Vulnerabilities in Apache Software Foundation

2,378 results
Vexday analysis

O portfólio da Apache Software Foundation acumula 1.872 CVEs catalogadas, das quais 215 são de severidade crítica e 83 contam com prova de conceito pública — fatores que ampliam a superfície de risco operacional para equipes de segurança. A taxa de exploração ativa é especialmente preocupante: 28 vulnerabilidades constam no catálogo KEV da CISA, representando uma proporção 3,3 vezes acima da média geral do catálogo, o que indica atenção consistente de agentes maliciosos ao ecossistema Apache. A falha mais comum é CWE-20 (validação inadequada de entrada), padrão estrutural que tende a se manifestar em múltiplos produtos e versões, exigindo revisão ampla e não pontual. Destaque para CVE-2021-40438, a vulnerabilidade de maior risco ativo no momento, com EPSS máximo de 1,0 — probabilidade de exploração na prática praticamente certa —, o que a torna prioridade imediata de remediação para qualquer organização que opere componentes Apache afetados.

CVE-2024-38473HIGHApache HTTP Server proxy encoding problemEPSS 25.9%CVE-2018-8033—In Apache OFBiz 16.11.01 to 16.11.04, the OFBiz HTTP engine (org.apache.ofbiz.service.engine.HttpEngine.java) handles requests for HTTP servEPSS 25.7%CVE-2025-60021CRITICALApache bRPC: Remote command injection vulnerability in heap builtin serviceEPSS 25.7%CVE-2021-41524—null pointer dereference in h2 fuzzingEPSS 25.2%CVE-2020-17527—Apache Tomcat: Request header mix-up between HTTP/2 streamsEPSS 24.6%CVE-2020-11989—Apache Shiro before 1.5.3, when using Apache Shiro with Spring dynamic controllers, a specially crafted request may cause an authentication EPSS 24.4%CVE-2024-37389MEDIUMApache NiFi: Improper Neutralization of Input in Parameter Context DescriptionEPSS 24.0%CVE-2024-52046CRITICALApache MINA: MINA applications using unbounded deserialization may allow RCEEPSS 23.9%CVE-2020-17526—Incorrect Session Validation in Apache Airflow Webserver versions prior to 1.10.14 with default config allows a malicious airflow user on siEPSS 23.3%CVE-2025-57738HIGHApache Syncope: Remote Code Execution by delegated administratorsEPSS 23.2%CVE-2024-24549HIGHApache Tomcat: HTTP/2 header handling DoSEPSS 23.1%CVE-2021-24122—Apache Tomcat information disclosureEPSS 22.9%CVE-2017-15709—When using the OpenWire protocol in ActiveMQ versions 5.14.0 to 5.15.2 it was found that certain system details (such as the OS and kernel vEPSS 22.8%CVE-2021-26919—Apache Druid Authenticated users can execute arbitrary code from malicious MySQL database systems.EPSS 22.8%CVE-2020-13936—Velocity Sandbox BypassEPSS 22.7%CVE-2018-8014—The defaults settings for the CORS filter provided in Apache Tomcat 9.0.0.M1 to 9.0.8, 8.5.0 to 8.5.31, 8.0.0.RC1 to 8.0.52, 7.0.41 to 7.0.8EPSS 21.3%CVE-2018-8034HIGHThe host name verification when using TLS with the WebSocket client was missing. It is now enabled by default. Versions Affected: Apache TomEPSS 21.3%CVE-2021-25641—Dubbo Zookeeper does not check serialization idEPSS 21.2%CVE-2022-26377—mod_proxy_ajp: Possible request smugglingEPSS 21.1%CVE-2016-2161—In Apache HTTP Server versions 2.4.0 to 2.4.23, malicious input to mod_auth_digest can cause the server to crash, and each instance continueEPSS 21.0%