Vulnerabilidades em Apache Software Foundation

2.367 resultados
Análise Vexday

O portfólio da Apache Software Foundation acumula 1.872 CVEs catalogadas, das quais 215 são de severidade crítica e 83 contam com prova de conceito pública — fatores que ampliam a superfície de risco operacional para equipes de segurança. A taxa de exploração ativa é especialmente preocupante: 28 vulnerabilidades constam no catálogo KEV da CISA, representando uma proporção 3,3 vezes acima da média geral do catálogo, o que indica atenção consistente de agentes maliciosos ao ecossistema Apache. A falha mais comum é CWE-20 (validação inadequada de entrada), padrão estrutural que tende a se manifestar em múltiplos produtos e versões, exigindo revisão ampla e não pontual. Destaque para CVE-2021-40438, a vulnerabilidade de maior risco ativo no momento, com EPSS máximo de 1,0 — probabilidade de exploração na prática praticamente certa —, o que a torna prioridade imediata de remediação para qualquer organização que opere componentes Apache afetados.

CVE-2021-28359Apache Airflow Reflected XSS via Origin Query Argument in URLEPSS 14.4%CVE-2024-21733MEDIUMApache Tomcat: Leaking of unrelated request bodies in default error pageEPSS 14.3%CVE-2026-43825HIGHApache OpenNLP :: Core :: ML :: LibSVM: Unsafe Java Deserialization in SvmDoccatModelEPSS 13.9%CVE-2016-8743Apache HTTP Server, in all releases prior to 2.2.32 and 2.4.25, was liberal in the whitespace accepted from requests and sent in response liEPSS 13.3%CVE-2017-5648While investigating bug 60718, it was noticed that some calls to application listeners in Apache Tomcat 9.0.0.M1 to 9.0.0.M17, 8.5.0 to 8.5.EPSS 13.2%CVE-2021-36090Apache Commons Compress 1.0 to 1.20 denial of service vulnerabilityEPSS 12.9%CVE-2021-43557Path traversal in request_uri variableEPSS 12.9%CVE-2018-1302When an HTTP/2 stream was destroyed after being handled, the Apache HTTP Server prior to version 2.4.30 could have written a NULL pointer poEPSS 12.9%CVE-2021-35516Apache Commons Compress 1.6 to 1.20 denial of service vulnerabilityEPSS 12.4%CVE-2020-13938Improper Handling of Insufficient PrivilegesEPSS 11.9%CVE-2021-42340DoS via memory leak with WebSocket connectionsEPSS 11.8%CVE-2018-8007Apache CouchDB administrative users can configure the database server via HTTP(S). Due to insufficient validation of administrator-supplied EPSS 11.6%CVE-2022-23437Infinite loop within Apache XercesJ xml parserEPSS 11.6%CVE-2021-35515Apache Commons Compress 1.6 to 1.20 denial of service vulnerabilityEPSS 11.6%CVE-2021-26117ActiveMQ: LDAP-Authentication does not verify passwords on servers with anonymous bindEPSS 11.3%CVE-2018-8037If an async request was completed by the application at the same time as the container triggered the async timeout, a race condition existedEPSS 11.3%CVE-2017-5653JAX-RS XML Security streaming clients in Apache CXF before 3.1.11 and 3.0.13 do not validate that the service response was signed or encryptEPSS 11.2%CVE-2023-22884CRITICALApache Airflow, Apache Airflow MySQL Provider: Arbitrary file read via MySQL provider in Apache AirflowEPSS 11.1%CVE-2018-11780A potential Remote Code Execution bug exists with the PDFInfo plugin in Apache SpamAssassin before 3.4.2.EPSS 10.8%CVE-2025-64408MEDIUMApache Causeway: Java deserialization vulnerability to authenticated attackersEPSS 10.8%