Vulnerabilities in Apache Software Foundation

1,894 results
Vexday analysis

O portfólio da Apache Software Foundation acumula 1.872 CVEs catalogadas, das quais 215 são de severidade crítica e 83 contam com prova de conceito pública — fatores que ampliam a superfície de risco operacional para equipes de segurança. A taxa de exploração ativa é especialmente preocupante: 28 vulnerabilidades constam no catálogo KEV da CISA, representando uma proporção 3,3 vezes acima da média geral do catálogo, o que indica atenção consistente de agentes maliciosos ao ecossistema Apache. A falha mais comum é CWE-20 (validação inadequada de entrada), padrão estrutural que tende a se manifestar em múltiplos produtos e versões, exigindo revisão ampla e não pontual. Destaque para CVE-2021-40438, a vulnerabilidade de maior risco ativo no momento, com EPSS máximo de 1,0 — probabilidade de exploração na prática praticamente certa —, o que a torna prioridade imediata de remediação para qualquer organização que opere componentes Apache afetados.

CVE-2023-40037Apache NiFi: Incomplete Validation of JDBC and JNDI Connection URLsEPSS 1.5%CVE-2023-31039CRITICALApache bRPC: ServerOptions.pid_file may cause arbitrary code executionEPSS 1.5%CVE-2023-35005Apache Airflow: Information disclosure on configuration viewEPSS 1.5%CVE-2023-38647CRITICALApache Helix: Deserialization vulnerability in Helix workflow and RESTEPSS 1.5%CVE-2025-48769MEDIUMApache NuttX RTOS: fs/vfs/fs_rename: use after freeEPSS 1.5%CVE-2021-44759Improper authentication vulnerability in TLS origin verificationEPSS 1.5%CVE-2021-39235Access mode of block tokens are not enforcedEPSS 1.5%CVE-2025-58098HIGHApache HTTP Server: Server Side Includes adds query string to #exec cmd=...EPSS 1.5%CVE-2023-25956HIGHApache Airflow AWS Provider: Arbitrary file read via AWS providerEPSS 1.5%CVE-2023-47037Apache Airflow missing fix for CVE-2023-40611 in 2.7.1 (DAG run broken access)EPSS 1.5%CVE-2023-33933HIGHApache Traffic Server: s3_auth plugin problem with hash calculationEPSS 1.5%CVE-2023-46750MEDIUMApache Shiro: URL Redirection to Untrusted Site ('Open Redirect') vulnerability in FORM authentication feature Apache Shiro.EPSS 1.5%CVE-2025-48734HIGHApache Commons BeanUtils: PropertyUtilsBean does not suppresses an enum's declaredClass property by defaultEPSS 1.5%CVE-2024-23539HIGHApache Fineract: Under certain system configurations, the sqlSearch parameter for specific endpoints was vulnerable to SQL injection attacks, potentially allowing attackers to manipulate database queries.EPSS 1.5%CVE-2022-43985MEDIUMApache Airflow prior to 2.4.2 has an open redirectEPSS 1.5%CVE-2022-47185HIGHApache Traffic Server: Invalid Range header causes a crashEPSS 1.5%CVE-2023-25613LDAP Injection Vulnerability in Apache KerbyEPSS 1.5%CVE-2023-37379Apache Airflow: Exposure of sensitive connection information, DOS and SSRF on "test connection" featureEPSS 1.5%CVE-2022-26884MEDIUMApache DolphinScheduler exposes files without authenticationEPSS 1.5%CVE-2022-26336A carefully crafted TNEF file can cause an out of memory exceptionEPSS 1.5%