Vulnerabilidades em Apache Software Foundation

2.334 resultados
Análise Vexday

O portfólio da Apache Software Foundation acumula 1.872 CVEs catalogadas, das quais 215 são de severidade crítica e 83 contam com prova de conceito pública — fatores que ampliam a superfície de risco operacional para equipes de segurança. A taxa de exploração ativa é especialmente preocupante: 28 vulnerabilidades constam no catálogo KEV da CISA, representando uma proporção 3,3 vezes acima da média geral do catálogo, o que indica atenção consistente de agentes maliciosos ao ecossistema Apache. A falha mais comum é CWE-20 (validação inadequada de entrada), padrão estrutural que tende a se manifestar em múltiplos produtos e versões, exigindo revisão ampla e não pontual. Destaque para CVE-2021-40438, a vulnerabilidade de maior risco ativo no momento, com EPSS máximo de 1,0 — probabilidade de exploração na prática praticamente certa —, o que a torna prioridade imediata de remediação para qualquer organização que opere componentes Apache afetados.

CVE-2016-8748—In Apache NiFi before 1.0.1 and 1.1.x before 1.1.1, there is a cross-site scripting vulnerability in connection details dialog when accessedEPSS 2.0%CVE-2025-53506HIGHApache Tomcat: DoS via excessive h2 streams at connection startEPSS 2.0%CVE-2021-44040—HTTP request line fuzzing attacksEPSS 2.0%CVE-2022-30973—Missing fix for CVE-2022-30126 in 1.28.2EPSS 2.0%CVE-2018-1314—In Apache Hive 2.3.3, 3.1.0 and earlier, Hive "EXPLAIN" operation does not check for necessary authorization of involved entities in a queryEPSS 2.0%CVE-2022-25763MEDIUMImproper input validation on HTTP/2 headers EPSS 2.0%CVE-2022-33879—Incomplete fix and new regex DoS in StandardsExtractingContentHandlerEPSS 2.0%CVE-2023-29247—Stored XSS on Apache AirflowEPSS 2.0%CVE-2026-23795MEDIUMApache Syncope: Console XXE on Keymaster parametersEPSS 2.0%CVE-2025-22828MEDIUMApache CloudStack: Unauthorised access to annotationsEPSS 2.0%CVE-2023-25696CRITICALApache Airflow Hive Provider Beeline RCEEPSS 2.0%CVE-2022-25598—Apache DolphinScheduler user registration is vulnerable to ReDoS attacksEPSS 2.0%CVE-2022-23206—Server-Side Request Forgery in Traffic Ops endpoint POST /user/login/oauthEPSS 2.0%CVE-2020-9479—unzip directory traversalEPSS 2.0%CVE-2022-28220—STARTTLS command injection in Apache JAMESEPSS 2.0%CVE-2025-46392MEDIUMApache Commons Configuration: Uncontrolled Resource Consumption when loading untrusted configurations in 1.xEPSS 2.0%CVE-2016-8742—The Windows installer that the Apache CouchDB team provides was vulnerable to local privilege escalation. All files in the install inherit tEPSS 2.0%CVE-2023-37379—Apache Airflow: Exposure of sensitive connection information, DOS and SSRF on "test connection" featureEPSS 2.0%CVE-2018-20244—In Apache Airflow before 1.10.2, a malicious admin user could edit the state of objects in the Airflow metadata database to execute arbitrarEPSS 2.0%CVE-2018-1338—A carefully crafted (or fuzzed) file can trigger an infinite loop in Apache Tika's BPGParser in versions of Apache Tika before 1.18.EPSS 2.0%