Apache Software Foundation
Self-Reporting Analysis
Of all the CVEs published by Apache Software Foundation as a CNA, 98.2% affect products that Apache Software Foundation develops as a vendor.
Of all the CVEs published that affect products developed by Apache Software Foundation, 69.6% are self-published by Apache Software Foundation as a CNA.
Trends Over Time
The number and severity of CVEs published by Apache Software Foundation over time
Top CVEs
All CVEs published by Apache Software Foundation as a CNA, regardless of affected vendor or product.
2,210 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-34197HIGH Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ.
Apache ActiveMQ Classic exposes the | Apr 7, 2026 | 8.8 | 99 | YES | YES |
CVE-2025-24813CRITICAL Path Equivalence: 'file.Name' (Internal Dot) leading to Remote Code Execution and/or Information disclosure and/or malicious content added to uploaded files via write enabled Defau | Mar 10, 2025 | 9.8 | 99 | YES | YES |
CVE-2024-32113CRITICAL Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache OFBiz.This issue affects Apache OFBiz: before 18.12.13.
Users are recommende | May 8, 2024 | 9.8 | 99 | YES | YES |
CVE-2024-27348CRITICAL RCE-Remote Command Execution vulnerability in Apache HugeGraph-Server.This issue affects Apache HugeGraph-Server: from 1.0.0 before 1.3.0 in Java8 & Java11
Users are recommended t | Apr 22, 2024 | 9.8 | 99 | YES | YES |
CVE-2023-27524CRITICAL Session Validation attacks in Apache Superset versions up to and including 2.0.1. Installations that have not altered the default configured SECRET_KEY according to installation in | Apr 24, 2023 | 9.8 | 99 | YES | YES |
CVE-2022-24706CRITICAL In Apache CouchDB prior to 3.2.2, an attacker can access an improperly secured default installation without authenticating and gain admin privileges. The CouchDB documentation has | Apr 26, 2022 | 9.8 | 99 | YES | YES |
CVE-2022-24112CRITICAL An attacker can abuse the batch-requests plugin to send requests to bypass the IP restriction of Admin API. A default configuration of Apache APISIX (with default API key) is vulne | Feb 11, 2022 | 9.8 | 99 | YES | YES |
CVE-2021-44228CRITICAL Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect agai | Dec 10, 2021 | 10.0 | 99 | YES | YES |
CVE-2021-42013CRITICAL It was found that the fix for CVE-2021-41773 in Apache HTTP Server 2.4.50 was insufficient. An attacker could use a path traversal attack to map URLs to files outside the directori | Oct 7, 2021 | 9.8 | 99 | YES | YES |
CVE-2021-41773CRITICAL A flaw was found in a change made to path normalization in Apache HTTP Server 2.4.49. An attacker could use a path traversal attack to map URLs to files outside the directories con | Oct 5, 2021 | 9.8 | 99 | YES | YES |
CVE Severity & Scoring
Exploit Exposure
Signals from CVEs in this cna scope (2210 CVEs).
Social Chatter
An overview of all social media posts that mention a CVE ID published by Apache Software Foundation as a CNA.
Media Mentions
Media articles that mention a CVE ID published by Apache Software Foundation as a CNA — matched by CVE ID, not by organization name.