Vulnerabilidades em Apache Software Foundation

2.378 resultados
Análise Vexday

O portfólio da Apache Software Foundation acumula 1.872 CVEs catalogadas, das quais 215 são de severidade crítica e 83 contam com prova de conceito pública — fatores que ampliam a superfície de risco operacional para equipes de segurança. A taxa de exploração ativa é especialmente preocupante: 28 vulnerabilidades constam no catálogo KEV da CISA, representando uma proporção 3,3 vezes acima da média geral do catálogo, o que indica atenção consistente de agentes maliciosos ao ecossistema Apache. A falha mais comum é CWE-20 (validação inadequada de entrada), padrão estrutural que tende a se manifestar em múltiplos produtos e versões, exigindo revisão ampla e não pontual. Destaque para CVE-2021-40438, a vulnerabilidade de maior risco ativo no momento, com EPSS máximo de 1,0 — probabilidade de exploração na prática praticamente certa —, o que a torna prioridade imediata de remediação para qualquer organização que opere componentes Apache afetados.

CVE-2025-68280MEDIUMApache SIS: XML External Entity (XXE) vulnerabilityEPSS 0.7%CVE-2025-27528CRITICALApache InLong: JDBC Vulnerability for Invisible Character Bypass Leading to Arbitrary File ReadEPSS 0.7%CVE-2022-31764HIGHApache ShardingSphere ElasticJob-UI allows RCE via event trace data source JDBCEPSS 0.7%CVE-2026-28564CRITICALApache IoTDB: REST Basic Authentication Accepts Stale Cached CredentialsEPSS 0.7%CVE-2026-68079CRITICALApache CXF: DefaultEncryptingCodeDataProvider allows unlimited authorization code replayEPSS 0.7%CVE-2026-63041MEDIUMApache APISIX: attach-consumer-label does not strip client-supplied consumer-label headersEPSS 0.7%CVE-2026-49086MEDIUMApache Camel Dapr: Pub/Sub consumer copied the inbound CloudEvent's pub/sub-name and topic into producer-direction routing headers, allowing an actor who can publish to the subscribed topic to influence internal behaviourEPSS 0.7%CVE-2024-27439MEDIUMApache Wicket: Possible bypass of CSRF protectionEPSS 0.7%CVE-2026-42253MEDIUMApache ActiveMQ, Apache ActiveMQ Web: HTTP Response Header Injection via JMS Message PropertiesEPSS 0.7%CVE-2026-32773MEDIUMApache Spark: XSS Vulnerability in Spark Web 3.5.4EPSS 0.7%CVE-2026-52760MEDIUMApache ActiveMQ, Apache ActiveMQ Web Console: Stored XSS via Unescaped values in ActiveMQ Web ConsoleEPSS 0.7%CVE-2022-33683MEDIUMDisabled Certificate Validation makes Broker, Proxy Admin Clients vulnerable to MITM attack EPSS 0.7%CVE-2026-39998MEDIUMApache APISIX: Identity Injection via forward-auth Plugin Missing Header CleanupEPSS 0.7%CVE-2026-59230MEDIUMApache Camel: Camel-Mail: the MimeMultipart data format copied MIME headers onto the Camel message without a header filter strategy when unmarshalling with headersInline enabledEPSS 0.7%CVE-2026-49097MEDIUMApache Camel: Camel-IRC: The irc.sendTo (and other irc.*) Exchange header constants used non-Camel-prefixed names that bypass the HTTP header filter, allowing an HTTP client to redirect outgoing IRC messages to arbitrary channels or usersEPSS 0.7%CVE-2026-33227MEDIUMApache ActiveMQ Client, Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ Web, Apache ActiveMQ: Improper Limitation of a Pathname to a Restricted Classpath DirectoryEPSS 0.7%CVE-2026-63046HIGHApache InLong: Agent Installer — Command Injection to RCE via Default CredentialsEPSS 0.7%CVE-2025-30675MEDIUMApache CloudStack: Unauthorised template/ISO list access to the domain/resource adminsEPSS 0.7%CVE-2025-58136HIGHApache Traffic Server: A simple legitimate POST request causes a crashEPSS 0.7%CVE-2026-28563MEDIUMApache Airflow: DAG authorization bypassEPSS 0.7%