Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Apache Software Foundation

First CVE: Mar 20, 1996Active for: 30 yearsTotal CVEs: 3,117
70.4
VTI Score
TOP TARGET

The Apache Software Foundation maintains one of the largest and most broadly deployed open-source software portfolios in the landscape, spanning web servers, application servers, data processing frameworks, and middleware that underpin critical infrastructure across enterprises and the public internet. Vulnerabilities affecting the Foundation's projects skew toward serious outcomes, with an elevated share reaching critical severity and a strong tendency to acquire public exploit code, reflecting the high-value nature of internet-facing and data-handling components. The exposure concentrates across flagship projects including the HTTP Server, Tomcat application server, Airflow orchestration platform, Struts web framework, and Traffic Server, with recurring weakness classes centered on input validation failures, cross-site scripting, and unsafe deserialization that are characteristic of web-tier and integration-heavy software. Defenders should treat Apache project advisories as broadly applicable and prioritize patches for internet-reachable or data-processing deployments; live severity and exploitation counts are shown alongside this summary.

FAUCET AI Generated
3,117
Total CVEs
More Total CVEs than 100% of tracked vendors
0.3
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 2% of tracked vendors
7.0
Avg CVSS Score
Higher Avg CVSS Score than 50% of tracked vendors
1.4%
In CISA KEV
Higher KEV Rate than 99% of tracked vendors

Trends Over Time

The number and severity of CVEs published that impact products developed by Apache Software Foundation over time

Volume of CVEsAvg CVSS Base Score
First CVE
Mar 20, 1996
30 years ago
Most Recent CVE
Jul 18, 2026
6 days ago

Self-Reporting Analysis

Of all the CVEs published by Apache Software Foundation as a CNA, 98.2% affect products that Apache Software Foundation develops as a vendor.

98.2%
Self-reported: 2,170 (98.2%)
Third-party: 40 (1.8%)

Of all the CVEs published that affect products developed by Apache Software Foundation, 69.6% are self-published by Apache Software Foundation as a CNA.

69.6%
30.4%
Self-published: 2,170 (69.6%)
Other CNAs: 947 (30.4%)

Products(381 total)

Top CVEs

Signals from CVEs in this vendor scope (3117 CVEs).

3,117 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2026-34197HIGH
Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ. Apache ActiveMQ Classic exposes the
Apr 7, 20268.899YESYES
CVE-2025-24813CRITICAL
Path Equivalence: 'file.Name' (Internal Dot) leading to Remote Code Execution and/or Information disclosure and/or malicious content added to uploaded files via write enabled Defau
Mar 10, 20259.899YESYES
CVE-2024-32113CRITICAL
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache OFBiz.This issue affects Apache OFBiz: before 18.12.13. Users are recommende
May 8, 20249.899YESYES
CVE-2024-27348CRITICAL
RCE-Remote Command Execution vulnerability in Apache HugeGraph-Server.This issue affects Apache HugeGraph-Server: from 1.0.0 before 1.3.0 in Java8 & Java11 Users are recommended t
Apr 22, 20249.899YESYES
CVE-2023-27524CRITICAL
Session Validation attacks in Apache Superset versions up to and including 2.0.1. Installations that have not altered the default configured SECRET_KEY according to installation in
Apr 24, 20239.899YESYES
CVE-2022-24706CRITICAL
In Apache CouchDB prior to 3.2.2, an attacker can access an improperly secured default installation without authenticating and gain admin privileges. The CouchDB documentation has
Apr 26, 20229.899YESYES
CVE-2022-24112CRITICAL
An attacker can abuse the batch-requests plugin to send requests to bypass the IP restriction of Admin API. A default configuration of Apache APISIX (with default API key) is vulne
Feb 11, 20229.899YESYES
CVE-2021-44228CRITICAL
Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect agai
Dec 10, 202110.099YESYES
CVE-2021-42013CRITICAL
It was found that the fix for CVE-2021-41773 in Apache HTTP Server 2.4.50 was insufficient. An attacker could use a path traversal attack to map URLs to files outside the directori
Oct 7, 20219.899YESYES
CVE-2021-41773CRITICAL
A flaw was found in a change made to path normalization in Apache HTTP Server 2.4.49. An attacker could use a path traversal attack to map URLs to files outside the directories con
Oct 5, 20219.899YESYES
View all 3,117 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products3,117 CVEs
43%
38%
17%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local146 (4.7%)
Network2,312 (74.2%)
Unknown648 (20.8%)
Physical1 (0.0%)
Adjacent Network10 (0.3%)
Attack Complexity
Low2,254 (72.3%)
High215 (6.9%)
Unknown648 (20.8%)
User Interaction
None2,119 (68.0%)
Unknown648 (20.8%)
Required350 (11.2%)
Privileges Required
Low670 (21.5%)
High68 (2.2%)
None1,731 (55.5%)
Unknown648 (20.8%)

Exploit Exposure

Signals from CVEs in this vendor scope (3117 CVEs).

CISA KEV
44 CVEs
1.4% of CVEs· 99th percentile
Metasploit
91 CVEs
2.9% of CVEs· 98th percentile
Nuclei
139 CVEs
4.5% of CVEs· 95th percentile
ExploitDB
218 CVEs
7.0% of CVEs· 75th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Apache Software Foundation.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Apache Software Foundation — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Apache Software Foundation's Products

View all 21 CNAs →

Top CWEs