Exposición de Apache HTTP Server

Web servers
561
score de exposición
1.580.941
sitios usan
5
en explotación
20
críticos
Análisis Vexday

O Apache HTTP Server acumula 169 CVEs catalogadas, com 16 classificadas como críticas e 34 surgidas apenas nos últimos 90 dias, sinalizando um ritmo elevado de descobertas recentes que exige atenção contínua. A taxa de exploração ativa é 6,6 vezes acima da média geral do catálogo CISA KEV, com 5 vulnerabilidades confirmadas em uso por agentes de ameaça — proporção que coloca o servidor entre as tecnologias de maior risco operacional imediato. A CVE mais perigosa atualmente ativa, CVE-2021-40438, apresenta EPSS de 1,0, o valor máximo possível, indicando probabilidade praticamente certa de exploração observada no ambiente real. O tipo de falha mais recorrente é CWE-476 (desreferência de ponteiro nulo), embora o perfil de risco mais crítico esteja nas vulnerabilidades com exploração confirmada, que devem ser priorizadas em qualquer plano de remediação.

CVEs

178 resultados
CVE-2024-36387MEDIUMApache HTTP Server: DoS by Null pointer in websocket over HTTP/2EPSS 1.7%CVE-2024-40898CRITICALApache HTTP Server: SSRF with mod_rewrite in server/vhost context on WindowsEPSS 1.5%CVE-2025-58098HIGHApache HTTP Server: Server Side Includes adds query string to #exec cmd=...EPSS 1.5%CVE-2018-3713angular-http-server node module suffers from a Path Traversal vulnerability due to lack of validation of possibleFilename, which allows a maEPSS 1.5%CVE-2019-2751Vulnerability in the Oracle HTTP Server component of Oracle Fusion Middleware (subcomponent: OHS Config MBeans). Supported versions that areEPSS 1.4%CVE-2026-28780CRITICALApache HTTP Server: buffer overflow in mod_proxy_ajp via ajp_msg_check_header()EPSS 1.4%CVE-2021-4433MEDIUMKarjasoft Sami HTTP Server HTTP HEAD Rrequest denial of serviceEPSS 1.3%CVE-2020-2952MEDIUMVulnerability in the Oracle HTTP Server product of Oracle Fusion Middleware (component: Web Listener). The supported version that is affecteEPSS 1.2%CVE-2021-35666MEDIUMVulnerability in the Oracle HTTP Server product of Oracle Fusion Middleware (component: OSSL Module). The supported version that is affectedEPSS 1.2%CVE-2025-49630HIGHApache HTTP Server: mod_proxy_http2 denial of serviceEPSS 1.1%CVE-2026-34355HIGHApache HTTP Server: mod_proxy_html buffer overflowEPSS 1.1%CVE-2023-26281MEDIUMIBM HTTP Server denial of serviceEPSS 1.1%CVE-2024-43394HIGHApache HTTP Server: SSRF on Windows due to UNC pathsEPSS 1.1%CVE-2020-2530MEDIUMVulnerability in the Oracle HTTP Server product of Oracle Fusion Middleware (component: Web Listener). Supported versions that are affected EPSS 1.1%CVE-2025-34096CRITICALEasy File Sharing HTTP Server 7.2 Buffer Overflow via POST to /sendemail.ghpEPSS 1.1%CVE-2026-42536HIGHApache HTTP Server: mod_xml2enc heap overflowEPSS 1.0%CVE-2025-23048CRITICALApache HTTP Server: mod_ssl access control bypass with session resumptionEPSS 1.0%CVE-2021-2315MEDIUMVulnerability in the Oracle HTTP Server product of Oracle Fusion Middleware (component: Web Listener). Supported versions that are affected EPSS 1.0%CVE-2024-39884MEDIUMApache HTTP Server: source code disclosure with handlers configured via AddTypeEPSS 0.9%CVE-2025-59775HIGHApache HTTP Server: NTLM Leakage on Windows through UNC SSRFEPSS 0.8%