Vulnerabilidades em Apache Software Foundation

2.378 resultados
Análise Vexday

O portfólio da Apache Software Foundation acumula 1.872 CVEs catalogadas, das quais 215 são de severidade crítica e 83 contam com prova de conceito pública — fatores que ampliam a superfície de risco operacional para equipes de segurança. A taxa de exploração ativa é especialmente preocupante: 28 vulnerabilidades constam no catálogo KEV da CISA, representando uma proporção 3,3 vezes acima da média geral do catálogo, o que indica atenção consistente de agentes maliciosos ao ecossistema Apache. A falha mais comum é CWE-20 (validação inadequada de entrada), padrão estrutural que tende a se manifestar em múltiplos produtos e versões, exigindo revisão ampla e não pontual. Destaque para CVE-2021-40438, a vulnerabilidade de maior risco ativo no momento, com EPSS máximo de 1,0 — probabilidade de exploração na prática praticamente certa —, o que a torna prioridade imediata de remediação para qualquer organização que opere componentes Apache afetados.

CVE-2017-12628—The JMX server embedded in Apache James, also used by the command line client is exposed to a java de-serialization issue, and thus can be uEPSS 0.8%CVE-2026-40961HIGHApache Airflow: Open Redirect Bypass VulnerabilityEPSS 0.8%CVE-2026-91863HIGHApache Neethi: Uncontrolled recursion while parsing crafted WS-Policy documents allows denial of serviceEPSS 0.8%CVE-2026-40861MEDIUMApache Airflow: Arbitrary File Read via Log Symlink following in FileTaskHandlerEPSS 0.8%CVE-2026-44616MEDIUMApache Zeppelin: LDAP injection in ActiveDirectoryGroupRealm filter constructionEPSS 0.8%CVE-2026-28779HIGHApache Airflow: Path of session token in cookie does not consider base_url - session hijacking via co-hosted applicationsEPSS 0.8%CVE-2026-30912HIGHApache Airflow: Exposing stack trace in case of constraint errorEPSS 0.8%CVE-2023-34395HIGHApache Airflow ODBC Provider: Remote code execution vulnerabilityEPSS 0.8%CVE-2026-46745MEDIUMApache Airflow FAB provider: LDAP Filter Injection in FAB Auth Manager _search_ldap reachable via /auth/tokenEPSS 0.8%CVE-2026-49268HIGHApache Shiro: LDAP DN Injection in DefaultLdapRealmEPSS 0.8%CVE-2023-48362CRITICALApache Drill: XXE Vulnerability in XML Format ReaderEPSS 0.8%CVE-2026-24098MEDIUMApache Airflow: Assigning single DAG permission leaked all DAGs Import ErrorsEPSS 0.8%CVE-2024-25090MEDIUMApache Roller: Insufficient input validation for some user profile and bookmark fields when Roller in untested-users modeEPSS 0.8%CVE-2026-41409CRITICALApache MINA: CWE-502 Deserialization of Untrusted DataEPSS 0.8%CVE-2026-63071CRITICALApache Syncope: RCE via Groovy Sandbox bypassEPSS 0.8%CVE-2026-42778CRITICALApache MINA: CWE-502 Deserialization of Untrusted Data (take 2)EPSS 0.8%CVE-2017-5646—For versions of Apache Knox from 0.2.0 to 0.11.0 - an authenticated user may use a specially crafted URL to impersonate another user while aEPSS 0.8%CVE-2025-26413HIGHApache Kvrocks: The server was crashed by the negative offsetEPSS 0.8%CVE-2024-36471HIGHApache Allura: sensitive information exposure via DNS rebindingEPSS 0.8%CVE-2025-46548MEDIUMApache Pekko Management, Apache Pekko Management, Apache Pekko Management, Akka Management, Akka Management, Akka Management: management API basic authentication is not effectiveEPSS 0.7%