Vulnerabilidades em Apache Software Foundation

2.388 resultados
Análise Vexday

O portfólio da Apache Software Foundation acumula 1.872 CVEs catalogadas, das quais 215 são de severidade crítica e 83 contam com prova de conceito pública — fatores que ampliam a superfície de risco operacional para equipes de segurança. A taxa de exploração ativa é especialmente preocupante: 28 vulnerabilidades constam no catálogo KEV da CISA, representando uma proporção 3,3 vezes acima da média geral do catálogo, o que indica atenção consistente de agentes maliciosos ao ecossistema Apache. A falha mais comum é CWE-20 (validação inadequada de entrada), padrão estrutural que tende a se manifestar em múltiplos produtos e versões, exigindo revisão ampla e não pontual. Destaque para CVE-2021-40438, a vulnerabilidade de maior risco ativo no momento, com EPSS máximo de 1,0 — probabilidade de exploração na prática praticamente certa —, o que a torna prioridade imediata de remediação para qualquer organização que opere componentes Apache afetados.

CVE-2026-56287HIGHApache Fineract: Boolean SQL Injection in Client Search API (orderBy parameter) leading to Local File DisclosureEPSS 0.7%CVE-2026-43866HIGHApache Camel, Apache Camel: Camel JMS - CVE-2026-40860 fix bypass via DefaultExchangeHolderEPSS 0.7%CVE-2026-24072HIGHApache HTTP Server: mod_rewrite elevation of privileges via ap_exprEPSS 0.7%CVE-2026-65182CRITICALApache Tomcat: Bypass longest prefix security constraintEPSS 0.7%CVE-2026-66276MEDIUMApache Qpid Proton-J: Unbounded disposition range handling can lead to denial of serviceEPSS 0.7%CVE-2024-56736MEDIUMApache HertzBeat: Server-Side Request Forgery (SSRF) in Api Config OssEPSS 0.7%CVE-2026-67591MEDIUMApache Qpid ProtonJ2: Incoming session flow control window can be exceededEPSS 0.7%CVE-2026-33582MEDIUMApache Answer: Uploading specially crafted TIFF files causes an Out-of-Memory errorEPSS 0.7%CVE-2026-66277MEDIUMApache Qpid Proton-J: Unable to govern the maximum number of transfer frames per incoming deliveryEPSS 0.7%CVE-2025-26865LOWApache OFBiz: Server-Side Template Injection affecting the ecommerce plugin leading to possible RCEEPSS 0.7%CVE-2026-67553MEDIUMApache Qpid Proton Dotnet: Incoming session flow control window can be exceededEPSS 0.7%CVE-2026-67555MEDIUMApache Qpid Proton Dotnet: Unable to govern the maximum number of transfer frames per incoming deliveryEPSS 0.7%CVE-2026-68077MEDIUMApache Qpid Broker-J: Unbounded disposition range handling can lead to denial of serviceEPSS 0.7%CVE-2026-67554MEDIUMApache Qpid Proton Dotnet: Unbounded disposition range handling can lead to denial of serviceEPSS 0.7%CVE-2026-75880MEDIUMApache Artemis, Apache ActiveMQ Artemis: Message selector wildcard handling could lead to denial of serviceEPSS 0.7%CVE-2026-23985MEDIUMApache Superset: Regular Expression Denial of Service (ReDoS) in SQL ParserEPSS 0.7%CVE-2026-66275MEDIUMApache Qpid Proton-J: Incoming session flow control window can be exceededEPSS 0.7%CVE-2026-68080MEDIUMApache Qpid Broker-J: Unbounded echo flow responses can lead to denial of serviceEPSS 0.7%CVE-2026-68075MEDIUMApache Qpid Broker-J: Incoming session flow control window can be exceededEPSS 0.7%CVE-2026-68078MEDIUMApache Qpid Broker-J: Unable to govern the maximum number of transfer frames per incoming deliveryEPSS 0.7%