Vulnerabilities in Apache Software Foundation

1,893 results
Vexday analysis

O portfólio da Apache Software Foundation acumula 1.872 CVEs catalogadas, das quais 215 são de severidade crítica e 83 contam com prova de conceito pública — fatores que ampliam a superfície de risco operacional para equipes de segurança. A taxa de exploração ativa é especialmente preocupante: 28 vulnerabilidades constam no catálogo KEV da CISA, representando uma proporção 3,3 vezes acima da média geral do catálogo, o que indica atenção consistente de agentes maliciosos ao ecossistema Apache. A falha mais comum é CWE-20 (validação inadequada de entrada), padrão estrutural que tende a se manifestar em múltiplos produtos e versões, exigindo revisão ampla e não pontual. Destaque para CVE-2021-40438, a vulnerabilidade de maior risco ativo no momento, com EPSS máximo de 1,0 — probabilidade de exploração na prática praticamente certa —, o que a torna prioridade imediata de remediação para qualquer organização que opere componentes Apache afetados.

CVE-2023-46104MEDIUMApache Superset: Allows for uncontrolled resource consumption via a ZIP bombEPSS 1.7%CVE-2025-29953CRITICALApache ActiveMQ NMS OpenWire Client: deserialization allowlist bypassEPSS 1.6%CVE-2017-7673Apache OpenMeetings 1.0.0 uses not very strong cryptographic storage, captcha is not used in registration and forget password dialogs and auEPSS 1.6%CVE-2023-46851Apache Allura: sensitive information exposure via importEPSS 1.6%CVE-2017-7682Apache OpenMeetings 3.2.0 is vulnerable to parameter manipulation attacks, as a result attacker has access to restricted areas.EPSS 1.6%CVE-2024-23452HIGHApache bRPC: HTTP request smuggling vulnerabilityEPSS 1.6%CVE-2021-39232Missing admin check for SCM related admin commandsEPSS 1.6%CVE-2023-36542HIGHApache NiFi: Potential Code Injection with Properties Referencing Remote ResourcesEPSS 1.6%CVE-2023-41834Apache Flink Stateful Functions allowed HTTP header injection due to Improper Neutralization of CRLF SequencesEPSS 1.6%CVE-2024-47208CRITICALApache OFBiz: URLs allowing remote use of Groovy expressions, leading to RCEEPSS 1.6%CVE-2017-12631Apache CXF Fediz ships with a number of container-specific plugins to enable WS-Federation for applications. A CSRF (Cross Style Request ForEPSS 1.6%CVE-2023-52291HIGHApache StreamPark (incubating): Unchecked maven build params could trigger remote command executionEPSS 1.6%CVE-2022-38362Docker Provider <3.0 RCE vulnerability in example dagEPSS 1.6%CVE-2021-32609XSS vulnerability on Explore pageEPSS 1.6%CVE-2022-28889Clickjacking in the web consoleEPSS 1.6%CVE-2023-31038HIGHApache Log4cxx: SQL injection when using ODBC appenderEPSS 1.6%CVE-2022-37866HIGHApache Ivy allows path traversal in the presence of a malicious repositoryEPSS 1.6%CVE-2022-24294ReDoS in Apache MXNet RTC ModuleEPSS 1.6%CVE-2022-36127Service unavailability impact in NodeJS agent(version <= 0.5.0)EPSS 1.6%CVE-2022-29405Apache Archiva Arbitrary user password reset vulnerabilityEPSS 1.6%