Vulnerabilidades em Apache Software Foundation

2.378 resultados
Análise Vexday

O portfólio da Apache Software Foundation acumula 1.872 CVEs catalogadas, das quais 215 são de severidade crítica e 83 contam com prova de conceito pública — fatores que ampliam a superfície de risco operacional para equipes de segurança. A taxa de exploração ativa é especialmente preocupante: 28 vulnerabilidades constam no catálogo KEV da CISA, representando uma proporção 3,3 vezes acima da média geral do catálogo, o que indica atenção consistente de agentes maliciosos ao ecossistema Apache. A falha mais comum é CWE-20 (validação inadequada de entrada), padrão estrutural que tende a se manifestar em múltiplos produtos e versões, exigindo revisão ampla e não pontual. Destaque para CVE-2021-40438, a vulnerabilidade de maior risco ativo no momento, com EPSS máximo de 1,0 — probabilidade de exploração na prática praticamente certa —, o que a torna prioridade imediata de remediação para qualquer organização que opere componentes Apache afetados.

CVE-2023-51441HIGHApache Axis 1.x (EOL) may allow SSRF when untrusted input is passed to the service admin HTTP APIEPSS 1.2%CVE-2023-46215HIGHApache Airflow Celery provider, Apache Airflow: Sensitive information logged as clear text when rediss, amqp, rpc protocols are used as Celery result backendEPSS 1.2%CVE-2023-50378MEDIUMApache Ambari: Various XSS problemsEPSS 1.2%CVE-2023-49145HIGHApache NiFi: Improper Neutralization of Input in Advanced User Interface for JoltEPSS 1.2%CVE-2022-42009HIGHApache Ambari: A malicious authenticated user can remotely execute arbitrary code in the context of the application.EPSS 1.2%CVE-2022-45855HIGHApache Ambari: Allows authenticated metrics consumers to perform RCEEPSS 1.2%CVE-2026-34356HIGHApache HTTP Server: ProxyPassReverseCookieMap buffer overflowEPSS 1.2%CVE-2025-27696MEDIUMApache Superset: Incorrect authorization leading to resource ownership takeoverEPSS 1.2%CVE-2023-27526MEDIUMApache Superset: Improper Authorization check on import chartsEPSS 1.2%CVE-2025-64404HIGHApache OpenOffice: Remote documents loaded without prompt via background and bullet imagesEPSS 1.2%CVE-2025-49630HIGHApache HTTP Server: mod_proxy_http2 denial of serviceEPSS 1.2%CVE-2023-28936MEDIUMApache OpenMeetings: insufficient check of invitation hashEPSS 1.2%CVE-2018-17184—A malicious user with enough administration entitlements can inject html-like elements containing JavaScript statements into Connector namesEPSS 1.2%CVE-2022-41703MEDIUMApache Superset: SQL injection vulnerability in adhoc clausesEPSS 1.2%CVE-2026-33007MEDIUMApache HTTP Server: mod_authn_socache crashEPSS 1.2%CVE-2022-46651—Apache Airflow: Security vulnerability on AirFlow ConnectionsEPSS 1.2%CVE-2026-43868MEDIUMApache Thrift: Rust implementation vulnerable to CVE-2020-13949 patternEPSS 1.2%CVE-2024-41172MEDIUMApache CXF: Unrestricted memory consumption in CXF HTTP clientsEPSS 1.2%CVE-2022-34870MEDIUMApache Geode stored Cross-Site Scripting (XSS) via data injection vulnerability in Pulse web applicationEPSS 1.2%CVE-2024-27138HIGHApache Archiva: disabling user registration is not effectiveEPSS 1.2%