Vulnerabilidades em Apache Software Foundation

2.378 resultados
Análise Vexday

O portfólio da Apache Software Foundation acumula 1.872 CVEs catalogadas, das quais 215 são de severidade crítica e 83 contam com prova de conceito pública — fatores que ampliam a superfície de risco operacional para equipes de segurança. A taxa de exploração ativa é especialmente preocupante: 28 vulnerabilidades constam no catálogo KEV da CISA, representando uma proporção 3,3 vezes acima da média geral do catálogo, o que indica atenção consistente de agentes maliciosos ao ecossistema Apache. A falha mais comum é CWE-20 (validação inadequada de entrada), padrão estrutural que tende a se manifestar em múltiplos produtos e versões, exigindo revisão ampla e não pontual. Destaque para CVE-2021-40438, a vulnerabilidade de maior risco ativo no momento, com EPSS máximo de 1,0 — probabilidade de exploração na prática praticamente certa —, o que a torna prioridade imediata de remediação para qualquer organização que opere componentes Apache afetados.

CVE-2023-37581—Apache Roller: Roller's weblog category, weblog settings and file-upload features did not properly sanitize input could be exploited to perform Reflected Cross Site Scripting (XSS) even on a Roller site configured for untrusted users.EPSS 1.2%CVE-2025-24814MEDIUMApache Solr: Core-creation with "trusted" configset can use arbitrary untrusted filesEPSS 1.2%CVE-2026-67587HIGHApache Airflow: DAG-author remote code execution on the Scheduler via a Serde `Callback` deserialization gadgetEPSS 1.2%CVE-2025-61795MEDIUMApache Tomcat: Delayed cleaning of multi-part upload temporary files may lead to DoSEPSS 1.2%CVE-2023-30465MEDIUMApache InLong: SQL injection in apache inLong 1.5.0EPSS 1.2%CVE-2022-46907—Apache JSPWiki: XSS Injection points in several pluginsEPSS 1.2%CVE-2023-31065CRITICALApache InLong: Insufficient Session Expiration in InLongEPSS 1.2%CVE-2023-28158MEDIUMApache Archiva privilege escalationEPSS 1.2%CVE-2024-34365CRITICALApache Karaf Cave: Cave SSRF and arbitrary file accessEPSS 1.2%CVE-2022-44644MEDIUMApache Linkis (incubating): The DatasourceManager module has a Local File Read VulnerabilityEPSS 1.2%CVE-2022-24947—Apache JSPWiki CSRF Account TakeoverEPSS 1.2%CVE-2023-24977HIGHApache InLong: Jdbc Connection causes arbitrary file reading in InLongEPSS 1.2%CVE-2023-25141HIGHJNDI injection into Apache sling-org-apache-sling-jcr-baseEPSS 1.2%CVE-2025-32896MEDIUMApache SeaTunnel: Unauthenticated insecure accessEPSS 1.2%CVE-2026-41044HIGHApache ActiveMQ, Apache ActiveMQ Broker, Apache ActiveMQ All: Authenticated user can perform RCE via DestinationView MBean exposed by JolokiaEPSS 1.1%CVE-2022-46870MEDIUMApache Zeppelin: Stored XSS in note permissionsEPSS 1.1%CVE-2023-29055HIGHApache Kylin: Insufficiently protected credentials in config fileEPSS 1.1%CVE-2023-42504MEDIUMApache Superset: Lack of rate limiting allows for possible denial of serviceEPSS 1.1%CVE-2024-41890MEDIUMApache Answer: The link to reset the user's password will remain valid after sending a new linkEPSS 1.1%CVE-2023-25621MEDIUMApache Sling does not allow to handle i18n content in a secure wayEPSS 1.1%