VulnSea

Apache Software Foundation has 91 CVEs on record. Disclosure cadence is accelerating: 90 in the last 90 days against 1 in the 90 before. The busiest recent month was September 2026 with 88. The median CVSS is 7.5 (high), with 28 rated critical. None have a confirmed exploitation report. The dominant weakness classes are CWE-863 (11) and CWE-79 (6). Most affected products: Apache Tomcat (12), org.apache.storm:storm-server (8), Apache Sling XSS (5).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
7.5
Publish → KEV
—
Last 90 days
90 prev 1

Products

  • Apache Tomcat 12
  • org.apache.storm:storm-server 8
  • Apache Sling XSS 5
  • Apache Doris 4
  • org.apache.syncope.core:syncope-core-provisioning-java 4
  • org.apache.syncope.core:syncope-core-spring 4
Follow Apache Software Foundation:RSS feedSave a search →Embed badge ↗
91
Total CVEs
28
Critical
0
CISA KEV
0
Exploited
Apache Software Foundation vulnerabilities (CVEs) — page 4 · VulnSea