Apache Software Foundation

First CVE: Dec 5, 2016Active for: 10 years
2,210
CVEs Published
More CVEs Published than 94% of tracked CNAs
200.9
Avg CVEs / Year
More Avg CVEs / Year than 95% of tracked CNAs
7.5
Avg CVSS Score
Higher Avg CVSS Score than 65% of tracked CNAs
1.5%
In CISA KEV
Higher KEV Rate than 90% of tracked CNAs

Self-Reporting Analysis

Of all the CVEs published by Apache Software Foundation as a CNA, 98.2% affect products that Apache Software Foundation develops as a vendor.

98.2%
Self-reported: 2,170Third-party: 40

Of all the CVEs published that affect products developed by Apache Software Foundation, 69.6% are self-published by Apache Software Foundation as a CNA.

69.6%
30.4%
Self-published: 2,170Published by other CNAs: 947

Trends Over Time

The number and severity of CVEs published by Apache Software Foundation over time

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 5, 2016
9 years ago
Most Recent CVE
Jul 21, 2026
3 days ago

Top CVEs

All CVEs published by Apache Software Foundation as a CNA, regardless of affected vendor or product.

2,210 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ. Apache ActiveMQ Classic exposes the
Apr 7, 20268.899YESYES
Path Equivalence: 'file.Name' (Internal Dot) leading to Remote Code Execution and/or Information disclosure and/or malicious content added to uploaded files via write enabled Defau
Mar 10, 20259.899YESYES
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache OFBiz.This issue affects Apache OFBiz: before 18.12.13. Users are recommende
May 8, 20249.899YESYES
RCE-Remote Command Execution vulnerability in Apache HugeGraph-Server.This issue affects Apache HugeGraph-Server: from 1.0.0 before 1.3.0 in Java8 & Java11 Users are recommended t
Apr 22, 20249.899YESYES
Session Validation attacks in Apache Superset versions up to and including 2.0.1. Installations that have not altered the default configured SECRET_KEY according to installation in
Apr 24, 20239.899YESYES
In Apache CouchDB prior to 3.2.2, an attacker can access an improperly secured default installation without authenticating and gain admin privileges. The CouchDB documentation has
Apr 26, 20229.899YESYES
An attacker can abuse the batch-requests plugin to send requests to bypass the IP restriction of Admin API. A default configuration of Apache APISIX (with default API key) is vulne
Feb 11, 20229.899YESYES
Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect agai
Dec 10, 202110.099YESYES
It was found that the fix for CVE-2021-41773 in Apache HTTP Server 2.4.50 was insufficient. An attacker could use a path traversal attack to map URLs to files outside the directori
Oct 7, 20219.899YESYES
A flaw was found in a change made to path normalization in Apache HTTP Server 2.4.49. An attacker could use a path traversal attack to map URLs to files outside the directories con
Oct 5, 20219.899YESYES

CVE Severity & Scoring

Severity distribution of CVEs published by this CNA2,210 CVEs
Severity distribution among all CVEs352,231 CVEs
LowMediumHighCritical
Attack Vector
Local114 (5.2%)
Network2,087 (94.4%)
Unknown0 (0.0%)
Physical1 (0.0%)
Adjacent Network8 (0.4%)
Attack Complexity
Low2,023 (91.5%)
High187 (8.5%)
Unknown0 (0.0%)
User Interaction
None1,901 (86.0%)
Unknown0 (0.0%)
Required303 (13.7%)
Privileges Required
Low625 (28.3%)
High56 (2.5%)
None1,529 (69.2%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this cna scope (2210 CVEs).

CISA KEV
34 CVEs
1.5% of CVEs· 90th percentile
Metasploit
48 CVEs
2.2% of CVEs· 91st percentile
Nuclei
118 CVEs
5.3% of CVEs· 94th percentile
ExploitDB
54 CVEs
2.4% of CVEs· 91st percentile

Social Chatter

An overview of all social media posts that mention a CVE ID published by Apache Software Foundation as a CNA.

Media Mentions

Media articles that mention a CVE ID published by Apache Software Foundation as a CNA — matched by CVE ID, not by organization name.

Top Affected Vendors

Top Affected Products

Top CWEs