Vulnerabilities in Apache Software Foundation

1,877 results
Vexday analysis

O portfólio da Apache Software Foundation acumula 1.872 CVEs catalogadas, das quais 215 são de severidade crítica e 83 contam com prova de conceito pública — fatores que ampliam a superfície de risco operacional para equipes de segurança. A taxa de exploração ativa é especialmente preocupante: 28 vulnerabilidades constam no catálogo KEV da CISA, representando uma proporção 3,3 vezes acima da média geral do catálogo, o que indica atenção consistente de agentes maliciosos ao ecossistema Apache. A falha mais comum é CWE-20 (validação inadequada de entrada), padrão estrutural que tende a se manifestar em múltiplos produtos e versões, exigindo revisão ampla e não pontual. Destaque para CVE-2021-40438, a vulnerabilidade de maior risco ativo no momento, com EPSS máximo de 1,0 — probabilidade de exploração na prática praticamente certa —, o que a torna prioridade imediata de remediação para qualquer organização que opere componentes Apache afetados.

CVE-2023-44313HIGHApache ServiceComb Service-Center: attacker can perform SSRF through the frontend APIEPSS 3.5%CVE-2021-31811A carefully crafted PDF file can trigger an OutOfMemory-Exception while loading a tiny fileEPSS 3.4%CVE-2021-40439Billion LaughsEPSS 3.4%CVE-2018-1290In Apache Fineract versions 1.0.0, 0.6.0-incubating, 0.5.0-incubating, 0.4.0-incubating, Using a single quotation escape with two continuousEPSS 3.4%CVE-2018-1287In Apache JMeter 2.X and 3.X, when using Distributed Test only (RMI based), jmeter server binds RMI Registry to wildcard host. This could alEPSS 3.4%CVE-2020-17514disabled hostname verificiationEPSS 3.4%CVE-2022-28330read beyond bounds in mod_isapiEPSS 3.4%CVE-2021-30129DoS/OOM leak vulnerability in Apache Mina SSHD ServerEPSS 3.4%CVE-2025-48989HIGHApache Tomcat: h2 DoS - Made You ResetEPSS 3.4%CVE-2016-8738In Apache Struts 2.5 through 2.5.5, if an application allows entering a URL in a form field and the built-in URLValidator is used, it is posEPSS 3.3%CVE-2021-27906A carefully crafted PDF file can trigger an OutOfMemory-Exception while loading the fileEPSS 3.3%CVE-2021-28131Impala logs contain secretsEPSS 3.3%CVE-2021-40369XSS vulnerability on Denounce pluginEPSS 3.3%CVE-2023-50291HIGHApache Solr: System Property redaction logic inconsistency can lead to leaked passwordsEPSS 3.3%CVE-2024-38346CRITICALApache CloudStack: Unauthenticated cluster service port leads to remote executionEPSS 3.3%CVE-2018-1296In Apache Hadoop 3.0.0-alpha1 to 3.0.0, 2.9.0, 2.8.0 to 2.8.3, and 2.5.0 to 2.7.5, HDFS exposes extended attribute key/value pairs during liEPSS 3.3%CVE-2021-33580regex injection leading to DoSEPSS 3.3%CVE-2017-15714The BIRT plugin in Apache OFBiz 16.11.01 to 16.11.03 does not escape user input property passed. This allows for code injection by passing tEPSS 3.3%CVE-2017-5635In Apache NiFi before 0.7.2 and 1.x before 1.1.2 in a cluster environment, if an anonymous user request is replicated to another node, the oEPSS 3.3%CVE-2024-22399CRITICALApache Seata: Remote Code Execution vulnerability via Hessian Deserialization in Apache Seata ServerEPSS 3.3%