Vulnerabilities in Apache Software Foundation

1,884 results
Vexday analysis

O portfólio da Apache Software Foundation acumula 1.872 CVEs catalogadas, das quais 215 são de severidade crítica e 83 contam com prova de conceito pública — fatores que ampliam a superfície de risco operacional para equipes de segurança. A taxa de exploração ativa é especialmente preocupante: 28 vulnerabilidades constam no catálogo KEV da CISA, representando uma proporção 3,3 vezes acima da média geral do catálogo, o que indica atenção consistente de agentes maliciosos ao ecossistema Apache. A falha mais comum é CWE-20 (validação inadequada de entrada), padrão estrutural que tende a se manifestar em múltiplos produtos e versões, exigindo revisão ampla e não pontual. Destaque para CVE-2021-40438, a vulnerabilidade de maior risco ativo no momento, com EPSS máximo de 1,0 — probabilidade de exploração na prática praticamente certa —, o que a torna prioridade imediata de remediação para qualquer organização que opere componentes Apache afetados.

CVE-2022-46364CRITICALApache CXF SSRF VulnerabilityEPSS 1.9%CVE-2022-38648PDFTranscoder does not block external resourcesEPSS 1.9%CVE-2021-44791Reflected XSS on certain HTTP endpointsEPSS 1.9%CVE-2021-43083Apache PLC4X 0.9.0 Buffer overflow in PLC4C via crafted server responseEPSS 1.9%CVE-2017-3151Apache Atlas versions 0.6.0-incubating and 0.7.0-incubating were found vulnerable to Stored Cross-Site Scripting in the edit-tag functionaliEPSS 1.9%CVE-2023-46226CRITICALApache IoTDB: Remote Code Execution (RCE) risk via the UDFEPSS 1.9%CVE-2024-54677MEDIUMApache Tomcat: DoS in examples web applicationEPSS 1.9%CVE-2021-44040HTTP request line fuzzing attacksEPSS 1.9%CVE-2025-22828MEDIUMApache CloudStack: Unauthorised access to annotationsEPSS 1.9%CVE-2023-29247Stored XSS on Apache AirflowEPSS 1.9%CVE-2023-26464HIGHApache Log4j 1.x (EOL) allows DoS in Chainsaw and SocketAppenderEPSS 1.9%CVE-2024-46901LOWApache Subversion: mod_dav_svn denial-of-service via control characters in pathsEPSS 1.9%CVE-2018-11786In Apache Karaf prior to 4.2.0 release, if the sshd service in Karaf is left on so an administrator can manage the running instance, any useEPSS 1.9%CVE-2022-25598Apache DolphinScheduler user registration is vulnerable to ReDoS attacksEPSS 1.9%CVE-2025-53506HIGHApache Tomcat: DoS via excessive h2 streams at connection startEPSS 1.9%CVE-2024-27894HIGHApache Pulsar: Pulsar Functions Worker Allows Unauthorized File Access and Unauthorized HTTP/HTTPS ProxyingEPSS 1.9%CVE-2023-25693CRITICALSqoop Apache Airflow Provider Remote Code Execution VulnerabilityEPSS 1.9%CVE-2017-5642During installation of Ambari 2.4.0 through 2.4.2, Ambari Server artifacts are not created with proper ACLs.EPSS 1.9%CVE-2022-33879Incomplete fix and new regex DoS in StandardsExtractingContentHandlerEPSS 1.9%CVE-2021-38161Not validating origin TLS certificateEPSS 1.9%