Vulnerabilidades em Apache Software Foundation

2.344 resultados
Análise Vexday

O portfólio da Apache Software Foundation acumula 1.872 CVEs catalogadas, das quais 215 são de severidade crítica e 83 contam com prova de conceito pública — fatores que ampliam a superfície de risco operacional para equipes de segurança. A taxa de exploração ativa é especialmente preocupante: 28 vulnerabilidades constam no catálogo KEV da CISA, representando uma proporção 3,3 vezes acima da média geral do catálogo, o que indica atenção consistente de agentes maliciosos ao ecossistema Apache. A falha mais comum é CWE-20 (validação inadequada de entrada), padrão estrutural que tende a se manifestar em múltiplos produtos e versões, exigindo revisão ampla e não pontual. Destaque para CVE-2021-40438, a vulnerabilidade de maior risco ativo no momento, com EPSS máximo de 1,0 — probabilidade de exploração na prática praticamente certa —, o que a torna prioridade imediata de remediação para qualquer organização que opere componentes Apache afetados.

CVE-2023-38647CRITICALApache Helix: Deserialization vulnerability in Helix workflow and RESTEPSS 2.0%CVE-2024-54677MEDIUMApache Tomcat: DoS in examples web applicationEPSS 2.0%CVE-2021-38161—Not validating origin TLS certificateEPSS 1.9%CVE-2021-36774—Mysql JDBC Connector Deserialize RCEEPSS 1.9%CVE-2018-1281—The clustered setup of Apache MXNet allows users to specify which IP address and port the scheduler will listen on via the DMLC_PS_ROOT_URI EPSS 1.9%CVE-2017-12623—An authorized user could upload a template which contained malicious code and accessed sensitive files via an XML External Entity (XXE) attaEPSS 1.9%CVE-2021-44549—SMTPS server hostname not checked when making TLS connection to SMTPS serverEPSS 1.9%CVE-2021-41767—Private tunnel identifier may be included in the non-private details of active connectionsEPSS 1.9%CVE-2022-44645HIGHApache Linkis (incubating): The DatasourceManager module has a serialization attack vulnerabilityEPSS 1.9%CVE-2017-5660—There is a vulnerability in Apache Traffic Server (ATS) 6.2.0 and prior and 7.0.0 and prior with the Host header and line folding. This can EPSS 1.9%CVE-2024-46901LOWApache Subversion: mod_dav_svn denial-of-service via control characters in pathsEPSS 1.9%CVE-2022-27949HIGHApache Airflow prior to 2.3.1 may include sensitive values in rendered templateEPSS 1.9%CVE-2021-27644—DolphinScheduler mysql jdbc connector parameters deserialize remote code executionEPSS 1.9%CVE-2021-43083—Apache PLC4X 0.9.0 Buffer overflow in PLC4C via crafted server responseEPSS 1.9%CVE-2023-46226CRITICALApache IoTDB: Remote Code Execution (RCE) risk via the UDFEPSS 1.9%CVE-2012-3536—Two XSS vulnerabilities were fixed in message list and view in the Hupa Webmail application from the Apache James project. An attacker couldEPSS 1.9%CVE-2022-31781—Regular Expression Denial of Service (ReDoS) in ContentType.java. (GHSL-2022-022)EPSS 1.9%CVE-2025-52434HIGHApache Tomcat: APR/Native Connector crash leading to DoSEPSS 1.9%CVE-2023-26464HIGHApache Log4j 1.x (EOL) allows DoS in Chainsaw and SocketAppenderEPSS 1.9%CVE-2022-40705HIGHApache SOAP: XML External Entity Injection (XXE) allows unauthenticated users to read arbitrary files via HTTPEPSS 1.9%