Apache vulnerabilities
3,483 CVEs affecting Apache products, 46 known to be exploited (CISA KEV), with EPSS scores. Most affected: HTTP Server, Tomcat, Airflow, Traffic Server, Struts.
- HTTP Server: 350 CVEs
- Tomcat: 274 CVEs
- Airflow: 158 CVEs
- Traffic Server: 121 CVEs
- Struts: 99 CVEs
- Camel: 86 CVEs
- OFBiz: 76 CVEs
- ActiveMQ: 75 CVEs
- Superset: 70 CVEs
- Cxf: 69 CVEs