Vulnerabilidades em Apache Software Foundation

2.398 resultados
Análise Vexday

O portfólio da Apache Software Foundation acumula 1.872 CVEs catalogadas, das quais 215 são de severidade crítica e 83 contam com prova de conceito pública — fatores que ampliam a superfície de risco operacional para equipes de segurança. A taxa de exploração ativa é especialmente preocupante: 28 vulnerabilidades constam no catálogo KEV da CISA, representando uma proporção 3,3 vezes acima da média geral do catálogo, o que indica atenção consistente de agentes maliciosos ao ecossistema Apache. A falha mais comum é CWE-20 (validação inadequada de entrada), padrão estrutural que tende a se manifestar em múltiplos produtos e versões, exigindo revisão ampla e não pontual. Destaque para CVE-2021-40438, a vulnerabilidade de maior risco ativo no momento, com EPSS máximo de 1,0 — probabilidade de exploração na prática praticamente certa —, o que a torna prioridade imediata de remediação para qualquer organização que opere componentes Apache afetados.

CVE-2025-26796MEDIUMApache Oozie: XSS in Oozie Web ConsoleEPSS 0.5%CVE-2025-62188HIGHApache DolphinScheduler: Users can access sensitive information through the actuator endpoint.EPSS 0.5%CVE-2025-24404HIGHApache HertzBeat (incubating): RCE by parse http sitemap xml responseEPSS 0.5%CVE-2026-49099MEDIUMApache Camel Salesforce: Non-Camel-prefixed Exchange header constants bypass the HTTP header filter, allowing an HTTP client to influence internal behaviourEPSS 0.5%CVE-2026-34033MEDIUMApache Answer: HTML Content Injection in EmailEPSS 0.5%CVE-2026-78254HIGHApache Ant: Path traversal in ftp and scp tasks allows arbitrary file writeEPSS 0.5%CVE-2026-45426LOWApache Airflow: Log server JWT authorization bypass via Python lstrip() character stripping allows cross-Dag log accessEPSS 0.5%CVE-2026-40963LOWApache Airflow: DAG authorization bypass on /ui/structure/structure_dataEPSS 0.5%CVE-2026-24734HIGHApache Tomcat Native, Apache Tomcat: OCSP revocation bypassEPSS 0.5%CVE-2026-44911LOWApache NiFi: Incorrect Authorization for Configuration Verification RequestsEPSS 0.5%CVE-2025-23408HIGHApache Fineract: weak password policyEPSS 0.5%CVE-2024-43166CRITICALIncorrect Default Permissions vulnerability in Apache DolphinScheduler. This issue affects Apache DolphinScheduler: before 3.2.2. Users arEPSS 0.5%CVE-2025-26467HIGHApache Cassandra: User with MODIFY permission on ALL KEYSPACES can escalate privileges to superuser via unsafe actions (4.0.16 only)EPSS 0.5%CVE-2026-34905MEDIUMApache Answer: Unlisted Questions Accessible via Direct API AccessEPSS 0.5%CVE-2026-49877HIGHApache ActiveMQ: Authenticated web users retain admin access by default in the Web ConsoleEPSS 0.5%CVE-2026-24733MEDIUMApache Tomcat: Security constraint bypass with HTTP/0.9EPSS 0.5%CVE-2025-66172HIGHApache CloudStack: Any user can attach a volume in their VMs from backups they should not have access toEPSS 0.5%CVE-2026-73370CRITICALApache Syncope: Cross-Realm boundaries reconciliation bypassEPSS 0.5%CVE-2026-73579CRITICALApache Syncope: Non-recursive Any search could skip Realms restrictionsEPSS 0.5%CVE-2026-73668CRITICALApache Syncope: Cross-realm disclosure of confidential ConnId bundles configuration valuesEPSS 0.5%