Cyber Resilience

← All vendors

Apache

CPE vendor key: apache · 966 CVEs published in the last 24 months.

CVEs (365 d)
743
▲ +78 vs prior 30d
Avg CVSS (365 d)
7.29
over 743 CVEs
Avg EPSS pct (365 d)
0.41
higher = more likely exploited
KEV hit rate (365 d)
0.3%
2 of 743 added to CISA KEV
LLM-credited CVEs
0
none detected

Monthly CVE volume — last 24 months

2024202520260181
Each point is one calendar month. Bars in the severity card to the right slice the same volume by CVSS band.

Severity mix

CritHighMedLow
Stacked by CVSS band (Critical / High / Medium / Low) using the best available metric per CVE.

Top affected products (24 mo)

airflow
70
tomcat
52
traffic_server
52
camel
50
http_server
39
cxf
29
ofbiz
28
activemq
25
thrift
25
cloudstack
20
Distinct CVEs that include each product in their CPE configuration.

Top CWEs (24 mo)

CWE-502
79
CWE-20
73
CWE-200
42
CWE-400
40
CWE-918
33
CWE-863
30
CWE-770
30
CWE-22
30
CWE-94
27
CWE-89
27
Distinct CVEs assigned each weakness.

Recent CISA KEV adds (last 12 months)

AddedCVEProductKEV name
2026-08-04CVE-2026-34486TomcatApache Tomcat Missing Encryption of Sensitive Data Vulnerability
2026-04-16CVE-2026-34197ActiveMQApache ActiveMQ Improper Input Validation Vulnerability
Filtered to KEV entries whose CISA vendor or product name matches this vendor exactly, to drop cross-OS noise (e.g. third-party Windows apps that CPE-map to Microsoft).

Generated 23 August 2026 22:22 UTC .