Vulnerabilidades em Apache Software Foundation

2.378 resultados
Análise Vexday

O portfólio da Apache Software Foundation acumula 1.872 CVEs catalogadas, das quais 215 são de severidade crítica e 83 contam com prova de conceito pública — fatores que ampliam a superfície de risco operacional para equipes de segurança. A taxa de exploração ativa é especialmente preocupante: 28 vulnerabilidades constam no catálogo KEV da CISA, representando uma proporção 3,3 vezes acima da média geral do catálogo, o que indica atenção consistente de agentes maliciosos ao ecossistema Apache. A falha mais comum é CWE-20 (validação inadequada de entrada), padrão estrutural que tende a se manifestar em múltiplos produtos e versões, exigindo revisão ampla e não pontual. Destaque para CVE-2021-40438, a vulnerabilidade de maior risco ativo no momento, com EPSS máximo de 1,0 — probabilidade de exploração na prática praticamente certa —, o que a torna prioridade imediata de remediação para qualquer organização que opere componentes Apache afetados.

CVE-2024-42062HIGHApache CloudStack: User Key Exposure to Domain AdminsEPSS 0.9%CVE-2026-33857MEDIUMApache HTTP Server: Off-by-one OOB reads in AJP getter functionsEPSS 0.9%CVE-2026-34032MEDIUMApache HTTP Server: mod_proxy_ajp: Heap Buffer Over-Read Due to Missing Null-Termination Check (ajp_msg_get_string)EPSS 0.9%CVE-2025-29868MEDIUMApache Answer: Using externally referenced images can leak user privacy.EPSS 0.9%CVE-2026-66256HIGHApache Shindig Common, Apache Shindig Social-Api: Remote Code Execution via XStream deserialization (OpenSocial REST API)EPSS 0.9%CVE-2022-37400—Apache OpenOffice Static Initialization Vector Allows to Recover Passwords for Web Connections Without Knowing the Master PasswordEPSS 0.9%CVE-2023-49198HIGHApache SeaTunnel Web: Arbitrary file read vulnerabilityEPSS 0.9%CVE-2026-33557CRITICALApache Kafka: Missing JWT token validation in OAUTHBEARER authenticationEPSS 0.9%CVE-2024-42447CRITICALApache Airflow Providers FAB: FAB provider 1.2.1 and 1.2.0 did not let user to logout for AirflowEPSS 0.9%CVE-2026-45249MEDIUMApache ECharts: XSS in Lines series tooltip renderingEPSS 0.9%CVE-2026-45360HIGHApache Airflow: Arbitrary import in custom deadline-reference deserializationEPSS 0.9%CVE-2024-50305HIGHApache Traffic Server: Valid Host field value can cause crashesEPSS 0.9%CVE-2026-43867CRITICALApache Camel: Camel-PQC: The AWS Secrets Manager key-lifecycle manager deserializes persisted key metadata with java.io.ObjectInputStream and no ObjectInputFilterEPSS 0.9%CVE-2026-58076HIGHApache Airflow: Unguarded import_string() of airflow_exc_ser / base_exc_ser exception nodes in BaseSerialization.deserialize enables DAG-author RCE on Scheduler / API ServerEPSS 0.9%CVE-2022-44729—Apache XML Graphics Batik: Information disclosure vulnerabilityEPSS 0.9%CVE-2025-30473HIGHApache Airflow Common SQL Provider: Remote Code Execution via Sql InjectionEPSS 0.9%CVE-2021-40331HIGHPermissions problem in the Apache Ranger Hive PluginEPSS 0.9%CVE-2024-51504CRITICALApache ZooKeeper: Authentication bypass with IP-based authentication in Admin ServerEPSS 0.9%CVE-2026-70449MEDIUMApache Wicket: Path traversal in resource style/variation/localeEPSS 0.9%CVE-2025-54831MEDIUMApache Airflow: Connection sensitive details exposed to users with READ permissionsEPSS 0.9%