0 has an overly permissive crossdomain.xml file. This allows for flash content to be loaded from untrusted domains.EPSS 1.8%CVE-2017-9806A vulnerability in the OpenOffice Writer DOC file parser before 4.1.4, and specifically in the WW8Fonts Constructor, allows attackers to craEPSS 1.8%CVE-2024-41937MEDIUMApache Airflow: Stored XSS Vulnerability on provider linkEPSS 1.8%CVE-2023-48291Apache Airflow: Improper access control to DAG resourcesEPSS 1.8%CVE-2017-7669In Apache Hadoop 2.8.0, 3.0.0-alpha1, and 3.0.0-alpha2, the LinuxContainerExecutor runs docker commands as root with insufficient input valiEPSS 1.8%CVE-2023-46819MEDIUMApache OFBiz: Execution of Solr plugin queries without authenticationEPSS 1.8%CVE-2021-43999Improper validation of SAML responsesEPSS 1.8%CVE-2024-31867MEDIUMApache Zeppelin: LDAP search filter query Injection VulnerabilityEPSS 1.8%CVE-2018-1315In Apache Hive 2.1.0 to 2.3.2, when 'COPY FROM FTP' statement is run using HPL/SQL extension to Hive, a compromised/malicious FTP server canEPSS 1.8%CVE-2023-39553HIGHApache Airflow Drill Provider Arbitrary File Read VulnerabilityEPSS 1.8%CVE-2021-41571Pulsar Admin API allows access to data from other tenants using getMessageById APIEPSS 1.8%CVE-2024-39864CRITICALApache CloudStack: Integration API service uses dynamic port when disabledEPSS 1.8%CVE-2022-34321HIGHApache Pulsar: Improper Authentication for Pulsar Proxy Statistics EndpointEPSS 1.8%CVE-2022-22931Path traversal in Apache James 3.6.1EPSS 1.8%