# Apache Log4j 2.14.1 by CVSS Score

The CVSS score distribution of the CVEs that affect Log4j 2.14.1.

Source: https://docs.deepinfo.com/reference/vulnerability/cvss-score-stats/examples/vendor-product-version/

Last updated: 2026-09-24

---
`GET https://api.deepinfo.com/v1/explore/vulnerability-insight/vulnerability-stats-by-cvss-scores?vendor=apache&product=log4j&version=2.14.1`

The CVSS score distribution of the CVEs that affect Log4j 2.14.1.

Example 4 of 5 · [CVSS Score Stats Examples](/reference/vulnerability/cvss-score-stats/examples/) · endpoint: [CVSS Score Stats](/reference/vulnerability/cvss-score-stats/)

Tags: `param` `vendor` · `param` `product` · `param` `version` · `value` `apache` · `value` `log4j` · `value` `2.14.1`

`version` keeps the CVEs whose affected range includes that exact release; the response repeats it in `version`.

## What to Notice

`cve_count` is 9 across 6 scores, from 5.9 to 10.0.

## Request

| Parameter | In | Value |
|---|---|---|
| `vendor` | query | `apache` |
| `product` | query | `log4j` |
| `version` | query | `2.14.1` |

```bash
curl 'https://api.deepinfo.com/v1/explore/vulnerability-insight/vulnerability-stats-by-cvss-scores?vendor=apache&product=log4j&version=2.14.1' \
  -H 'apikey: YOUR_API_KEY' \
  -H 'Accept: application/json'
```

## Response

### 200 · OK

`Content-Type: application/json` · `ratelimit-limit: 1` · `ratelimit-remaining: 0` · `ratelimit-reset: 1` · `x-ratelimit-limit-second: 1` · `x-ratelimit-remaining-second: 0` · `deepinfo-request-id: 5f0c6a8e-1b2d-4c3e-9f4a-7b8c9d0e1f2a`

```json
{
  "vendor": "apache",
  "product": "log4j",
  "version": "2.14.1",
  "cve_count": 9,
  "cve_count_by_score": [
    {
      "score": 6.3,
      "cve_count": 3
    },
    {
      "score": 6.9,
      "cve_count": 2
    },
    {
      "score": 5.9,
      "cve_count": 1
    },
    {
      "score": 6.6,
      "cve_count": 1
    },
    {
      "score": 9.0,
      "cve_count": 1
    },
    {
      "score": 10.0,
      "cve_count": 1
    }
  ]
}
```

## Related Examples

- [Apache Log4j CVEs by CVSS Score](/reference/vulnerability/cvss-score-stats/examples/vendor-product/)
- [Apache Log4j 2.x by CVSS Score](/reference/vulnerability/cvss-score-stats/examples/version-startswith/)
- [Microsoft CVEs by CVSS Score](/reference/vulnerability/cvss-score-stats/examples/vendor-microsoft/)
