Vulnerabilidades em Apache Software Foundation

2.378 resultados
Análise Vexday

O portfólio da Apache Software Foundation acumula 1.872 CVEs catalogadas, das quais 215 são de severidade crítica e 83 contam com prova de conceito pública — fatores que ampliam a superfície de risco operacional para equipes de segurança. A taxa de exploração ativa é especialmente preocupante: 28 vulnerabilidades constam no catálogo KEV da CISA, representando uma proporção 3,3 vezes acima da média geral do catálogo, o que indica atenção consistente de agentes maliciosos ao ecossistema Apache. A falha mais comum é CWE-20 (validação inadequada de entrada), padrão estrutural que tende a se manifestar em múltiplos produtos e versões, exigindo revisão ampla e não pontual. Destaque para CVE-2021-40438, a vulnerabilidade de maior risco ativo no momento, com EPSS máximo de 1,0 — probabilidade de exploração na prática praticamente certa —, o que a torna prioridade imediata de remediação para qualquer organização que opere componentes Apache afetados.

CVE-2026-39816HIGHApache NiFi: Missing Execute Code Required Permission on TinkerpopClientServiceEPSS 0.9%CVE-2024-37358HIGHApache James: denial of service through the use of IMAP literalsEPSS 0.9%CVE-2026-23907MEDIUMApache PDFBox Examples: Path Traversal in PDFBox ExtractEmbeddedFiles Example CodeEPSS 0.9%CVE-2026-40859HIGHApache Camel: Camel-Vertx-Http: Unsafe Java deserialization of HTTP response bodies via a raw ObjectInputStream when transferException is enabledEPSS 0.9%CVE-2026-45505HIGHApache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Jolokia `addNetworkConnector` Discovery Wrapper BypassEPSS 0.9%CVE-2026-50203CRITICALApache Airflow SFTP provider: Path traversal in SFTPHook.retrieve_directory allows local file write outside the destination directory via malicious server-supplied directory-entry namesEPSS 0.9%CVE-2022-44730—Apache XML Graphics Batik: Information disclosure vulnerabilityEPSS 0.9%CVE-2017-15719—In Wicket jQuery UI 6.28.0 and earlier, 7.9.1 and earlier, and 8.0.0-M8 and earlier, a security issue has been discovered in the WYSIWYG ediEPSS 0.9%CVE-2024-29006CRITICALApache CloudStack: x-forwarded-for HTTP header parsed by defaultEPSS 0.9%CVE-2024-26016MEDIUMApache Superset: Improper authorization validation on dashboards and charts importEPSS 0.9%CVE-2022-38745HIGHApache OpenOffice: Empty entry in Java class pathEPSS 0.9%CVE-2026-56623HIGHApache MINA SSHD: Path traversal in org.apache.sshd:sshd-git on WindowsEPSS 0.9%CVE-2026-54399HIGHApache HttpComponents Core: Unbounded HTTP Header/Line Length in Default ConfigurationEPSS 0.9%CVE-2025-30474MEDIUMApache Commons VFS: Failing to find an FTP file can reveal the URI's password in an error messageEPSS 0.9%CVE-2026-54428HIGHApache HttpComponents Core: HPackDecoder Unlimited Header List Size Before SETTINGS ACKEPSS 0.9%CVE-2017-5657—Several REST service endpoints of Apache Archiva are not protected against Cross Site Request Forgery (CSRF) attacks. A malicious site openeEPSS 0.9%CVE-2023-50380MEDIUMApache Ambari: authenticated users could perform XXE to read arbitrary files on the serverEPSS 0.9%CVE-2026-42782HIGHApache Syncope: Post-auth RCE via Groovy staticEPSS 0.9%CVE-2026-41284HIGHApache Tomcat: Unbounded read in WebDAV LOCK and PROPFIND handlingEPSS 0.9%CVE-2026-65927HIGHApache Tomcat: RewriteValve [N] restarts at the second rule and may bypass access controlEPSS 0.9%