Vulnerabilidades em Apache Software Foundation

2.378 resultados
Análise Vexday

O portfólio da Apache Software Foundation acumula 1.872 CVEs catalogadas, das quais 215 são de severidade crítica e 83 contam com prova de conceito pública — fatores que ampliam a superfície de risco operacional para equipes de segurança. A taxa de exploração ativa é especialmente preocupante: 28 vulnerabilidades constam no catálogo KEV da CISA, representando uma proporção 3,3 vezes acima da média geral do catálogo, o que indica atenção consistente de agentes maliciosos ao ecossistema Apache. A falha mais comum é CWE-20 (validação inadequada de entrada), padrão estrutural que tende a se manifestar em múltiplos produtos e versões, exigindo revisão ampla e não pontual. Destaque para CVE-2021-40438, a vulnerabilidade de maior risco ativo no momento, com EPSS máximo de 1,0 — probabilidade de exploração na prática praticamente certa —, o que a torna prioridade imediata de remediação para qualquer organização que opere componentes Apache afetados.

CVE-2022-37023—Apache Geode deserialization of untrusted data flaw when using REST API on Java 8 or Java 11EPSS 1.7%CVE-2025-48769MEDIUMApache NuttX RTOS: fs/vfs/fs_rename: use after freeEPSS 1.7%CVE-2023-46104MEDIUMApache Superset: Allows for uncontrolled resource consumption via a ZIP bombEPSS 1.7%CVE-2023-46279—Apache Dubbo: Bypass deny serialize list check in Apache DubboEPSS 1.7%CVE-2023-42781—Apache Airflow: Permission verification bypass allows viewing dagruns of other dagsEPSS 1.7%CVE-2021-32609—XSS vulnerability on Explore pageEPSS 1.7%CVE-2023-27604HIGHApache Airflow Sqoop Provider: Airflow Sqoop Provider RCE VulnerabilityEPSS 1.7%CVE-2022-37866HIGHApache Ivy allows path traversal in the presence of a malicious repositoryEPSS 1.7%CVE-2026-33264CRITICALApache Airflow: DAG author RCE on webserver via unrestricted import_string() in BaseSerialization.deserialize()EPSS 1.6%CVE-2017-7673—Apache OpenMeetings 1.0.0 uses not very strong cryptographic storage, captcha is not used in registration and forget password dialogs and auEPSS 1.6%CVE-2023-46851—Apache Allura: sensitive information exposure via importEPSS 1.6%CVE-2022-41137HIGHApache Hive: Deserialization of untrusted data when fetching partitions from the MetastoreEPSS 1.6%CVE-2023-35088CRITICALApache InLong: SQL injection in audit endpointEPSS 1.6%CVE-2017-7682—Apache OpenMeetings 3.2.0 is vulnerable to parameter manipulation attacks, as a result attacker has access to restricted areas.EPSS 1.6%CVE-2024-23452HIGHApache bRPC: HTTP request smuggling vulnerabilityEPSS 1.6%CVE-2026-28780CRITICALApache HTTP Server: buffer overflow in mod_proxy_ajp via ajp_msg_check_header()EPSS 1.6%CVE-2025-59118HIGHApache OFBiz: Critical Remote Command Execution via Unrestricted File UploadEPSS 1.6%CVE-2022-45136CRITICALApache Jena SDB allows arbitrary deserialisation via JDBCEPSS 1.6%CVE-2023-51784CRITICALApache InLong: Remote Code Execution vulnerability in Apache InLong ManagerEPSS 1.6%CVE-2025-59789HIGHApache bRPC: Stack Exhaustion via Unbounded Recursion in JSON ParserEPSS 1.6%