Apache

Security Scorecard

Score

13F

Total CVEs

1,018

Patch Rate

12%

126 patched

Avg Response

521d

days to patch

Critical Gaps

20

exploitable, no detection

Severity Breakdown

Critical10
High57
Medium98
Low0

Patch Status

Patched126 (12%)
Partial/Workaround2 (0%)
Unpatched890 (87%)

CVEs (1,028)

CVE IDTitleSeverityScoreDaysPatch
CVE-2026-23881Kyverno Policy Engine Denial of ServiceHigh7.7-Patched
CVE-2020-36956Openfire XSS VulnerabilityMedium6.4-Patched
CVE-2025-27821HDFS Native Client VulnerabilityHigh7.3-Patched
CVE-2025-14969Hibernate Reactive Denial of ServiceMedium4.3-Patched
CVE-2026-0603Hibernate SQL Injection FlawHigh8.3-Patched
CVE-2025-69820Beam Directory TraversalMedium6.00dUnpatched
CVE-2026-22445Apimo Connector Plugin VulnerabilityMedium5.3-Patched
CVE-2026-22022Apache Solr Rule-Based Authorization Plugin VulnerabilityHigh8.2-Patched
CVE-2026-22444Apache Solr Core API BypassHigh7.1-Patched
CVE-2026-21663Revive Adserver XSS VulnerabilityMedium6.1-Patched