Vulnerabilidades em Apache Software Foundation

2.398 resultados
Análise Vexday

O portfólio da Apache Software Foundation acumula 1.872 CVEs catalogadas, das quais 215 são de severidade crítica e 83 contam com prova de conceito pública — fatores que ampliam a superfície de risco operacional para equipes de segurança. A taxa de exploração ativa é especialmente preocupante: 28 vulnerabilidades constam no catálogo KEV da CISA, representando uma proporção 3,3 vezes acima da média geral do catálogo, o que indica atenção consistente de agentes maliciosos ao ecossistema Apache. A falha mais comum é CWE-20 (validação inadequada de entrada), padrão estrutural que tende a se manifestar em múltiplos produtos e versões, exigindo revisão ampla e não pontual. Destaque para CVE-2021-40438, a vulnerabilidade de maior risco ativo no momento, com EPSS máximo de 1,0 — probabilidade de exploração na prática praticamente certa —, o que a torna prioridade imediata de remediação para qualquer organização que opere componentes Apache afetados.

CVE-2026-66422HIGHApache Tomcat: Servlet role references can bypass declarative role constraintsEPSS 0.5%CVE-2026-47340MEDIUMApache DolphinScheduler: An incorrect authorization vulnerability allows authenticated users to access alert instances associated with alert groups they do not have permission to access.EPSS 0.5%CVE-2026-32967MEDIUMApache DolphinScheduler: The `/v2` experimental interface lacks permission checksEPSS 0.5%CVE-2025-64402MEDIUMApache OpenOffice: Remote documents loaded without prompt via OLE objectsEPSS 0.5%CVE-2026-75020HIGHApache APISIX: ldap-auth plugin cross-subtree identity impersonationEPSS 0.5%CVE-2026-54048MEDIUMApache Impala: Avro Schema URL Server-Side Request ForgeryEPSS 0.5%CVE-2026-50623MEDIUMApache CXF: Authentication Bypass in OAuth2 TokenIntrospectionServiceEPSS 0.5%CVE-2026-25854MEDIUMApache Tomcat: Occasionally open redirectEPSS 0.5%CVE-2026-65181HIGHApache Impala: RCE via External Data Source Class LoadingEPSS 0.5%CVE-2026-42526MEDIUMApache Airflow Amazon provider: Prevent unauthorized access to team-scoped secrets in AWS Secrets Manager and SSM Parameter Store backendsEPSS 0.5%CVE-2026-34476HIGHApache SkyWalking MCP: Server-Side Request Forgery via SW-URL Header in MCP ServerEPSS 0.5%CVE-2026-50222HIGHApache CloudStack: Improper access control in Userdata reference APIsEPSS 0.5%CVE-2026-41280MEDIUMApache DolphinScheduler: Incorrect Authorization vulnerability allows users with system login privileges to delete task definitions in unauthorized projectsEPSS 0.5%CVE-2026-31377HIGHApache Doris: Improper Authentication Allows Unauthorized Access to FE Meta ServiceEPSS 0.5%CVE-2026-62440CRITICALApache CloudStack: Improper access control in Kubernetes Service (CKS) cluster manipulationEPSS 0.5%CVE-2026-44618MEDIUMApache CXF: XXE vulnerability in WS-Transfer functionalityEPSS 0.5%CVE-2026-31388MEDIUMApache OFBiz: Cross-Tenant Data Exposure via Program Export FeatureEPSS 0.5%CVE-2025-55017CRITICALApache IoTDB: Path Traversal VulnerabilityEPSS 0.5%CVE-2025-62233MEDIUMApache DolphinScheduler: Deserialization of untrusted data in RPCEPSS 0.5%CVE-2026-40005CRITICALApache IoTDB: Path Traversal in Pipe File Transfer ReceiverEPSS 0.5%