Vulnerabilidades em Apache Software Foundation

2.378 resultados
Análise Vexday

O portfólio da Apache Software Foundation acumula 1.872 CVEs catalogadas, das quais 215 são de severidade crítica e 83 contam com prova de conceito pública — fatores que ampliam a superfície de risco operacional para equipes de segurança. A taxa de exploração ativa é especialmente preocupante: 28 vulnerabilidades constam no catálogo KEV da CISA, representando uma proporção 3,3 vezes acima da média geral do catálogo, o que indica atenção consistente de agentes maliciosos ao ecossistema Apache. A falha mais comum é CWE-20 (validação inadequada de entrada), padrão estrutural que tende a se manifestar em múltiplos produtos e versões, exigindo revisão ampla e não pontual. Destaque para CVE-2021-40438, a vulnerabilidade de maior risco ativo no momento, com EPSS máximo de 1,0 — probabilidade de exploração na prática praticamente certa —, o que a torna prioridade imediata de remediação para qualquer organização que opere componentes Apache afetados.

CVE-2026-66909CRITICALApache CXF: Unsafe deserialization of inbound JMS ObjectMessageEPSS 1.1%CVE-2026-40473HIGHApache Camel Mina: Unsafe Deserialization in MinaConverter.toObjectInput() via TCP/UDPEPSS 1.1%CVE-2022-43718MEDIUMApache Superset: Cross-Site Scripting vulnerability on upload formsEPSS 1.1%CVE-2024-26579CRITICALApache Inlong JDBC VulnerabilityEPSS 1.1%CVE-2026-53421CRITICALApache Syncope: Remote Code Execution via Scripted ConnectorEPSS 1.1%CVE-2017-7662—Apache CXF Fediz ships with an OpenId Connect (OIDC) service which has a Client Registration Service, which is a simple web application thatEPSS 1.1%CVE-2026-27172HIGHApache Camel: Unsafe Java deserialization in camel-consul ConsulRegistry allows arbitrary code execution via malicious values read from the Consul KV storeEPSS 1.1%CVE-2026-27446CRITICALApache Artemis, Apache ActiveMQ Artemis: Auth bypass for Core downstream federationEPSS 1.1%CVE-2023-36387MEDIUMApache Superset: Improper API permission for low privilege usersEPSS 1.1%CVE-2024-43394HIGHApache HTTP Server: SSRF on Windows due to UNC pathsEPSS 1.1%CVE-2023-49620—Apache DolphinScheduler: Authenticated users could delete UDFs in resource center they were not authorized forEPSS 1.1%CVE-2023-39264MEDIUMApache Superset: Stack traces enabled by defaultEPSS 1.1%CVE-2023-25601—Apache DolphinScheduler 3.0.0 to 3.1.1 python gateway has improper authenticationEPSS 1.1%CVE-2022-45048HIGHApache Ranger: code execution vulnerability in policy expressionsEPSS 1.1%CVE-2024-27309HIGHApache Kafka: Potential incorrect access control during migration from ZK mode to KRaft modeEPSS 1.1%CVE-2022-45064HIGHApache Sling Engine: Include-based XSSEPSS 1.1%CVE-2026-25917HIGHApache Airflow: API extra-links triggers XCom deserialization/class instantiation (Airflow 3.1.5)EPSS 1.1%CVE-2024-29737HIGHApache StreamPark (incubating): maven build params could trigger remote command executionEPSS 1.1%CVE-2023-34981HIGHApache Tomcat: AJP response header mix-upEPSS 1.1%CVE-2025-24859LOWApache Roller: Insufficient Session Expiration on Password ChangeEPSS 1.1%