Vulnerabilidades em Apache Software Foundation

2.370 resultados
Análise Vexday

O portfólio da Apache Software Foundation acumula 1.872 CVEs catalogadas, das quais 215 são de severidade crítica e 83 contam com prova de conceito pública — fatores que ampliam a superfície de risco operacional para equipes de segurança. A taxa de exploração ativa é especialmente preocupante: 28 vulnerabilidades constam no catálogo KEV da CISA, representando uma proporção 3,3 vezes acima da média geral do catálogo, o que indica atenção consistente de agentes maliciosos ao ecossistema Apache. A falha mais comum é CWE-20 (validação inadequada de entrada), padrão estrutural que tende a se manifestar em múltiplos produtos e versões, exigindo revisão ampla e não pontual. Destaque para CVE-2021-40438, a vulnerabilidade de maior risco ativo no momento, com EPSS máximo de 1,0 — probabilidade de exploração na prática praticamente certa —, o que a torna prioridade imediata de remediação para qualquer organização que opere componentes Apache afetados.

CVE-2017-9789When under stress, closing many connections, the HTTP/2 handling code in Apache httpd 2.4.26 would sometimes access memory after it has beenEPSS 9.6%CVE-2018-1311The Apache Xerces-C 3.0.0 to 3.2.3 XML parser contains a use-after-free error triggered during the scanning of external DTDs. This flaw has EPSS 9.5%CVE-2021-26920Apache Druid: The HTTP inputSource allows authenticated users to read data from other sources than intendedEPSS 9.5%CVE-2021-25329Incomplete fix for CVE-2020-9484EPSS 9.5%CVE-2022-24070Apache Subversion mod_dav_svn is vulnerable to memory corruptionEPSS 9.5%CVE-2024-56337CRITICALApache Tomcat: RCE due to TOCTOU issue in JSP compilation - CVE-2024-50379 mitigation was incompleteEPSS 9.0%CVE-2018-8026This vulnerability in Apache Solr 6.0.0 to 6.6.4 and 7.0.0 to 7.3.1 relates to an XML external entity expansion (XXE) in Solr config files (EPSS 9.0%CVE-2017-15691In Apache uimaj prior to 2.10.2, Apache uimaj 3.0.0-xxx prior to 3.0.0-beta, Apache uima-as prior to 2.10.2, Apache uimaFIT prior to 2.4.0, EPSS 9.0%CVE-2026-29146HIGHApache Tomcat: EncryptInterceptor vulnerable to padding oracle attack by defaultEPSS 8.8%CVE-2018-17190In all versions of Apache Spark, its standalone resource manager accepts code to execute on a 'master' host, that then runs that code on 'woEPSS 8.8%CVE-2017-9793The REST Plugin in Apache Struts 2.1.x, 2.3.7 through 2.3.33 and 2.5 through 2.5.12 is using an outdated XStream library which is vulnerableEPSS 8.8%CVE-2019-0197A vulnerability was found in Apache HTTP Server 2.4.34 to 2.4.38. When HTTP/2 was enabled for a http: host or H2Upgrade was enabled for h2 oEPSS 8.7%CVE-2021-26291block repositories using http by defaultEPSS 8.7%CVE-2025-27533MEDIUMApache ActiveMQ: Unchecked buffer length can cause excessive memory allocationEPSS 8.7%CVE-2018-1327The Apache Struts REST Plugin is using XStream library which is vulnerable and allow perform a DoS attack when using a malicious request witEPSS 8.6%CVE-2018-11761In Apache Tika 0.1 to 1.18, the XML parsers were not configured to limit entity expansion. They were therefore vulnerable to an entity expanEPSS 8.6%CVE-2018-8039It is possible to configure Apache CXF to use the com.sun.net.ssl implementation via 'System.setProperty("java.protocol.handler.pkgs", "com.EPSS 8.5%CVE-2018-8012No authentication/authorization is enforced when a server attempts to join a quorum in Apache ZooKeeper before 3.4.10, and 3.5.0-alpha throuEPSS 8.5%CVE-2022-25762Response mix-up with WebSocket concurrent send and closeEPSS 8.4%CVE-2017-12627In Apache Xerces-C XML Parser library before 3.2.1, processing of external DTD paths can result in a null pointer dereference under certain EPSS 8.4%