Vulnerabilidades em Apache Software Foundation

2.378 resultados
Análise Vexday

O portfólio da Apache Software Foundation acumula 1.872 CVEs catalogadas, das quais 215 são de severidade crítica e 83 contam com prova de conceito pública — fatores que ampliam a superfície de risco operacional para equipes de segurança. A taxa de exploração ativa é especialmente preocupante: 28 vulnerabilidades constam no catálogo KEV da CISA, representando uma proporção 3,3 vezes acima da média geral do catálogo, o que indica atenção consistente de agentes maliciosos ao ecossistema Apache. A falha mais comum é CWE-20 (validação inadequada de entrada), padrão estrutural que tende a se manifestar em múltiplos produtos e versões, exigindo revisão ampla e não pontual. Destaque para CVE-2021-40438, a vulnerabilidade de maior risco ativo no momento, com EPSS máximo de 1,0 — probabilidade de exploração na prática praticamente certa —, o que a torna prioridade imediata de remediação para qualquer organização que opere componentes Apache afetados.

CVE-2023-48796—Apache dolphinscheduler sensitive information disclosureEPSS 1.2%CVE-2022-42735HIGHApache ShenYu Admin ultra viresEPSS 1.2%CVE-2024-43383HIGHApache Lucene.Net.Replicator: Remote Code Execution in Lucene.Net.ReplicatorEPSS 1.2%CVE-2023-51518CRITICALApache James server: Privilege escalation via JMX pre-authentication deserialisationEPSS 1.2%CVE-2025-54812LOWApache Log4cxx: Improper HTML escaping in HTMLLayoutEPSS 1.2%CVE-2026-86792HIGHApache Airflow Apache Kafka provider: Connection-editor remote code execution on the Scheduler via Kafka connection callback configurationEPSS 1.2%CVE-2023-49736MEDIUMApache Superset: SQL Injection on where_in JINJA macroEPSS 1.2%CVE-2026-34480MEDIUMApache Log4j Core: Silent log event loss in XmlLayout due to unescaped XML 1.0 forbidden charactersEPSS 1.2%CVE-2026-34478MEDIUMApache Log4j Core: Log injection in Rfc5424Layout due to silent configuration incompatibilityEPSS 1.2%CVE-2023-46749MEDIUMApache Shiro before 1.13.0 or 2.0.0-alpha-4, may be susceptible to a path traversal attack that results in an authentication bypass when used together with path rewriting EPSS 1.2%CVE-2021-35940—Regression of CVE-2017-12613EPSS 1.2%CVE-2023-31454HIGHApache InLong: IDOR make users can bind any clusterEPSS 1.2%CVE-2023-31453HIGHApache InLong: IDOR make users can delete others' subscriptionEPSS 1.2%CVE-2017-9794—When a cluster is operating in secure mode, a user with read privileges for specific data regions can use the gfsh command line utility to eEPSS 1.2%CVE-2026-24308MEDIUMApache ZooKeeper: Sensitive information disclosure in client configuration handlingEPSS 1.2%CVE-2024-31867MEDIUMApache Zeppelin: LDAP search filter query Injection VulnerabilityEPSS 1.2%CVE-2024-29831HIGHApache DolphinScheduler: RCE by arbitrary js executionEPSS 1.2%CVE-2026-41604HIGHApache Thrift: Swift Range crash in skip()EPSS 1.2%CVE-2024-36268HIGHApache InLong TubeMQ Client: Remote Code Execution vulnerabilityEPSS 1.2%CVE-2013-4317—In Apache CloudStack 4.1.0 and 4.1.1, when calling the CloudStack API call listProjectAccounts as a regular, non-administrative user, the usEPSS 1.2%