Vulnerabilidades em Apache Software Foundation

2.345 resultados
Análise Vexday

O portfólio da Apache Software Foundation acumula 1.872 CVEs catalogadas, das quais 215 são de severidade crítica e 83 contam com prova de conceito pública — fatores que ampliam a superfície de risco operacional para equipes de segurança. A taxa de exploração ativa é especialmente preocupante: 28 vulnerabilidades constam no catálogo KEV da CISA, representando uma proporção 3,3 vezes acima da média geral do catálogo, o que indica atenção consistente de agentes maliciosos ao ecossistema Apache. A falha mais comum é CWE-20 (validação inadequada de entrada), padrão estrutural que tende a se manifestar em múltiplos produtos e versões, exigindo revisão ampla e não pontual. Destaque para CVE-2021-40438, a vulnerabilidade de maior risco ativo no momento, com EPSS máximo de 1,0 — probabilidade de exploração na prática praticamente certa —, o que a torna prioridade imediata de remediação para qualquer organização que opere componentes Apache afetados.

CVE-2024-27136MEDIUMApache JSPWiki: Cross-site scripting vulnerability on upload pageEPSS 60.8%CVE-2021-30181Apache Dubbo RCE on customers via Script route poisoning (Nashorn script injection)EPSS 60.6%CVE-2021-30180Apache Dubbo RCE on customers via Condition route poisoning (Unsafe YAML unmarshaling)EPSS 60.4%CVE-2019-17567mod_proxy_wstunnel tunneling of non Upgraded connectionsEPSS 60.3%CVE-2025-31650HIGHApache Tomcat: DoS via malformed HTTP/2 PRIORITY_UPDATE frameEPSS 59.9%CVE-2019-0190A bug exists in the way mod_ssl handled client renegotiations. A remote attacker could send a carefully crafted request that would cause modEPSS 59.1%CVE-2018-11803Subversion's mod_dav_svn Apache HTTPD module versions 1.11.0 and 1.10.0 to 1.10.3 will crash after dereferencing an uninitialized pointer ifEPSS 58.5%CVE-2017-7668The HTTP strict parsing changes added in Apache httpd 2.2.32 and 2.4.24 introduced a bug in token list parsing, which allows ap_find_token()EPSS 57.5%CVE-2018-8006An instance of a cross-site scripting vulnerability was identified to be present in the web based administration console on the queue.jsp paEPSS 57.2%CVE-2024-27317HIGHApache Pulsar: Pulsar Functions Worker's Archive Extraction Vulnerability Allows Unauthorized File ModificationEPSS 56.9%CVE-2022-28731Apache JSPWiki CSRF in UserPreferences.jspEPSS 56.9%CVE-2017-9788In Apache httpd before 2.2.34 and 2.4.x before 2.4.27, the value placeholder in [Proxy-]Authorization headers of type 'Digest' was not initiEPSS 56.8%CVE-2018-8011mod_md, DoS via Coredumps on specially crafted requestsEPSS 55.6%CVE-2021-29200RCE vulnerability in latest Apache OFBiz due to Java serialisation using RMIEPSS 55.4%CVE-2022-43396HIGHApache Kylin: Command injection by Useless configurationEPSS 55.3%CVE-2021-44521Remote code execution for scripted UDFsEPSS 55.0%CVE-2020-35452mod_auth_digest possible stack overflow by one nul byteEPSS 54.8%CVE-2022-23307HIGHA deserialization flaw in the Chainsaw component of Log4j 1 can lead to malicious code execution.EPSS 54.4%CVE-2017-7659A maliciously constructed HTTP/2 request could cause mod_http2 in Apache HTTP Server 2.4.24, 2.4.25 to dereference a NULL pointer and crash EPSS 53.9%CVE-2023-39456HIGHApache Traffic Server: Malformed http/2 frames can cause an abortEPSS 53.8%