Package impact

java Maven / org.apache.tomcat:tomcat-catalina

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Published Description Impact
CVE-2016-5388 high 8.1 8.1 10y ago Improper Access Control in Apache Tomcat suseredhatdebianjava+2
CVE-2025-55668 high 8.0 10d ago Session Fixation vulnerability in Apache Tomcat via rewrite valve. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.7, from 10.1.0-M1 through 10.1.41, from 9.0.0.M1 through 9.0.105. Old… redhatsusedebianjava
CVE-2025-46701 high 8.0 10d ago Apache Tomcat - CGI security constraint bypass archredhatsusedebian+1
CVE-2025-31651 high 8.0 6mo ago Apache Tomcat Rewrite rule bypass rockylinuxredhatsusedebian+1
CVE-2025-52520 high 8.0 9mo ago Apache Tomcat Catalina is vulnerable to DoS attack through bypassing of size limits redhatrockylinuxsusedebian+1
CVE-2025-49125 high 8.0 9mo ago Apache Tomcat - Security constraint bypass for pre/post-resources archredhatrockylinuxsuse+2
CVE-2025-48988 high 8.0 9mo ago Apache Tomcat - DoS in multipart upload archredhatrockylinuxsuse+2
CVE-2024-56337 high 8.0 11mo ago Apache Tomcat Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability redhatrockylinuxsusedebian+1
CVE-2023-46589 high 8.0 2y ago Apache Tomcat Improper Input Validation vulnerability redhatrockylinuxsusedebian+1
CVE-2020-9484 high 8.0 6y ago Potential remote code execution in Apache Tomcat archsusedebianjava
CVE-2026-43513 high 7.5 7.5 16d ago Apache Tomcat: LockOutRealm treats user names as case-sensitive susedebianjavaapache
CVE-2026-41284 high 7.5 7.5 16d ago Apache Tomcat: Unbounded read in WebDAV LOCK and PROPFIND handling susedebianjavaapache
CVE-2025-55752 high 7.5 7.5 6mo ago Apache Tomcat Vulnerable to Relative Path Traversal rockylinuxredhatsusedebian+2
CVE-2017-12616 high 7.5 7.5 9y ago Exposure of Sensitive Information to an Unauthorized Actor in Apache Tomcat susejavaapache
CVE-2026-42498 high 7.3 7.3 16d ago Apache Tomcat - WebSocket authentication header exposure susedebianjavaapache
CVE-2025-24813 medium 7.0 1y ago Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT redhatrockylinuxsusedebian+1
CVE-2024-50379 medium 5.5 11mo ago Apache Tomcat Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability redhatrockylinuxsusedebian+1
CVE-2023-28708 medium 5.5 3y ago Moderate: tomcat security and bug fix update redhatsusedebianalmalinux+1
CVE-2025-61795 medium 5.3 5.3 7mo ago Apache Tomcat Vulnerable to Improper Resource Shutdown or Release susedebianjavaapache
CVE-2012-5886 medium 5.0 14y ago Improper Authentication in Apache Tomcat javaapache
CVE-2014-0119 medium 4.3 12y ago Missing XML Validation in Apache Tomcat susejavaapache
CVE-2014-0096 medium 4.3 12y ago Improper Input Validation in Apache Tomcat javaapache
CVE-2017-12617 unknown 1.5 4y ago Unrestricted Upload of File with Dangerous Type Apache Tomcat susejava
CVE-2016-8735 unknown 1.5 4y ago Apache Tomcat Improper Access Control vulnerability susedebianjava
CVE-2026-34487 unknown 2mo ago Apache Tomcat vulnerable to Insertion of Sensitive Information into Log File susedebianjavagcp
CVE-2026-34483 unknown 2mo ago Apache Tomcat has an Improper Encoding or Escaping of Output vulnerability in the JsonAccessLogValve susedebianjava
CVE-2026-25854 unknown 2mo ago Apache Tomcat has an Open Redirect vulnerability susedebianjava
CVE-2026-24733 unknown 3mo ago Apache Tomcat - Security constraint bypass with HTTP/0.9 susedebianjava
CVE-2025-66614 unknown 3mo ago Apache Tomcat - Client certificate verification bypass susedebianjava
CVE-2025-49124 unknown 1y ago Apache Tomcat installer for Windows has an untrusted search path vulnerability susedebianjava
CVE-2024-52316 unknown 2y ago Apache Tomcat - Authentication Bypass susedebianjava
CVE-2022-45143 unknown 3y ago Apache Tomcat improperly escapes input from JsonErrorReportValve susedebianjava