# Apache Log4j 2.x by CVSS Score

The CVSS score distribution of the CVEs that affect any Log4j 2 release, with version__startswith.

Source: https://docs.deepinfo.com/reference/vulnerability/cvss-score-stats/examples/version-startswith/

Last updated: 2026-09-24

---
`GET https://api.deepinfo.com/v1/explore/vulnerability-insight/vulnerability-stats-by-cvss-scores?vendor=apache&product=log4j&version__startswith=2.`

The CVSS score distribution of the CVEs that affect any Log4j 2 release, with version__startswith.

Example 5 of 5 · [CVSS Score Stats Examples](/reference/vulnerability/cvss-score-stats/examples/) · endpoint: [CVSS Score Stats](/reference/vulnerability/cvss-score-stats/)

Tags: `param` `vendor` · `param` `product` · `param` `version__startswith` · `value` `apache` · `value` `log4j` · `value` `2.`

`version__startswith` keeps the CVEs that affect any release whose version starts with the given text.

## What to Notice

`cve_count` is 12 across 8 scores.

## Request

| Parameter | In | Value |
|---|---|---|
| `vendor` | query | `apache` |
| `product` | query | `log4j` |
| `version__startswith` | query | `2.` |

```bash
curl 'https://api.deepinfo.com/v1/explore/vulnerability-insight/vulnerability-stats-by-cvss-scores?vendor=apache&product=log4j&version__startswith=2.' \
  -H 'apikey: YOUR_API_KEY' \
  -H 'Accept: application/json'
```

## Response

### 200 · OK

`Content-Type: application/json` · `ratelimit-limit: 1` · `ratelimit-remaining: 0` · `ratelimit-reset: 1` · `x-ratelimit-limit-second: 1` · `x-ratelimit-remaining-second: 0` · `deepinfo-request-id: 5f0c6a8e-1b2d-4c3e-9f4a-7b8c9d0e1f2a`

```json
{
  "vendor": "apache",
  "product": "log4j",
  "version": "2.",
  "cve_count": 12,
  "cve_count_by_score": [
    {
      "score": 6.3,
      "cve_count": 3
    },
    {
      "score": 6.9,
      "cve_count": 3
    },
    {
      "score": 3.7,
      "cve_count": 1
    },
    {
      "score": 5.9,
      "cve_count": 1
    },
    {
      "score": 6.6,
      "cve_count": 1
    },
    {
      "score": 9.0,
      "cve_count": 1
    },
    {
      "score": 9.8,
      "cve_count": 1
    },
    {
      "score": 10.0,
      "cve_count": 1
    }
  ]
}
```

## Related Examples

- [Apache Log4j 2.14.1 by CVSS Score](/reference/vulnerability/cvss-score-stats/examples/vendor-product-version/)
- [Apache Log4j CVEs by CVSS Score](/reference/vulnerability/cvss-score-stats/examples/vendor-product/)
- [Microsoft CVEs by CVSS Score](/reference/vulnerability/cvss-score-stats/examples/vendor-microsoft/)
