Vulnerabilidades em Apache Software Foundation

2.398 resultados
Análise Vexday

O portfólio da Apache Software Foundation acumula 1.872 CVEs catalogadas, das quais 215 são de severidade crítica e 83 contam com prova de conceito pública — fatores que ampliam a superfície de risco operacional para equipes de segurança. A taxa de exploração ativa é especialmente preocupante: 28 vulnerabilidades constam no catálogo KEV da CISA, representando uma proporção 3,3 vezes acima da média geral do catálogo, o que indica atenção consistente de agentes maliciosos ao ecossistema Apache. A falha mais comum é CWE-20 (validação inadequada de entrada), padrão estrutural que tende a se manifestar em múltiplos produtos e versões, exigindo revisão ampla e não pontual. Destaque para CVE-2021-40438, a vulnerabilidade de maior risco ativo no momento, com EPSS máximo de 1,0 — probabilidade de exploração na prática praticamente certa —, o que a torna prioridade imediata de remediação para qualquer organização que opere componentes Apache afetados.

CVE-2026-48910MEDIUMApache JSPWiki: Markdown parser allows XSS injection in Markdown error processingEPSS 0.6%CVE-2025-27867MEDIUMApache Felix HTTP Webconsole Plugin: XSS in HTTP Webconsole PluginEPSS 0.6%CVE-2026-31986CRITICALApache OFBiz: Unauthenticated RCE via Default JWT Signing Key and Widget Template InjectionEPSS 0.6%CVE-2026-63015MEDIUMApache InLong: Non-template responsible persons can view template informationEPSS 0.6%CVE-2024-45478MEDIUMApache Ranger: Stored XSS in Edit Service page - Add logic to validate user inputEPSS 0.6%CVE-2025-49812HIGHApache HTTP Server: mod_ssl TLS upgrade attackEPSS 0.6%CVE-2025-53192HIGHApache Commons OGNL: Expression Injection leading to RCEEPSS 0.6%CVE-2026-32990MEDIUMApache Tomcat: Fix for CVE-2025-66614 is incompleteEPSS 0.6%CVE-2026-23981MEDIUMApache Superset: Improper Authorization in Chart Update allowing Dashboard ModificationEPSS 0.6%CVE-2026-32642LOWApache Artemis, Apache ActiveMQ Artemis: Temporary address auto-created for OpenWire consumer without createAddress permissionEPSS 0.6%CVE-2026-40914MEDIUMApache Artemis Stomp Protocol, Apache ActiveMQ Artemis Stomp Protocol: Address routing-type can be updated by STOMP protocol user without the createAddress permissionEPSS 0.6%CVE-2025-30001HIGHApache StreamPark: Authenticated users can trigger remote command executionEPSS 0.6%CVE-2026-59739HIGHApache ZooKeeper: Information disclosure via SetWatches reconnect replayEPSS 0.6%CVE-2025-31698HIGHApache Traffic Server: Client IP address from PROXY protocol is not used for ACLEPSS 0.6%CVE-2026-46453MEDIUMApache Camel: Camel-Elasticsearch-Rest-Client: Exchange header constants without the Camel prefix bypass inbound HTTP header filtering, allowing untrusted clients to override the Elasticsearch query and operationEPSS 0.6%CVE-2026-25219MEDIUMApache Airflow: Sensitive Azure Service Bus connection string (and possibly other providers) exposed to users with view accessEPSS 0.6%CVE-2026-48206MEDIUMApache Camel JIRA: A set of non-Camel-prefixed Exchange header constants bypass the HTTP header filter, allowing an HTTP client to drive arbitrary JIRA issue operations using the endpoint's configured credentialsEPSS 0.6%CVE-2024-45693HIGHApache CloudStack: Request origin validation bypass makes account takeover possibleEPSS 0.5%CVE-2026-46591HIGHApache Camel: Camel-Neo4j: JSON property names from the CamelNeo4jMatchProperties header are interpolated into the Cypher WHERE clause without validation, allowing Cypher injection (incomplete remediation of CVE-2025-66169)EPSS 0.5%CVE-2026-87785CRITICALApache Syncope: JWT subject spoofingEPSS 0.5%