Vulnerabilidades em Apache Software Foundation

2.378 resultados
Análise Vexday

O portfólio da Apache Software Foundation acumula 1.872 CVEs catalogadas, das quais 215 são de severidade crítica e 83 contam com prova de conceito pública — fatores que ampliam a superfície de risco operacional para equipes de segurança. A taxa de exploração ativa é especialmente preocupante: 28 vulnerabilidades constam no catálogo KEV da CISA, representando uma proporção 3,3 vezes acima da média geral do catálogo, o que indica atenção consistente de agentes maliciosos ao ecossistema Apache. A falha mais comum é CWE-20 (validação inadequada de entrada), padrão estrutural que tende a se manifestar em múltiplos produtos e versões, exigindo revisão ampla e não pontual. Destaque para CVE-2021-40438, a vulnerabilidade de maior risco ativo no momento, com EPSS máximo de 1,0 — probabilidade de exploração na prática praticamente certa —, o que a torna prioridade imediata de remediação para qualquer organização que opere componentes Apache afetados.

CVE-2024-53949HIGHApache Superset: Lower privilege users are able to create Role when FAB_ADD_SECURITY_API is enabledEPSS 0.7%CVE-2026-46586HIGHApache OFBiz: Improper Validation in traverseContent Service Enables Authenticated Groovy Code ExecutionEPSS 0.7%CVE-2018-17195—The template upload API endpoint accepted requests from different domain when sent in conjunction with ARP spoofing + man in the middle (MiTEPSS 0.7%CVE-2026-61899HIGHApache Tapestry: Possible classpath file download through URL manipulationEPSS 0.7%CVE-2022-33682MEDIUMDisabled Hostname Verification makes Brokers, Proxies vulnerable to MITM attackEPSS 0.7%CVE-2026-30911HIGHApache Airflow: Execution API HITL Endpoints Missing Per-Task AuthorizationEPSS 0.7%CVE-2026-61466CRITICALApache CXF: OAuth2 Dynamic Client Registration Scope Self-EscalationEPSS 0.7%CVE-2026-42535CRITICALApache HTTP Server: mod_dav_fs protected directory accessEPSS 0.7%CVE-2024-41178HIGHApache Arrow Rust Object Store: AWS WebIdentityToken exposure in log filesEPSS 0.7%CVE-2024-38503LOWApache Syncope: HTML tags can be injected into Console or Enduser text fieldsEPSS 0.7%CVE-2024-28148MEDIUMApache Superset: Incorrect datasource authorization on explore REST API EPSS 0.7%CVE-2026-57822MEDIUMApache Artemis, Apache ActiveMQ Artemis: Message-based management parameter deserialization may lead to denial of serviceEPSS 0.7%CVE-2023-49250HIGHApache DolphinScheduler: Insecure TLS TrustManager used in HttpUtilEPSS 0.7%CVE-2026-58186HIGHApache Traffic Server: webp_transform plugin decodes unsafely and mislabels degraded responsesEPSS 0.7%CVE-2026-49488MEDIUMApache OpenMeetings: Arbitrary File ReadEPSS 0.7%CVE-2026-50629MEDIUMApache CXF: OAuth2: Log Injection via Unsanitized Client IdentifierEPSS 0.7%CVE-2026-40542HIGHApache HttpClient: SCRAM-SHA-256 mutual authentication bypass may cause the client to accept authentication without proper mutual authentication verificationEPSS 0.7%CVE-2024-45477MEDIUMApache NiFi: Improper Neutralization of Input in Parameter DescriptionEPSS 0.7%CVE-2024-36448HIGHApache IoTDB Workbench: SSRF Vulnerability (EOL)EPSS 0.7%CVE-2026-26032MEDIUMApache Ivy: PackagerResolver path traversal vulnerabilityEPSS 0.7%