| CVE-2023-44487 |
high |
7.5 |
9.0 |
3y ago |
Moderate: nginx:1.22 security update |
+12 |
| CVE-2025-46701 |
high |
— |
8.0 |
10d ago |
Apache Tomcat - CGI security constraint bypass |
+1 |
| CVE-2026-29129 |
high |
— |
8.0 |
2mo ago |
Apache Tomcat: Configured cipher preference order not preserved |
|
| CVE-2026-24880 |
high |
— |
8.0 |
2mo ago |
Apache Tomcat has an HTTP Request/Response Smuggling vulnerability |
|
| CVE-2025-31651 |
high |
— |
8.0 |
6mo ago |
Apache Tomcat Rewrite rule bypass |
+1 |
| CVE-2025-53506 |
high |
— |
8.0 |
9mo ago |
Important: tomcat security update |
+1 |
| CVE-2025-52520 |
high |
— |
8.0 |
9mo ago |
Apache Tomcat Catalina is vulnerable to DoS attack through bypassing of size limits |
+1 |
| CVE-2025-49125 |
high |
— |
8.0 |
9mo ago |
Apache Tomcat - Security constraint bypass for pre/post-resources |
+2 |
| CVE-2025-48988 |
high |
— |
8.0 |
9mo ago |
Apache Tomcat - DoS in multipart upload |
+2 |
| CVE-2025-31650 |
high |
— |
8.0 |
11mo ago |
Apache Tomcat Denial of Service via invalid HTTP priority header |
+2 |
| CVE-2024-56337 |
high |
— |
8.0 |
11mo ago |
Apache Tomcat Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability |
+1 |
| CVE-2024-34750 |
high |
— |
8.0 |
2y ago |
Apache Tomcat - Denial of Service |
+1 |
| CVE-2024-24549 |
high |
— |
8.0 |
2y ago |
Apache Tomcat Denial of Service due to improper input validation vulnerability for HTTP/2 requests |
+1 |
| CVE-2023-46589 |
high |
— |
8.0 |
2y ago |
Apache Tomcat Improper Input Validation vulnerability |
+1 |
| CVE-2021-24122 |
high |
— |
8.0 |
5y ago |
Information Disclosure in Apache Tomcat |
|
| CVE-2019-0199 |
high |
— |
8.0 |
6y ago |
Apache Tomcat Denial of Service vulnerability |
|
| CVE-2020-9484 |
high |
— |
8.0 |
6y ago |
Potential remote code execution in Apache Tomcat |
|
| CVE-2018-8037 |
high |
— |
8.0 |
8y ago |
Apache Tomcat Race Condition vulnerability |
|
| CVE-2018-8034 |
high |
— |
8.0 |
8y ago |
The host name verification missing in Apache Tomcat |
|
| CVE-2018-8014 |
high |
— |
8.0 |
8y ago |
The defaults settings for the CORS filter provided in Apache Tomcat are insecure and enable 'supportsCredentials' for all origins |
|
| CVE-2018-11784 |
high |
— |
8.0 |
8y ago |
Apache Tomcat Open Redirect vulnerability |
|
| CVE-2026-43513 |
high |
7.5 |
7.5 |
16d ago |
Apache Tomcat: LockOutRealm treats user names as case-sensitive |
|
| CVE-2026-41284 |
high |
7.5 |
7.5 |
16d ago |
Apache Tomcat: Unbounded read in WebDAV LOCK and PROPFIND handling |
|
| CVE-2025-55752 |
high |
7.5 |
7.5 |
6mo ago |
Apache Tomcat Vulnerable to Relative Path Traversal |
+2 |
| CVE-2025-48989 |
high |
7.5 |
7.5 |
9mo ago |
Apache Tomcat Improper Resource Shutdown or Release vulnerability |
+2 |
| CVE-2026-42498 |
high |
7.3 |
7.3 |
16d ago |
Apache Tomcat - WebSocket authentication header exposure |
|
| CVE-2025-24813 |
medium |
— |
7.0 |
1y ago |
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT |
+1 |
| CVE-2020-1938 |
medium |
— |
7.0 |
6y ago |
Improper Privilege Management in Tomcat |
|
| CVE-2024-50379 |
medium |
— |
5.5 |
11mo ago |
Apache Tomcat Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability |
+1 |
| CVE-2023-42795 |
medium |
— |
5.5 |
2y ago |
Moderate: tomcat security update |
+1 |
| CVE-2023-45648 |
medium |
— |
5.5 |
2y ago |
Moderate: tomcat security update |
+1 |
| CVE-2023-41080 |
medium |
— |
5.5 |
2y ago |
Moderate: tomcat security update |
+1 |
| CVE-2023-24998 |
medium |
— |
5.5 |
3y ago |
Moderate: tomcat security and bug fix update |
+2 |
| CVE-2023-28709 |
medium |
— |
5.5 |
3y ago |
Moderate: tomcat security and bug fix update |
+1 |
| CVE-2020-1935 |
medium |
— |
5.5 |
6y ago |
Potential HTTP request smuggling in Apache Tomcat |
|
| CVE-2025-61795 |
medium |
5.3 |
5.3 |
7mo ago |
Apache Tomcat Vulnerable to Improper Resource Shutdown or Release |
|
| CVE-2014-0095 |
medium |
— |
5.0 |
12y ago |
Denial of service in Apache Tomcat |
|