Vulnerabilities in Apache Software Foundation

1,877 results
Vexday analysis

O portfólio da Apache Software Foundation acumula 1.872 CVEs catalogadas, das quais 215 são de severidade crítica e 83 contam com prova de conceito pública — fatores que ampliam a superfície de risco operacional para equipes de segurança. A taxa de exploração ativa é especialmente preocupante: 28 vulnerabilidades constam no catálogo KEV da CISA, representando uma proporção 3,3 vezes acima da média geral do catálogo, o que indica atenção consistente de agentes maliciosos ao ecossistema Apache. A falha mais comum é CWE-20 (validação inadequada de entrada), padrão estrutural que tende a se manifestar em múltiplos produtos e versões, exigindo revisão ampla e não pontual. Destaque para CVE-2021-40438, a vulnerabilidade de maior risco ativo no momento, com EPSS máximo de 1,0 — probabilidade de exploração na prática praticamente certa —, o que a torna prioridade imediata de remediação para qualquer organização que opere componentes Apache afetados.

CVE-2018-11758This affects Apache Cayenne 4.1.M1, 3.2.M1, 4.0.M2 to 4.0.M5, 4.0.B1, 4.0.B2, 4.0.RC1, 3.1, 3.1.1, 3.1.2. CayenneModeler is a desktop GUI toEPSS 3.0%CVE-2018-17194When a client request to a cluster node was replicated to other nodes in the cluster for verification, the Content-Length was forwarded. On EPSS 3.0%CVE-2017-7688Apache OpenMeetings 1.0.0 updates user password in insecure manner.EPSS 3.0%CVE-2017-7686Apache Ignite 1.0.0-RC3 to 2.0 uses an update notifier component to update the users about new project releases that include additional funcEPSS 3.0%CVE-2019-12397Policy import functionality in Apache Ranger 0.7.0 to 1.2.0 is vulnerable to a cross-site scripting issue. Upgrade to 2.0.0 or later versionEPSS 3.0%CVE-2025-54988HIGHApache Tika PDF parser module: XXE vulnerability in PDFParser's handling of XFAEPSS 3.0%CVE-2017-5661In Apache FOP before 2.2, files lying on the filesystem of the server which uses FOP can be revealed to arbitrary users who send maliciouslyEPSS 3.0%CVE-2021-43045Possible DOS vulnerabilities in C# Avro SDKEPSS 3.0%CVE-2017-5659Apache Traffic Server before 6.2.1 generates a coredump when there is a mismatch between content length and chunked encoding.EPSS 3.0%CVE-2023-28935HIGHApache UIMA DUCC: DUCC (EOL) allows RCEEPSS 3.0%CVE-2017-15717A flaw in the way URLs are escaped and encoded in the org.apache.sling.xss.impl.XSSAPIImpl#getValidHref and org.apache.sling.xss.impl.XSSFilEPSS 2.9%CVE-2017-12632A malicious host header in an incoming HTTP request could cause NiFi to load resources from an external server. The fix to sanitize host heaEPSS 2.9%CVE-2021-31522Apache Kylin unsafe class loadingEPSS 2.9%CVE-2021-34797Apache Geode project log file redaction of sensitive information vulnerabilityEPSS 2.9%CVE-2017-12608A vulnerability in Apache OpenOffice Writer DOC file parser before 4.1.4, and specifically in ImportOldFormatStyles, allows attackers to craEPSS 2.9%CVE-2016-5396Apache Traffic Server 6.0.0 to 6.2.0 are affected by an HPACK Bomb Attack.EPSS 2.9%CVE-2021-33192Display information UI XSSEPSS 2.9%CVE-2024-24795MEDIUMApache HTTP Server: HTTP Response Splitting in multiple modulesEPSS 2.9%CVE-2021-37404Heap buffer overflow in libhdfs native libraryEPSS 2.9%CVE-2020-1936Stored XSS in Apache AmbariEPSS 2.9%