Vulnerabilidades em Apache Software Foundation

2.378 resultados
Análise Vexday

O portfólio da Apache Software Foundation acumula 1.872 CVEs catalogadas, das quais 215 são de severidade crítica e 83 contam com prova de conceito pública — fatores que ampliam a superfície de risco operacional para equipes de segurança. A taxa de exploração ativa é especialmente preocupante: 28 vulnerabilidades constam no catálogo KEV da CISA, representando uma proporção 3,3 vezes acima da média geral do catálogo, o que indica atenção consistente de agentes maliciosos ao ecossistema Apache. A falha mais comum é CWE-20 (validação inadequada de entrada), padrão estrutural que tende a se manifestar em múltiplos produtos e versões, exigindo revisão ampla e não pontual. Destaque para CVE-2021-40438, a vulnerabilidade de maior risco ativo no momento, com EPSS máximo de 1,0 — probabilidade de exploração na prática praticamente certa —, o que a torna prioridade imediata de remediação para qualquer organização que opere componentes Apache afetados.

CVE-2017-9796—When an Apache Geode cluster before v1.3.0 is operating in secure mode, a user with read access to specific regions within a Geode cluster mEPSS 1.5%CVE-2022-37022—Apache Geode deserialization of untrusted data flaw when using JMX over RMI on Java 11EPSS 1.5%CVE-2022-43670MEDIUMXSS in Sling CMS Reference App Taxonomy PathEPSS 1.5%CVE-2022-46365CRITICALApache StreamPark (incubating): Logic error causing any account resetEPSS 1.5%CVE-2023-27296HIGHApache InLong: JDBC Deserialization Vulnerability in InLongEPSS 1.5%CVE-2023-32200HIGHApache Jena: Exposure of execution in script engine expressions.EPSS 1.5%CVE-2024-50386HIGHApache CloudStack: Directly downloaded templates can be used to abuse KVM-based infrastructureEPSS 1.5%CVE-2022-24963CRITICALApache Portable Runtime (APR): out-of-bound writes in the apr_encode family of functionsEPSS 1.5%CVE-2024-27905CRITICALApache Aurora: padding oracle can allow construction an authentication cookieEPSS 1.5%CVE-2018-1332—Apache Storm version 1.0.6 and earlier, 1.2.1 and earlier, and version 1.1.2 and earlier expose a vulnerability that could allow a user to iEPSS 1.5%CVE-2023-29246HIGHApache OpenMeetings: allows null-byte InjectionEPSS 1.5%CVE-2023-26513HIGHApache Sling Resource Merger: Requests to certain paths managed by the Apache Sling Resource Merger can lead to DoSEPSS 1.5%CVE-2024-29735MEDIUMApache Airflow: Potentially harmful permission changing by log task handlerEPSS 1.5%CVE-2025-35003CRITICALApache NuttX RTOS: NuttX Bluetooth Stack HCI and UART DoS/RCE Vulnerabilities.EPSS 1.5%CVE-2023-28754HIGHShardingSphere-Agent: Deserialization vulnerability in ShardingSphere AgentEPSS 1.5%CVE-2025-49656HIGHApache Jena: Administrative users can create files outside the server directory space via the admin UIEPSS 1.5%CVE-2023-30771CRITICALApache IoTDB Workbench: apache/iotdb-web-workbench: forge the JWTToken to access workbenchEPSS 1.4%CVE-2024-24746HIGHApache NimBLE: Denial of service in NimBLE Bluetooth stackEPSS 1.4%CVE-2024-51941HIGHApache Ambari: Remote Code Injection in Ambari Metrics and AMS AlertsEPSS 1.4%CVE-2023-22849MEDIUMApache Sling App CMS: XSS in CMS Reference / UI ComponentsEPSS 1.4%