Vulnerabilidades em Apache Software Foundation

2.371 resultados
Análise Vexday

O portfólio da Apache Software Foundation acumula 1.872 CVEs catalogadas, das quais 215 são de severidade crítica e 83 contam com prova de conceito pública — fatores que ampliam a superfície de risco operacional para equipes de segurança. A taxa de exploração ativa é especialmente preocupante: 28 vulnerabilidades constam no catálogo KEV da CISA, representando uma proporção 3,3 vezes acima da média geral do catálogo, o que indica atenção consistente de agentes maliciosos ao ecossistema Apache. A falha mais comum é CWE-20 (validação inadequada de entrada), padrão estrutural que tende a se manifestar em múltiplos produtos e versões, exigindo revisão ampla e não pontual. Destaque para CVE-2021-40438, a vulnerabilidade de maior risco ativo no momento, com EPSS máximo de 1,0 — probabilidade de exploração na prática praticamente certa —, o que a torna prioridade imediata de remediação para qualquer organização que opere componentes Apache afetados.

CVE-2017-15697A malicious X-ProxyContextPath or X-Forwarded-Context header containing external resources or embedded code could cause remote code executioEPSS 4.8%CVE-2018-1288In Apache Kafka 0.9.0.0 to 0.9.0.1, 0.10.0.0 to 0.10.2.1, 0.11.0.0 to 0.11.0.2, and 1.0.0, authenticated Kafka users may perform action reseEPSS 4.8%CVE-2025-53020HIGHApache HTTP Server: HTTP/2 DoS by Memory IncreaseEPSS 4.8%CVE-2026-40466HIGHApache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Possible bypass of CVE-2026-34197 via HTTP discovery second-stage URIEPSS 4.8%CVE-2016-8736Apache OpenMeetings before 3.1.2 is vulnerable to Remote Code Execution via RMI deserialization attack.EPSS 4.8%CVE-2017-15692In Apache Geode before v1.4.0, the TcpServer within the Geode locator opens a network port that deserializes data. If an unprivileged user gEPSS 4.8%CVE-2022-29063Java Deserialization via RMI Connection from the Solr plugin of Apache OFBizEPSS 4.8%CVE-2021-43350LDAP filter injection vulnerability in Traffic OpsEPSS 4.8%CVE-2019-10076A carefully crafted malicious attachment could trigger an XSS vulnerability on Apache JSPWiki 2.9.0 to 2.11.0.M3, which could lead to sessioEPSS 4.7%CVE-2019-10077A carefully crafted InterWiki link could trigger an XSS vulnerability on Apache JSPWiki 2.9.0 to 2.11.0.M3, which could lead to session hijaEPSS 4.7%CVE-2017-7670The Traffic Router component of the incubating Apache Traffic Control project is vulnerable to a Slowloris style Denial of Service attack. TEPSS 4.7%CVE-2021-29943Apache Solr Unprivileged users may be able to perform unauthorized read/write to collectionsEPSS 4.7%CVE-2018-8036In Apache PDFBox 1.8.0 to 1.8.14 and 2.0.0RC1 to 2.0.10, a carefully crafted (or fuzzed) file can trigger an infinite loop which leads to anEPSS 4.6%CVE-2021-41973Apache MINA HTTP listener DOSEPSS 4.6%CVE-2018-1313In Apache Derby 10.3.1.4 to 10.14.1.0, a specially-crafted network packet can be used to request the Derby Network Server to boot a databaseEPSS 4.6%CVE-2019-12410While investigating UBSAN errors in https://github.com/apache/arrow/pull/5365 it was discovered Apache Arrow versions 0.12.0 to 0.14.1, leftEPSS 4.6%CVE-2024-34750HIGHApache Tomcat: HTTP/2 excess header handling DoSEPSS 4.6%CVE-2017-5644Apache POI in versions prior to release 3.15 allows remote attackers to cause a denial of service (CPU consumption) via a specially crafted EPSS 4.6%CVE-2020-9493Java deserialization in ChainsawEPSS 4.6%CVE-2018-1317In Apache Zeppelin prior to 0.8.0 the cron scheduler was enabled by default and could allow users to run paragraphs as other users without aEPSS 4.6%