Vulnerabilidades em Apache Software Foundation

2.345 resultados
Análise Vexday

O portfólio da Apache Software Foundation acumula 1.872 CVEs catalogadas, das quais 215 são de severidade crítica e 83 contam com prova de conceito pública — fatores que ampliam a superfície de risco operacional para equipes de segurança. A taxa de exploração ativa é especialmente preocupante: 28 vulnerabilidades constam no catálogo KEV da CISA, representando uma proporção 3,3 vezes acima da média geral do catálogo, o que indica atenção consistente de agentes maliciosos ao ecossistema Apache. A falha mais comum é CWE-20 (validação inadequada de entrada), padrão estrutural que tende a se manifestar em múltiplos produtos e versões, exigindo revisão ampla e não pontual. Destaque para CVE-2021-40438, a vulnerabilidade de maior risco ativo no momento, com EPSS máximo de 1,0 — probabilidade de exploração na prática praticamente certa —, o que a torna prioridade imediata de remediação para qualquer organização que opere componentes Apache afetados.

CVE-2022-40127HIGHApache Airflow <2.4.0 has an RCE in a bash exampleEPSS 85.7%CVE-2021-31805Forced OGNL evaluation, when evaluated on raw not validated user input in tag attributes, may lead to RCE.EPSS 85.4%CVE-2022-27166XSS vulnerability on XHRHtml2Markup.jsp in JSPWiki 2.11.2EPSS 85.4%CVE-2022-28730Apache JSPWiki Cross-site scripting vulnerability on AJAXPreview.jspEPSS 85.4%CVE-2022-24697CRITICALApache Kylin prior to 4.0.2 allows command injection when the configuration overwrites function overwrites system parametersEPSS 84.8%CVE-2023-25690CRITICALApache HTTP Server: HTTP request splitting with mod_rewrite and mod_proxyEPSS 84.5%CVE-2021-38294Shell Command Injection Vulnerability in Nimbus Thrift ServerEPSS 84.5%CVE-2018-11759The Apache Web Server (httpd) specific code that normalised the requested path before matching it to the URI-worker map in Apache Tomcat JK EPSS 83.8%CVE-2023-50386HIGHApache Solr: Backup/Restore APIs allow for deployment of executables in malicious ConfigSetsEPSS 83.7%CVE-2021-44224Possible NULL dereference or SSRF in forward proxy configurations in Apache HTTP Server 2.4.51 and earlierEPSS 82.3%CVE-2022-28732Apache JSPWiki Cross-site scripting vulnerability on WeblogPluginEPSS 82.0%CVE-2022-45402MEDIUMApache Airflow: Open redirect during loginEPSS 81.8%CVE-2021-30128Unsafe deserialization in Apache OFBizEPSS 81.2%CVE-2021-4104HIGHDeserialization of untrusted data in JMSAppender in Apache Log4j 1.2EPSS 81.1%CVE-2025-27636MEDIUMApache Camel: Camel Message Header Injection via Improper FilteringEPSS 81.1%CVE-2022-34169HIGHApache Xalan Java XSLT library is vulnerable to an integer truncation issue when processing malicious XSLT stylesheetsEPSS 81.0%CVE-2021-38540Apache Airflow: Variable Import endpoint missed authentication checkEPSS 80.9%CVE-2021-36749Apache Druid: The HTTP inputSource allows authenticated users to read data from other sources than intended (incomplete fix of CVE-2021-26920)EPSS 80.9%CVE-2023-50164Apache Struts: File upload component had a directory traversal vulnerabilityEPSS 80.8%CVE-2024-56325CRITICALApache Pinot: Authentication bypass issue. If the path does not contain / and contain . authentication is not requiredEPSS 80.2%