The Apache Software Foundation maintains one of the largest and most broadly deployed open-source software portfolios in the landscape, spanning web servers, application servers, data processing frameworks, and middleware that underpin critical infrastructure across enterprises and the public internet. Vulnerabilities affecting the Foundation's projects skew toward serious outcomes, with an elevated share reaching critical severity and a strong tendency to acquire public exploit code, reflecting the high-value nature of internet-facing and data-handling components. The exposure concentrates across flagship projects including the HTTP Server, Tomcat application server, Airflow orchestration platform, Struts web framework, and Traffic Server, with recurring weakness classes centered on input validation failures, cross-site scripting, and unsafe deserialization that are characteristic of web-tier and integration-heavy software. Defenders should treat Apache project advisories as broadly applicable and prioritize patches for internet-reachable or data-processing deployments; live severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Apache Software Foundation over time
Of all the CVEs published by Apache Software Foundation as a CNA, 98.2% affect products that Apache Software Foundation develops as a vendor.
Of all the CVEs published that affect products developed by Apache Software Foundation, 69.6% are self-published by Apache Software Foundation as a CNA.
Signals from CVEs in this vendor scope (3117 CVEs).
3,117 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-34197HIGH Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ.
Apache ActiveMQ Classic exposes the | Apr 7, 2026 | 8.8 | 99 | YES | YES |
CVE-2025-24813CRITICAL Path Equivalence: 'file.Name' (Internal Dot) leading to Remote Code Execution and/or Information disclosure and/or malicious content added to uploaded files via write enabled Defau | Mar 10, 2025 | 9.8 | 99 | YES | YES |
CVE-2024-32113CRITICAL Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache OFBiz.This issue affects Apache OFBiz: before 18.12.13.
Users are recommende | May 8, 2024 | 9.8 | 99 | YES | YES |
CVE-2024-27348CRITICAL RCE-Remote Command Execution vulnerability in Apache HugeGraph-Server.This issue affects Apache HugeGraph-Server: from 1.0.0 before 1.3.0 in Java8 & Java11
Users are recommended t | Apr 22, 2024 | 9.8 | 99 | YES | YES |
CVE-2023-27524CRITICAL Session Validation attacks in Apache Superset versions up to and including 2.0.1. Installations that have not altered the default configured SECRET_KEY according to installation in | Apr 24, 2023 | 9.8 | 99 | YES | YES |
CVE-2022-24706CRITICAL In Apache CouchDB prior to 3.2.2, an attacker can access an improperly secured default installation without authenticating and gain admin privileges. The CouchDB documentation has | Apr 26, 2022 | 9.8 | 99 | YES | YES |
CVE-2022-24112CRITICAL An attacker can abuse the batch-requests plugin to send requests to bypass the IP restriction of Admin API. A default configuration of Apache APISIX (with default API key) is vulne | Feb 11, 2022 | 9.8 | 99 | YES | YES |
CVE-2021-44228CRITICAL Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect agai | Dec 10, 2021 | 10.0 | 99 | YES | YES |
CVE-2021-42013CRITICAL It was found that the fix for CVE-2021-41773 in Apache HTTP Server 2.4.50 was insufficient. An attacker could use a path traversal attack to map URLs to files outside the directori | Oct 7, 2021 | 9.8 | 99 | YES | YES |
CVE-2021-41773CRITICAL A flaw was found in a change made to path normalization in Apache HTTP Server 2.4.49. An attacker could use a path traversal attack to map URLs to files outside the directories con | Oct 5, 2021 | 9.8 | 99 | YES | YES |
Signals from CVEs in this vendor scope (3117 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Apache Software Foundation.
Media articles that mention a CVE ID that affects a product developed by Apache Software Foundation — matched by CVE ID, not by vendor name.