Exposure of Apache HTTP Server

Web servers
544
exposure score
1,520,448
sites use
6
exploited
20
critical
Vexday analysis

O Apache HTTP Server acumula 169 CVEs catalogadas, com 16 classificadas como críticas e 34 surgidas apenas nos últimos 90 dias, sinalizando um ritmo elevado de descobertas recentes que exige atenção contínua. A taxa de exploração ativa é 6,6 vezes acima da média geral do catálogo CISA KEV, com 5 vulnerabilidades confirmadas em uso por agentes de ameaça — proporção que coloca o servidor entre as tecnologias de maior risco operacional imediato. A CVE mais perigosa atualmente ativa, CVE-2021-40438, apresenta EPSS de 1,0, o valor máximo possível, indicando probabilidade praticamente certa de exploração observada no ambiente real. O tipo de falha mais recorrente é CWE-476 (desreferência de ponteiro nulo), embora o perfil de risco mais crítico esteja nas vulnerabilidades com exploração confirmada, que devem ser priorizadas em qualquer plano de remediação.

CVEs

178 results
CVE-2024-38472HIGHApache HTTP Server on WIndows UNC SSRFEPSS 69.5%CVE-2022-22719mod_lua Use of uninitialized value of in r:parsebodyEPSS 69.1%CVE-2021-26691Apache HTTP Server mod_session response handling heap overflowEPSS 68.3%CVE-2021-26690mod_session NULL pointer dereferenceEPSS 65.3%CVE-2018-1303A specially crafted HTTP request header could have crashed the Apache HTTP Server prior to version 2.4.30 due to an out of bound read while EPSS 64.9%CVE-2021-34798NULL pointer dereference in httpd coreEPSS 64.5%CVE-2021-36160mod_proxy_uwsgi out of bound readEPSS 62.9%CVE-2022-37436MEDIUMApache HTTP Server: mod_proxy prior to 2.4.55 allows a backend to trigger HTTP response splittingEPSS 61.0%CVE-2019-17567mod_proxy_wstunnel tunneling of non Upgraded connectionsEPSS 60.3%CVE-2019-0190A bug exists in the way mod_ssl handled client renegotiations. A remote attacker could send a carefully crafted request that would cause modEPSS 59.1%CVE-2017-7668The HTTP strict parsing changes added in Apache httpd 2.2.32 and 2.4.24 introduced a bug in token list parsing, which allows ap_find_token()EPSS 57.5%CVE-2020-1927In Apache HTTP Server 2.4.0 to 2.4.41, redirects configured with mod_rewrite that were intended to be self-referential might be fooled by enEPSS 56.7%CVE-2020-11993Apache HTTP Server versions 2.4.20 to 2.4.43 When trace/debug was enabled for the HTTP/2 module and on certain traffic edge patterns, logginEPSS 56.4%CVE-2020-35452mod_auth_digest possible stack overflow by one nul byteEPSS 54.8%CVE-2017-9788In Apache httpd before 2.2.34 and 2.4.x before 2.4.27, the value placeholder in [Proxy-]Authorization headers of type 'Digest' was not initiEPSS 53.7%CVE-2019-10097In Apache HTTP Server 2.4.32-2.4.39, when mod_remoteip was configured to use a trusted intermediary proxy server using the "PROXY" protocol,EPSS 52.9%CVE-2021-30641Unexpected URL matching with 'MergeSlashes OFF'EPSS 52.6%CVE-2020-1934In Apache HTTP Server 2.4.0 to 2.4.41, mod_proxy_ftp may use uninitialized memory when proxying to a malicious FTP server.EPSS 52.0%CVE-2021-31618NULL pointer dereference on specially crafted HTTP/2 requestEPSS 51.5%CVE-2022-23943mod_sed: Read/write beyond boundsEPSS 50.4%