Vulnerabilities in Apache Software Foundation

2,378 results
Vexday analysis

O portfólio da Apache Software Foundation acumula 1.872 CVEs catalogadas, das quais 215 são de severidade crítica e 83 contam com prova de conceito pública — fatores que ampliam a superfície de risco operacional para equipes de segurança. A taxa de exploração ativa é especialmente preocupante: 28 vulnerabilidades constam no catálogo KEV da CISA, representando uma proporção 3,3 vezes acima da média geral do catálogo, o que indica atenção consistente de agentes maliciosos ao ecossistema Apache. A falha mais comum é CWE-20 (validação inadequada de entrada), padrão estrutural que tende a se manifestar em múltiplos produtos e versões, exigindo revisão ampla e não pontual. Destaque para CVE-2021-40438, a vulnerabilidade de maior risco ativo no momento, com EPSS máximo de 1,0 — probabilidade de exploração na prática praticamente certa —, o que a torna prioridade imediata de remediação para qualquer organização que opere componentes Apache afetados.

CVE-2021-31618—NULL pointer dereference on specially crafted HTTP/2 requestEPSS 51.5%CVE-2018-11763—In Apache HTTP Server 2.4.17 to 2.4.34, by sending continuous, large SETTINGS frames a client can occupy a connection, server thread and CPUEPSS 50.8%CVE-2021-33035—Buffer overflow from a crafted DBF fileEPSS 50.6%CVE-2022-23943—mod_sed: Read/write beyond boundsEPSS 50.4%CVE-2020-17518—Apache Flink directory traversal attack: remote file writing through the REST APIEPSS 50.0%CVE-2026-23918HIGHApache HTTP Server: http2: double free and possible RCE on early resetEPSS 49.7%CVE-2020-13950—mod_proxy_http NULL pointer dereferenceEPSS 49.4%CVE-2016-0736—In Apache HTTP Server versions 2.4.0 to 2.4.23, mod_session_crypto was encrypting its data/cookie using the configured ciphers with possiblyEPSS 49.0%CVE-2023-24998—Apache Commons FileUpload, Apache Tomcat: FileUpload DoS with excessive partsEPSS 48.8%CVE-2023-28709—Apache Tomcat: Fix for CVE-2023-24998 is incompleteEPSS 48.0%CVE-2024-25065CRITICALApache OFBiz: Path traversal allowing authentication bypass.EPSS 47.7%CVE-2018-1323—The IIS/ISAPI specific code in the Apache Tomcat JK ISAPI Connector 1.2.0 to 1.2.42 that normalised the requested path before matching it toEPSS 46.4%CVE-2021-33193—Request splitting via HTTP/2 method injection and mod_proxyEPSS 46.2%CVE-2025-68493HIGHApache Struts, Apache Struts: XXE vulnerability in outdated XWork componentEPSS 45.8%CVE-2022-33980—Apache Commons Configuration insecure interpolation defaultsEPSS 45.6%CVE-2024-52012MEDIUMApache Solr: Configset upload on Windows allows arbitrary path write-accessEPSS 45.0%CVE-2025-30065CRITICALApache Parquet Java: Arbitrary code execution in the parquet-avro module when reading an Avro schema from a Parquet file metadataEPSS 43.6%CVE-2025-61622CRITICALApache Fory, Apache Fory: Python RCE via unguarded pickle fallback serializer in pyforyEPSS 43.5%CVE-2018-1306—The PortletV3AnnotatedDemo Multipart Portlet war file code provided in Apache Pluto version 3.0.0 could allow a remote attacker to obtain seEPSS 43.5%CVE-2024-45387CRITICALApache Traffic Control: SQL Injection in Traffic Ops endpoint PUT deliveryservice_request_commentsEPSS 42.4%