Vulnerabilidades em Apache Software Foundation

2.334 resultados
Análise Vexday

O portfólio da Apache Software Foundation acumula 1.872 CVEs catalogadas, das quais 215 são de severidade crítica e 83 contam com prova de conceito pública — fatores que ampliam a superfície de risco operacional para equipes de segurança. A taxa de exploração ativa é especialmente preocupante: 28 vulnerabilidades constam no catálogo KEV da CISA, representando uma proporção 3,3 vezes acima da média geral do catálogo, o que indica atenção consistente de agentes maliciosos ao ecossistema Apache. A falha mais comum é CWE-20 (validação inadequada de entrada), padrão estrutural que tende a se manifestar em múltiplos produtos e versões, exigindo revisão ampla e não pontual. Destaque para CVE-2021-40438, a vulnerabilidade de maior risco ativo no momento, com EPSS máximo de 1,0 — probabilidade de exploração na prática praticamente certa —, o que a torna prioridade imediata de remediação para qualquer organização que opere componentes Apache afetados.

CVE-2017-15718The YARN NodeManager in Apache Hadoop 2.7.3 and 2.7.4 can leak the password for credential store provider used by the NodeManager to YARN ApEPSS 3.6%CVE-2006-20001Apache HTTP Server: mod_dav out of bounds read, or write of zero byteEPSS 3.5%CVE-2022-31813mod_proxy X-Forwarded-For dropped by hop-by-hop mechanismEPSS 3.5%CVE-2021-27577Incorrect handling of url fragment leads to cache poisoningEPSS 3.5%CVE-2017-15698When parsing the AIA-Extension field of a client certificate, Apache Tomcat Native Connector 1.2.0 to 1.2.14 and 1.1.23 to 1.1.34 did not coEPSS 3.5%CVE-2016-6800The default configuration of the Apache OFBiz framework offers a blog functionality. Different users are able to operate blogs which are relEPSS 3.5%CVE-2018-11797In Apache PDFBox 1.8.0 to 1.8.15 and 2.0.0RC1 to 2.0.11, a carefully crafted PDF file can trigger an extremely long running computation whenEPSS 3.5%CVE-2025-48989HIGHApache Tomcat: h2 DoS - Made You ResetEPSS 3.5%CVE-2017-7665In Apache NiFi before 0.7.4 and 1.x before 1.3.0, there are certain user input components in the UI which had been guarding for some forms oEPSS 3.5%CVE-2023-44313HIGHApache ServiceComb Service-Center: attacker can perform SSRF through the frontend APIEPSS 3.5%CVE-2021-41616CRITICALApache ddlutils 1.0 readobject vulnerabilityEPSS 3.5%CVE-2022-23942Apache Doris hardcoded cryptography initializationEPSS 3.5%CVE-2021-31811A carefully crafted PDF file can trigger an OutOfMemory-Exception while loading a tiny fileEPSS 3.4%CVE-2025-49125HIGHApache Tomcat: Security constraint bypass for pre/post-resourcesEPSS 3.4%CVE-2021-40369XSS vulnerability on Denounce pluginEPSS 3.4%CVE-2018-8015In Apache ORC 1.0.0 to 1.4.3 a malformed ORC file can trigger an endlessly recursive function call in the C++ or Java parser. The impact of EPSS 3.4%CVE-2020-17514disabled hostname verificiationEPSS 3.4%CVE-2022-46366CRITICALApache Tapestry prior to version 4 (EOL) allows RCE though deserialization of untrusted inputEPSS 3.4%CVE-2022-38649CRITICALApache Airflow Pinot provider allowed Command InjectionEPSS 3.4%CVE-2018-1287In Apache JMeter 2.X and 3.X, when using Distributed Test only (RMI based), jmeter server binds RMI Registry to wildcard host. This could alEPSS 3.4%