Vulnerabilidades em Apache Software Foundation

2.398 resultados
Análise Vexday

O portfólio da Apache Software Foundation acumula 1.872 CVEs catalogadas, das quais 215 são de severidade crítica e 83 contam com prova de conceito pública — fatores que ampliam a superfície de risco operacional para equipes de segurança. A taxa de exploração ativa é especialmente preocupante: 28 vulnerabilidades constam no catálogo KEV da CISA, representando uma proporção 3,3 vezes acima da média geral do catálogo, o que indica atenção consistente de agentes maliciosos ao ecossistema Apache. A falha mais comum é CWE-20 (validação inadequada de entrada), padrão estrutural que tende a se manifestar em múltiplos produtos e versões, exigindo revisão ampla e não pontual. Destaque para CVE-2021-40438, a vulnerabilidade de maior risco ativo no momento, com EPSS máximo de 1,0 — probabilidade de exploração na prática praticamente certa —, o que a torna prioridade imediata de remediação para qualquer organização que opere componentes Apache afetados.

CVE-2026-77181CRITICALApache Syncope: ClientApp update entitlement not effectiveEPSS 0.5%CVE-2026-73470CRITICALApache Syncope: Delegating users can grant unowned RolesEPSS 0.5%CVE-2026-25604MEDIUMApache Airflow AWS Auth Manager - Host Header Injection Leading to SAML Authentication BypassEPSS 0.5%CVE-2025-64406MEDIUMApache OpenOffice: Possible memory corruption during CSV importEPSS 0.5%CVE-2025-65998HIGHApache Syncope: Default AES key used for internal password encryptionEPSS 0.5%CVE-2018-1334—In Apache Spark 1.0.0 to 2.1.2, 2.2.0 to 2.2.1, and 2.3.0, when using PySpark or SparkR, it's possible for a different local user to connectEPSS 0.5%CVE-2026-34502HIGHApache Portable Runtime Utility: Heap buffer overflow in APR memcached clientEPSS 0.5%CVE-2026-34501HIGHApache Portable Runtime Utility: Heap buffer overflow in APR redis clientEPSS 0.5%CVE-2025-66524HIGHApache NiFi: Deserialization of Untrusted Data in GetAsanaObject ProcessorEPSS 0.5%CVE-2026-49270MEDIUMApache ActiveMQ Broker, Apache ActiveMQ, Apache ActiveMQ All: Durable Subscription Disclosure via Crafted BrokerInfo (OpenWire)EPSS 0.5%CVE-2026-44930MEDIUMApache CXF: LDAP Injection vulnerability in XKMS LDAP RepositoryEPSS 0.5%CVE-2024-43115HIGHApache DolphinScheduler: Alert Script AttackEPSS 0.5%CVE-2026-59084CRITICALApache Tomcat: EncryptInterceptor requirements not clearly documentedEPSS 0.5%CVE-2026-76985MEDIUMApache Wicket: XSS in Palette via getAdditionalAttributesEPSS 0.5%CVE-2026-75802MEDIUMApache Wicket: XSS in AjaxEditableLabel and its subclasses via IChoiceRenderer and defaultNullLabelEPSS 0.5%CVE-2026-76983MEDIUMApache Wicket: XSS in AutoLabelTextResolver via FormComponent.setLabelEPSS 0.5%CVE-2026-76982MEDIUMApache Wicket: XSS in Button via its model objectEPSS 0.5%CVE-2025-62198MEDIUMApache Atlas: Stored XSS in Create Entity pageEPSS 0.5%CVE-2026-76984MEDIUMApache Wicket: XSS in MetaDataHeaderItem via addTagAttributeEPSS 0.5%CVE-2026-47065CRITICALApache MINA: Critical Deserialization Allow-list Bypass via resolveProxyClass - ZDRES-232EPSS 0.5%