Vulnerabilidades em Apache Software Foundation

2.398 resultados
Análise Vexday

O portfólio da Apache Software Foundation acumula 1.872 CVEs catalogadas, das quais 215 são de severidade crítica e 83 contam com prova de conceito pública — fatores que ampliam a superfície de risco operacional para equipes de segurança. A taxa de exploração ativa é especialmente preocupante: 28 vulnerabilidades constam no catálogo KEV da CISA, representando uma proporção 3,3 vezes acima da média geral do catálogo, o que indica atenção consistente de agentes maliciosos ao ecossistema Apache. A falha mais comum é CWE-20 (validação inadequada de entrada), padrão estrutural que tende a se manifestar em múltiplos produtos e versões, exigindo revisão ampla e não pontual. Destaque para CVE-2021-40438, a vulnerabilidade de maior risco ativo no momento, com EPSS máximo de 1,0 — probabilidade de exploração na prática praticamente certa —, o que a torna prioridade imediata de remediação para qualquer organização que opere componentes Apache afetados.

CVE-2025-53606CRITICALApache Seata (incubating): Deserialization of untrusted Data in Apache Seata ServerEPSS 0.6%CVE-2026-73239MEDIUMApache Allura: Missing permission checks IDOREPSS 0.6%CVE-2026-43646HIGHApache Wicket: crafted URLs can bypass PackageResourceGuardEPSS 0.6%CVE-2024-47249MEDIUMApache NimBLE: Lack of input sanitization leading to out-of-bound reads in multiple advertisement handlerEPSS 0.6%CVE-2026-70469HIGHApache NiFi: Improper Handling of Case Sensitivity for Content-Encoding in HTTP RequestsEPSS 0.6%CVE-2026-60023HIGHApache Answer: Unauthorized disclosure of deleted or pending answer contentEPSS 0.6%CVE-2026-34487HIGHApache Tomcat: Cloud membership for clustering component exposed the Kubernetes bearer tokenEPSS 0.6%CVE-2026-34483HIGHApache Tomcat: Incomplete escaping of JSON access logsEPSS 0.6%CVE-2026-68076MEDIUMApache Airflow: Connections test API: team-scope guard bypass resolves another team's environment ConnectionEPSS 0.6%CVE-2026-75030CRITICALApache Syncope: Incomplete authorization checks for Group members deprovisioningEPSS 0.6%CVE-2026-25903HIGHApache NiFi: Missing Authorization of Restricted Permissions for Component UpdatesEPSS 0.6%CVE-2026-26929MEDIUMApache Airflow: Wildcard DagVersion Listing Bypasses Per‑DAG RBAC and Leaks MetadataEPSS 0.6%CVE-2024-29008MEDIUMApache CloudStack: The extraconfig feature can be abused to load hypervisor resources on a VM instanceEPSS 0.6%CVE-2026-65948HIGHApache Ranger: UnixAuth lacks brute-force protectionEPSS 0.6%CVE-2026-23969MEDIUMApache Superset: Exposure of Sensitive Information via Incomplete ClickHouse Function FilteringEPSS 0.6%CVE-2022-38170—Overly permissive umask for daemonsEPSS 0.6%CVE-2026-66722HIGHApache CloudStack: ProjectRole & ProjectRolePermission authorization issueEPSS 0.6%CVE-2024-41177MEDIUMApache Zeppelin: XSS in the Helium moduleEPSS 0.6%CVE-2026-40010CRITICALApache Wicket: possible session fixation using AuthenticatedWebSessionEPSS 0.6%CVE-2026-31909HIGHApache OFBiz: Unauthenticated Shipment Label Image DisclosureEPSS 0.6%