Apache

Security Scorecard

Score

13F

Total CVEs

1,018

Patch Rate

12%

126 patched

Avg Response

521d

days to patch

Critical Gaps

20

exploitable, no detection

Severity Breakdown

Critical10
High57
Medium98
Low0

Patch Status

Patched126 (12%)
Partial/Workaround2 (0%)
Unpatched890 (87%)

CVEs (1,028)

CVE IDTitleSeverityScoreDaysPatch
CVE-2025-29847Apache Linkis JDBC Engine Bypass VulnerabilityHigh7.5-Patched
CVE-2025-59355Apache Linkis Log Decoding VulnerabilityMedium6.5-Patched
CVE-2025-15537Mapnik Heap OverflowMedium5.3-Patched
CVE-2026-23769Lucy XSS Filter VulnerabilityMedium6.5-Patched
CVE-2026-23768Lucy XSS Filter VulnerabilityMedium6.1-Patched
CVE-2025-68438Apache Airflow UI Template ExposureHigh7.50dUnpatched
CVE-2025-60021Apache bRPC Heap Profiler Remote Command InjectionCritical9.8-Patched
CVE-2025-68675Apache Airflow Proxy VulnerabilityHigh7.50dUnpatched
CVE-2025-70302GPAC Heap OverflowMedium5.5-Patched
CVE-2025-66169Apache Camel Neo4j VulnerabilityMedium5.3-Patched