Vulnerabilidades em Apache Software Foundation

2.378 resultados
Análise Vexday

O portfólio da Apache Software Foundation acumula 1.872 CVEs catalogadas, das quais 215 são de severidade crítica e 83 contam com prova de conceito pública — fatores que ampliam a superfície de risco operacional para equipes de segurança. A taxa de exploração ativa é especialmente preocupante: 28 vulnerabilidades constam no catálogo KEV da CISA, representando uma proporção 3,3 vezes acima da média geral do catálogo, o que indica atenção consistente de agentes maliciosos ao ecossistema Apache. A falha mais comum é CWE-20 (validação inadequada de entrada), padrão estrutural que tende a se manifestar em múltiplos produtos e versões, exigindo revisão ampla e não pontual. Destaque para CVE-2021-40438, a vulnerabilidade de maior risco ativo no momento, com EPSS máximo de 1,0 — probabilidade de exploração na prática praticamente certa —, o que a torna prioridade imediata de remediação para qualquer organização que opere componentes Apache afetados.

CVE-2026-24343HIGHApache HertzBeat: Uncontrolled Resource Consumption via Crafted XPath ExpressionsEPSS 0.7%CVE-2023-41916MEDIUMApache Linkis DataSource: DatasourceManager module has a JDBC parameter judgment logic vulnerability that allows for arbitrary file readingEPSS 0.7%CVE-2024-34457MEDIUMApache StreamPark IDOR VulnerabilityEPSS 0.7%CVE-2024-22281HIGHApache Helix Front (UI): Helix front hard-coded secret in the express-sessionEPSS 0.7%CVE-2026-25077HIGHApache CloudStack: Unauthenticated Command Injection in Direct Download TemplatesEPSS 0.7%CVE-2026-24656LOWApache Karaf: Decanter log-socket collector has deserialization vulnerabilityEPSS 0.7%CVE-2026-42811CRITICALApache Polaris: could broaden vended GCS credentials through unescaped identifier content in access-boundary CEL conditionsEPSS 0.7%CVE-2026-50112HIGHApache CloudStack: RCE and SSRF in direct download, metalink and NFS templatesEPSS 0.7%CVE-2023-48396CRITICALApache SeaTunnel Web: Authentication bypassEPSS 0.7%CVE-2025-26795HIGHApache IoTDB JDBC driver: Exposure of Sensitive Information in IoTDB JDBC driverEPSS 0.7%CVE-2024-47248MEDIUMApache NimBLE: Buffer overflow in NimBLE MESH Bluetooth stackEPSS 0.7%CVE-2026-49328MEDIUMApache Fesod (Incubating): Improper validation of user-supplied URLs leading to SSRFEPSS 0.7%CVE-2024-47252HIGHApache HTTP Server: mod_ssl error log variable escapingEPSS 0.7%CVE-2026-47897HIGHApache Lucene.Net: Arbitrary file write from malicious server to Lucene.Net.Replicator clientEPSS 0.7%CVE-2025-26864HIGHApache IoTDB: Exposure of Sensitive Information in IoTDB OpenID AuthenticationEPSS 0.7%CVE-2025-48912HIGHApache Superset: Improper authorization bypass on row level security via SQL InjectionEPSS 0.7%CVE-2026-41869CRITICALApache Nutch: Unauthenticated forced shutdown and job interruption in Nutch Server (Nutch REST API)EPSS 0.7%CVE-2025-30677MEDIUMApache Pulsar IO Kafka Connector, Apache Pulsar IO Kafka Connect Adaptor: Sensitive information logged in Pulsar's Apache Kafka ConnectorsEPSS 0.7%CVE-2026-41043MEDIUMApache ActiveMQ, Apache ActiveMQ Web: ActiveMQ Web Console - XSS vulnerability when browsing queuesEPSS 0.7%CVE-2026-32228HIGHApache Airflow: Users with asset materialization permisssions could trigger Dags they had no access toEPSS 0.7%