Vulnerabilidades em Apache Software Foundation

2.346 resultados
Análise Vexday

O portfólio da Apache Software Foundation acumula 1.872 CVEs catalogadas, das quais 215 são de severidade crítica e 83 contam com prova de conceito pública — fatores que ampliam a superfície de risco operacional para equipes de segurança. A taxa de exploração ativa é especialmente preocupante: 28 vulnerabilidades constam no catálogo KEV da CISA, representando uma proporção 3,3 vezes acima da média geral do catálogo, o que indica atenção consistente de agentes maliciosos ao ecossistema Apache. A falha mais comum é CWE-20 (validação inadequada de entrada), padrão estrutural que tende a se manifestar em múltiplos produtos e versões, exigindo revisão ampla e não pontual. Destaque para CVE-2021-40438, a vulnerabilidade de maior risco ativo no momento, com EPSS máximo de 1,0 — probabilidade de exploração na prática praticamente certa —, o que a torna prioridade imediata de remediação para qualquer organização que opere componentes Apache afetados.

CVE-2018-1306The PortletV3AnnotatedDemo Multipart Portlet war file code provided in Apache Pluto version 3.0.0 could allow a remote attacker to obtain seEPSS 43.5%CVE-2025-68493HIGHApache Struts, Apache Struts: XXE vulnerability in outdated XWork componentEPSS 43.3%CVE-2021-37580Apache ShenYu Admin bypass JWT authenticationEPSS 41.9%CVE-2022-22721core: Possible buffer overflow with very large or unlimited LimitXMLRequestBodyEPSS 41.7%CVE-2024-38476CRITICALApache HTTP Server may use exploitable/malicious backend application output to run local handlers via internal redirectEPSS 41.6%CVE-2024-45387CRITICALApache Traffic Control: SQL Injection in Traffic Ops endpoint PUT deliveryservice_request_commentsEPSS 41.5%CVE-2020-13954Apache CXF Reflected XSS in the services listing page via the styleSheetPathEPSS 40.9%CVE-2020-17525Remote unauthenticated denial-of-service in Subversion mod_authz_svnEPSS 40.1%CVE-2016-6816The code in Apache Tomcat 9.0.0.M1 to 9.0.0.M11, 8.5.0 to 8.5.6, 8.0.0.RC1 to 8.0.38, 7.0.0 to 7.0.72, and 6.0.0 to 6.0.47 that parsed the HEPSS 39.6%CVE-2021-39275ap_escape_quotes buffer overflowEPSS 39.4%CVE-2017-7679In Apache httpd 2.2.x before 2.2.33 and 2.4.x before 2.4.26, mod_mime can read one byte past the end of a buffer when sending a malicious CoEPSS 39.3%CVE-2025-54988HIGHApache Tika PDF parser module: XXE vulnerability in PDFParser's handling of XFAEPSS 37.7%CVE-2022-22733Access-Token in ElasticJob UI causes password disclosureEPSS 37.6%CVE-2024-39573HIGHApache HTTP Server: mod_rewrite proxy handler substitutionEPSS 37.2%CVE-2020-11981An issue was found in Apache Airflow versions 1.10.10 and below. When using CeleryExecutor, if an attacker can connect to the broker (Redis,EPSS 36.5%CVE-2023-37941MEDIUMApache Superset: Metadata db write access can lead to remote code executionEPSS 35.5%CVE-2026-49975HIGHApache HTTP Server: mod_http2 denial of serviceEPSS 34.3%CVE-2020-1947In Apache ShardingSphere(incubator) 4.0.0-RC3 and 4.0.0, the ShardingSphere's web console uses the SnakeYAML library for parsing YAML inputsEPSS 33.9%CVE-2025-48976HIGHApache Commons FileUpload, Apache Commons FileUpload: FileUpload DoS via part headersEPSS 33.0%CVE-2025-48988HIGHApache Tomcat: FileUpload large number of parts with headers DoSEPSS 30.5%