Vulnerabilidades em Apache Software Foundation

2.398 resultados
Análise Vexday

O portfólio da Apache Software Foundation acumula 1.872 CVEs catalogadas, das quais 215 são de severidade crítica e 83 contam com prova de conceito pública — fatores que ampliam a superfície de risco operacional para equipes de segurança. A taxa de exploração ativa é especialmente preocupante: 28 vulnerabilidades constam no catálogo KEV da CISA, representando uma proporção 3,3 vezes acima da média geral do catálogo, o que indica atenção consistente de agentes maliciosos ao ecossistema Apache. A falha mais comum é CWE-20 (validação inadequada de entrada), padrão estrutural que tende a se manifestar em múltiplos produtos e versões, exigindo revisão ampla e não pontual. Destaque para CVE-2021-40438, a vulnerabilidade de maior risco ativo no momento, com EPSS máximo de 1,0 — probabilidade de exploração na prática praticamente certa —, o que a torna prioridade imediata de remediação para qualquer organização que opere componentes Apache afetados.

CVE-2026-48912MEDIUMApache Answer: Improper authorization in avatar update cleanup allows authenticated users to delete arbitrary uploaded files by URLEPSS 0.5%CVE-2026-50749MEDIUMApache Answer: Missing authorization in revision audit reject allows authenticated users to reject pending revisionsEPSS 0.5%CVE-2026-58301MEDIUMApache Shiro: Server-side POST request may be steered to an alternate hostEPSS 0.5%CVE-2026-72524HIGHApache Doris: Authorization bypass allowing a low-privilege user to read/write/drop arbitrary tablesEPSS 0.5%CVE-2026-47898MEDIUMApache Lucene.Net: XXE vulnerability in Lucene.Net.Analysis.Common PatternParserEPSS 0.5%CVE-2026-56207CRITICALApache Impala: SAML authentication bypass via forged bearer tokenEPSS 0.5%CVE-2025-46647MEDIUMApache APISIX: improper validation of issuer from introspection discovery url in plugin openid-connectEPSS 0.5%CVE-2026-64607MEDIUMApache HttpComponents Client: Connection Leak on Content-Encoding Decode Error Leads to Pool Exhaustion DoSEPSS 0.5%CVE-2025-59355MEDIUMApache Linkis: Password ExposureEPSS 0.5%CVE-2026-66797MEDIUMApache CloudStack: Unauthorised comment creation and disclosureEPSS 0.5%CVE-2025-54941MEDIUMApache Airflow: Command injection in "example_dag_decorator"EPSS 0.5%CVE-2025-64407MEDIUMApache OpenOffice: URL fetching can be used to exfiltrate arbitrary INI file values and environment variablesEPSS 0.5%CVE-2026-40048HIGHApache Camel PQC: Unsafe Deserialization from FileBasedKeyLifecycleManagerEPSS 0.5%CVE-2026-32327CRITICALApache Portable Runtime Utility: apr-util XML stack recursion crashEPSS 0.5%CVE-2026-80181CRITICALApache Allura: Server-side request forgeryEPSS 0.5%CVE-2025-59302MEDIUMApache CloudStack: Potential remote code execution on Javascript engine defined rulesEPSS 0.5%CVE-2026-61487MEDIUMApache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Authorization bypass via temporary composite destinationsEPSS 0.5%CVE-2026-65183HIGHApache Tomcat: TOCTOU when setting specific permissions for Unix Domain SocketsEPSS 0.5%CVE-2026-52691HIGHApache Griffin Hive Metastore Module: SQL Injection Vulnerability in Hive Metastore ModuleEPSS 0.5%CVE-2025-62228MEDIUMApache Flink CDC, Apache Flink CDC, Apache Flink CDC, Apache Flink CDC, Apache Flink CDC: SQL injection via maliciously crafted identifiersEPSS 0.5%