Vulnerabilidades em Apache Software Foundation

2.378 resultados
Análise Vexday

O portfólio da Apache Software Foundation acumula 1.872 CVEs catalogadas, das quais 215 são de severidade crítica e 83 contam com prova de conceito pública — fatores que ampliam a superfície de risco operacional para equipes de segurança. A taxa de exploração ativa é especialmente preocupante: 28 vulnerabilidades constam no catálogo KEV da CISA, representando uma proporção 3,3 vezes acima da média geral do catálogo, o que indica atenção consistente de agentes maliciosos ao ecossistema Apache. A falha mais comum é CWE-20 (validação inadequada de entrada), padrão estrutural que tende a se manifestar em múltiplos produtos e versões, exigindo revisão ampla e não pontual. Destaque para CVE-2021-40438, a vulnerabilidade de maior risco ativo no momento, com EPSS máximo de 1,0 — probabilidade de exploração na prática praticamente certa —, o que a torna prioridade imediata de remediação para qualquer organização que opere componentes Apache afetados.

CVE-2026-41605HIGHApache Thrift: Swift Compact Protocol integer overflowEPSS 1.3%CVE-2022-43717MEDIUMApache Superset: Cross-Site Scripting on dashboardsEPSS 1.3%CVE-2025-30177MEDIUMApache Camel: Camel-Undertow Message Header Injection via Improper FilteringEPSS 1.2%CVE-2023-31064HIGHApache InLong: Insecurity direct object references cancelling applicationsEPSS 1.2%CVE-2023-31206HIGHApache InLong: Attackers can change the immutable name and type of nodesEPSS 1.2%CVE-2023-24829HIGHApache IoTDB Workbench: apache/iotdb-web-workbench: forge the JWTToken to access workbenchEPSS 1.2%CVE-2025-59059CRITICALApache Ranger: Remote Code Execution Vulnerability in NashornScriptEngineCreatorEPSS 1.2%CVE-2024-50378MEDIUMApache Airflow: Secrets not masked in UI when sensitive variables are set via Airflow cliEPSS 1.2%CVE-2026-44416CRITICALApache Ranger: Remote Code Execution via Arbitrary Class InstantiationEPSS 1.2%CVE-2024-31141MEDIUMApache Kafka Clients: Privilege escalation to filesystem read-access via automatic ConfigProviderEPSS 1.2%CVE-2022-45438MEDIUMApache Superset: Dashboard metadata information leakEPSS 1.2%CVE-2024-24683MEDIUMApache Hop Engine: ID isn't escaped when generating HTMLEPSS 1.2%CVE-2023-51770HIGHApache DolphinScheduler: Arbitrary File Read VulnerabilityEPSS 1.2%CVE-2024-51569HIGHApache NimBLE: Lack of input sanitization leading to out-of-bound reads in Number of Completed Packets HCI event handlerEPSS 1.2%CVE-2024-29178HIGHApache StreamPark: FreeMarker SSTI RCE VulnerabilityEPSS 1.2%CVE-2024-45498HIGHApache Airflow: Command Injection in an example DAGEPSS 1.2%CVE-2023-31098CRITICALApache InLong: Weak Password Implementation in InLongEPSS 1.2%CVE-2023-45725—Apache CouchDB, IBM Cloudant: Privilege Escalation Using _design DocumentsEPSS 1.2%CVE-2023-45348—Apache Airflow: Configuration information leakage vulnerabilityEPSS 1.2%CVE-2023-41752HIGHApache Traffic Server: s3_auth plugin problem with hash calculationEPSS 1.2%