Vulnerabilidades em Apache Software Foundation

2.345 resultados
Análise Vexday

O portfólio da Apache Software Foundation acumula 1.872 CVEs catalogadas, das quais 215 são de severidade crítica e 83 contam com prova de conceito pública — fatores que ampliam a superfície de risco operacional para equipes de segurança. A taxa de exploração ativa é especialmente preocupante: 28 vulnerabilidades constam no catálogo KEV da CISA, representando uma proporção 3,3 vezes acima da média geral do catálogo, o que indica atenção consistente de agentes maliciosos ao ecossistema Apache. A falha mais comum é CWE-20 (validação inadequada de entrada), padrão estrutural que tende a se manifestar em múltiplos produtos e versões, exigindo revisão ampla e não pontual. Destaque para CVE-2021-40438, a vulnerabilidade de maior risco ativo no momento, com EPSS máximo de 1,0 — probabilidade de exploração na prática praticamente certa —, o que a torna prioridade imediata de remediação para qualquer organização que opere componentes Apache afetados.

CVE-2021-27850Bypass of the fix for CVE-2019-0195EPSS 93.5%CVE-2024-45507HIGHApache OFBiz: Prevent use of URLs in files when loading them from Java or Groovy, leading to a RCEEPSS 93.2%CVE-2022-33891HIGHApache Spark shell command injection vulnerability via Spark UIEPSS 93.1%KEVCVE-2021-27905SSRF vulnerability with the Replication handlerEPSS 93.1%CVE-2022-24706CRITICALRemote Code Execution Vulnerability in PackagingEPSS 92.5%KEVCVE-2024-45216CRITICALApache Solr: Authentication bypass possible using a fake URL Path endingEPSS 91.7%CVE-2024-27316HIGHApache HTTP Server: HTTP/2 DoS by memory exhaustion on endless continuation framesEPSS 91.3%CVE-2018-1335From Apache Tika versions 1.7 to 1.17, clients could send carefully crafted headers to tika-server that could be used to inject commands intEPSS 90.9%CVE-2023-37582CRITICALApache RocketMQ: Possible remote code execution when using the update configuration functionEPSS 90.4%CVE-2016-8735CRITICALRemote code execution is possible with Apache Tomcat before 6.0.48, 7.x before 7.0.73, 8.x before 8.0.39, 8.5.x before 8.5.7, and 9.x beforeEPSS 90.3%KEVCVE-2017-5645In Apache Log4j 2.x before 2.8.2, when using the TCP socket server or UDP socket server to receive serialized log events from another applicEPSS 89.8%CVE-2022-30522mod_sed denial of serviceEPSS 89.5%CVE-2021-45456Command injectionEPSS 88.9%CVE-2017-12636CouchDB administrative users can configure the database server via HTTP(S). Some of the configuration options include paths for operating syEPSS 87.9%CVE-2024-36104CRITICALApache OFBiz: Path traversal leading to a RCEEPSS 87.8%CVE-2025-66516HIGHApache Tika core, Apache Tika parsers, Apache Tika PDF parser module: Update to CVE-2025-54988 to expand scope of artifacts affectedEPSS 87.7%CVE-2021-27907Apache Superset stored XSS on Dashboard markdownEPSS 86.4%CVE-2021-45232security vulnerability on unauthorized access.EPSS 86.3%CVE-2023-39265LOWApache Superset: Possible Unauthorized Registration of SQLite Database ConnectionsEPSS 86.2%CVE-2022-41678Apache ActiveMQ: Insufficient API restrictions on Jolokia allow authenticated users to perform RCEEPSS 85.8%