Vulnerabilidades em Apache Software Foundation

2.378 resultados
Análise Vexday

O portfólio da Apache Software Foundation acumula 1.872 CVEs catalogadas, das quais 215 são de severidade crítica e 83 contam com prova de conceito pública — fatores que ampliam a superfície de risco operacional para equipes de segurança. A taxa de exploração ativa é especialmente preocupante: 28 vulnerabilidades constam no catálogo KEV da CISA, representando uma proporção 3,3 vezes acima da média geral do catálogo, o que indica atenção consistente de agentes maliciosos ao ecossistema Apache. A falha mais comum é CWE-20 (validação inadequada de entrada), padrão estrutural que tende a se manifestar em múltiplos produtos e versões, exigindo revisão ampla e não pontual. Destaque para CVE-2021-40438, a vulnerabilidade de maior risco ativo no momento, com EPSS máximo de 1,0 — probabilidade de exploração na prática praticamente certa —, o que a torna prioridade imediata de remediação para qualquer organização que opere componentes Apache afetados.

CVE-2026-50632HIGHApache CXF: JNDI Injection Vulnerability in JMSConfigFactoryEPSS 1.1%CVE-2023-30576MEDIUMApache Guacamole: Use-after-free in handling of RDP audio input bufferEPSS 1.1%CVE-2023-36388MEDIUMApache Superset: Improper API permission for low privilege users allows for SSRFEPSS 1.1%CVE-2023-31101—Apache InLong: Users who joined later can see the data of deleted usersEPSS 1.1%CVE-2026-52680CRITICALApache Kyuubi: REST batch multipart upload path traversal allows controlled file writeEPSS 1.1%CVE-2023-22946MEDIUMApache Spark proxy-user privilege escalation from malicious configuration classEPSS 1.1%CVE-2024-31411MEDIUMApache StreamPipes: Potential remote code execution (RCE) via file uploadEPSS 1.1%CVE-2017-7661—Apache CXF Fediz ships with a number of container-specific plugins to enable WS-Federation for applications. A CSRF (Cross Style Request ForEPSS 1.1%CVE-2024-23537HIGHApache Fineract: Under certain circumstances, this vulnerability allowed users, without specific permissions, to escalate their privileges to any role.EPSS 1.1%CVE-2022-37392MEDIUMApache Traffic Server: Improperly reading the client requestsEPSS 1.1%CVE-2022-45801—Apache StreamPark (incubating): LDAP Injection VulnerabilityEPSS 1.1%CVE-2023-35701MEDIUMApache Hive: Arbitrary command execution via JDBC driverEPSS 1.1%CVE-2022-45135CRITICALApache Cocoon: SQL injection in DatabaseCookieAuthenticatorActionEPSS 1.1%CVE-2026-50223HIGHApache OFBiz: DataResource Low-Privileged Authenticated FreeMarker Template Injection Leads to Remote Code ExecutionEPSS 1.1%CVE-2026-41606MEDIUMApache Thrift: c_glib dispatch stack overflowEPSS 1.1%CVE-2017-12630—In Apache Drill 1.11.0 and earlier when submitting form from Query page users are able to pass arbitrary script or HTML which will take effeEPSS 1.1%CVE-2023-31469HIGHApache StreamPipes: Privilege escalation through non-admin userEPSS 1.1%CVE-2025-24860MEDIUMApache Cassandra: CassandraNetworkAuthorizer and CassandraCIDRAuthorizer can be bypassed allowing access to different network regionsEPSS 1.1%CVE-2023-29032HIGHApache OpenMeetings: allows bypass authenticationEPSS 1.1%CVE-2024-21742MEDIUMApache James Mime4J: Mime4J DOM header injectionEPSS 1.1%