Vulnerabilities in Apache Software Foundation

1,893 results
Vexday analysis

O portfólio da Apache Software Foundation acumula 1.872 CVEs catalogadas, das quais 215 são de severidade crítica e 83 contam com prova de conceito pública — fatores que ampliam a superfície de risco operacional para equipes de segurança. A taxa de exploração ativa é especialmente preocupante: 28 vulnerabilidades constam no catálogo KEV da CISA, representando uma proporção 3,3 vezes acima da média geral do catálogo, o que indica atenção consistente de agentes maliciosos ao ecossistema Apache. A falha mais comum é CWE-20 (validação inadequada de entrada), padrão estrutural que tende a se manifestar em múltiplos produtos e versões, exigindo revisão ampla e não pontual. Destaque para CVE-2021-40438, a vulnerabilidade de maior risco ativo no momento, com EPSS máximo de 1,0 — probabilidade de exploração na prática praticamente certa —, o que a torna prioridade imediata de remediação para qualquer organização que opere componentes Apache afetados.

CVE-2021-45230Apache Airflow: Creating DagRuns didn't respect Dag-level permissions in the WebserverEPSS 1.7%CVE-2022-24969bypass of CVE-2021-25640EPSS 1.7%CVE-2018-1307In Apache jUDDI 3.2 through 3.3.4, if using the WADL2Java or WSDL2Java classes, which parse a local or remote XML document and then mediatesEPSS 1.7%CVE-2024-38286HIGHApache Tomcat: Denial of ServiceEPSS 1.7%CVE-2021-44145Apache NiFi information disclosure by XXEEPSS 1.7%CVE-2024-28098MEDIUMApache Pulsar: Improper Authorization For Topic-Level Policy ManagementEPSS 1.7%CVE-2024-23952MEDIUMApache Superset: Allows for uncontrolled resource consumption via a ZIP bomb (version range fix for CVE-2023-46104)EPSS 1.7%CVE-2021-37150MEDIUMProtocol vs scheme mismatchEPSS 1.7%CVE-2022-31778Transfer-Encoding not treated as hop-by-hopEPSS 1.7%CVE-2024-45034HIGHApache Airflow: Authenticated DAG authors could execute code on scheduler nodesEPSS 1.7%CVE-2022-29158Regular Expression Denial of Service (ReDoS) vulnerability in Apache OFBizEPSS 1.7%CVE-2025-32897CRITICALApache Seata (incubating): Deserialization of untrusted Data in Apache Seata ServerEPSS 1.7%CVE-2022-27949HIGHApache Airflow prior to 2.3.1 may include sensitive values in rendered templateEPSS 1.7%CVE-2024-52318MEDIUMApache Tomcat: Incorrect JSP tag recycling leads to XSSEPSS 1.7%CVE-2023-40272HIGHApache Airflow Spark Provider Arbitrary File Read via JDBCEPSS 1.7%CVE-2023-46279Apache Dubbo: Bypass deny serialize list check in Apache DubboEPSS 1.7%CVE-2025-46392MEDIUMApache Commons Configuration: Uncontrolled Resource Consumption when loading untrusted configurations in 1.xEPSS 1.7%CVE-2023-42781Apache Airflow: Permission verification bypass allows viewing dagruns of other dagsEPSS 1.7%CVE-2025-27888MEDIUMApache Druid: Server-Side Request Forgery and Cross-Site ScriptingEPSS 1.7%CVE-2022-41137HIGHApache Hive: Deserialization of untrusted data when fetching partitions from the MetastoreEPSS 1.7%