Known vulnerabilities in Apache Tomcat 9.0.23 - page 2
Vendor:
Apache Foundation
Software:
Apache Tomcat
Version:
9.0.23
Software CPE:
cpe:2.3:a:apache_foundation:apache_tomcat:*:*:*:*:*:*:*:*
Website:
https://www.apache.org
Total vulnerabilities:
94
Public exploits:
22
Known exploited (KEV):
4
Highest CVSSv4 Score:
9.3
Vulnerabilities by Severity
10.1.59
11.0.25
9.0.121
10.1.58
11.0.24
10.1.57
9.0.120
9.0.119
11.0.23
10.1.56
10.1.55
11.0.22
9.0.118
11.0.21
10.1.54
9.0.117
10.1.53
11.0.20
9.0.116
11.0.19
10.1.52
11.0.18
10.1.51
9.0.115
11.0.17
9.0.114
11.0.16
10.1.50
11.0.15
9.0.113
10.1.49
9.0.112
11.0.14
9.1.109
11.0.13
10.1.48
9.0.111
10.1.47
11.0.12
9.0.110
10.1.46
10.1.45
11.0.11
9.0.109
10.1.44
11.0.10
9.0.108
9.0.107
11.0.9
10.1.43
11.0.8
10.1.42
9.0.106
10.1.41
9.0.105
11.0.7
9.0.104
11.0.6
10.1.40
9.0.103
10.1.39
10.1.38
9.0.102
9.0.101
10.1.37
11.0.5
11.0.4
10.1.36
9.0.100
10.1.35
9.0.99
11.0.3
9.0.98
11.0.2
10.1.34
10.1.33
10.1.32
11.0.1
9.0.97
11.0.0
10.1.31
9.0.96
10.1.30
11.0.0-M26
9.0.95
10.1.29
11.0.0-M25
9.0.94
9.0.93
10.1.28
11.0.0-M24
10.1.27
9.0.92
11.0.0-M23
10.1.26
11.0.0-M22
9.0.91
10.1.25
11.0.0-M21
9.0.90
10.1.24
9.0.89
11.0.0-M20
10.1.23
10.1.22
10.1.21
11.0.0-M19
9.0.88
8.5.100
10.1.20
9.0.87
11.0.0-M18
10.1.19
8.5.99
9.0.86
11.0.0-M17
10.1.18
8.5.98
9.0.85
11.0.0-M16
10.1.17
9.0.84
8.5.97
11.0.0-M15
10.1.16
8.5.96
11.0.0-M14
9.0.83
10.1.15
8.5.95
11.0.0-M13
9.0.82
11.0.0-M12
10.1.14
9.0.81
8.5.94
11.0.0-M11
10.1.13
9.0.80
8.5.93
8.5.92
10.1.12
9.0.79
11.0.0-M10
10.1.11
8.5.91
11.0.0-M9
9.0.78
9.0.77
11.0.0-M8
9.0.76
10.1.10
8.5.90
11.0.0-M7
10.1.9
8.5.89
9.0.75
11.0.0-M6
8.5.88
10.1.8
9.0.74
11.0.0-M5
11.0.0-M4
10.1.7
8.5.87
9.0.73
10.1.6
8.5.86
9.0.72
11.0.0-M3
8.5.85
9.0.71
10.1.5
11.0.0-M2
10.1.4
11.0.0-M1
10.1.3
9.0.70
8.5.84
10.1.2
9.0.69
8.5.83
9.0.68
10.0.27
10.1.1
10.0.26
9.0.67
10.1.0
10.0.25
9.0.66
10.1.0-M20
10.0.24
10.1.0-M19
10.1.0-M18
10.1.0-M17
10.0.23
9.0.65
8.5.82
8.0.0-RC10
5.5
5.5.36
8.5.81
8.5.80
9.0.64
10.1.0-M16
10.0.22
9.0.63
10.1.0-M15
10.0.21
8.5.79
10.1.0-M14
10.0.20
9.0.62
8.5.78
9.0.61
10.1.0-M13
10.0.19
8.5.77
10.1.0-M12
10.0.18
9.0.60
8.5.76
10.1.0-M11
10.0.17
9.0.59
8.5.75
10.1.0-M10
10.0.16
9.0.58
10.1.0-M9
10.0.15
9.0.57
8.5.74
10.0.14
10.1.0-M8
9.0.56
8.5.73
9.0.55
10.0.13
10.1.0-M7
8.6.72
8.5.72
9.0.54
10.0.12
10.1.0-M6
8.5.71
9.0.53
10.0.11
10.1.0-M5
8.5.70
10.1.0-M4
9.0.52
10.0.10
9.0.51
10.0.9
10.1.0-M3
8.5.69
9.0.50
9.0.49
10.0.8
10.1.0-M2
8.5.68
8.5.67
9.0.48
9.0.47
10.0.7
10.1.0-M1
8.5.66
9.0.46
10.0.6
7.0.109
8.5.65
9.0.45
10.0.5
10.0.4
8.5.64
9.0.44
10.0.3
8.5.63
9.0.43
10.0.2
7.0.108
8.5.62
9.0.42
10.0.1
8.5.61
9.0.41
10.0.0
7.0.107
8.5.60
9.0.40
10.0.0-M10
8.5.59
9.0.39
10.0.0-M9
7.0.106
8.5.58
9.0.38
10.0.0-M8
7.0.105
8.5.57
9.0.37
10.0.0-M7
8.5.56
9.0.36
10.0.0-M6
7.0.104
8.5.55
9.0.35
10.0.0-M5
8.5.54
9.0.34
10.0.0-M4
7.0.103
7.0.102
8.5.53
9.0.33
10.0.0-M3
7.0.101
8.5.52
9.0.32
10.0.0-M2
10.0.0-M1
7.0.100
9.0.0-M27
9.0.0-M26
9.0.0-M25
9.0.0-M24
9.0.0-M23
10.0.0.0-M1
8.5.51
9.0.31
7.0.99
8.5.50
9.0.30
7.0.98
8.5.49
8.5.48
9.0.28
9.0.29
7.0.97
8.5.47
9.0.27
8.5.46
9.0.26
9.0.25
8.5.44
8.5.45
9.0.23
9.0.24
7.0.96
7.0.95
8.5.43
9.0.22
1.2.3
1.2.17
1.2.46
1.2.43
1.2.42
1.2.41
1.2.27
1.2.23
1.2.21
1.2.16
9.0.21
9.0.20
9.0.18
9.0.17
9.0.15
9.0.3
9.0.0
8.5.42
8.5.41
8.5.39
8.5.27
8.5.26
8.5.25
8.5.15
8.5.8
8.5.7
7.0.93
7.0.92
7.0.89
7.0.83
7.0.74
9.0.19
8.5.40
7.0.94
8.5.38
8.5.37
8.5.36
8.5.35
9.0.16
9.0.14
9.0.13
7.0.91
8.5.34
8.5.33
9.0.12
9.0.11
6.0.53
6.0.52
6.0.51
6.0.50
6.0.49
7.0.90
9.0.10
9.0.8
9.0.7
9.0.6
8.5.31
8.5.30
8.5.29
8.0.52
8.0.51
7.0.88
7.0.87
7.0.86
9.0.9
8.5.32
8.5.28
8.5.24
8.0.53
8.0.50
8.0.48
8.0.46
8.0.45
8.5.22
8.5.21
8.5.20
8.5.19
8.5.18
8.5.17
8.5.16
9.0.0-M14
9.0.0-M16
9.0.0-M22
8.0.49
7.0.85
7.0.84
9.0.5
9.0.4
9.0.2
9.0.1
8.5.23
8.0.47
7.0.82
7.0.80
7.0.81
7.0.79
9.0.0-M21
9.0.0-M20
9.0.0-M19
9.0.0-M18
9.0.0-M17
7.0.78
8.0.44
8.5.14
8.5.13
8.5.12
8.5.11
8.5.10
8.0.43
8.0.42
7.0.77
7.0.76
9.0.0-M15
7.0.75
8.5.9
8.0.41
8.5.6
6.0.48
6.0.46
7.0.71
7.0.73
9.0.0-M13
9.0.0-M12
9.0.0-M11
8.0.39
8.0.38
9.0.0-M10
8.5.5
8.0.37
7.0.72
6.0.47
8.0.0.RC1
8.5.4
9.0.0-M9
9.0.0-M7
9.0.0-M5
9.0.0-M4
9.0.0-M3
9.0.0-M2
9.0.0-M1
8.5.1
8.5.0
8.0.34
8.0.33
8.0.32
8.0.31
8.0.30
8.0.29
8.0.28
8.0.27
8.0.26
8.0.25
8.0.24
8.0.23
8.0.22
8.0.21
8.0.20
8.0.19
8.0.18
8.0.17
8.0.16
8.0.15
8.0.14
8.0.13
8.0.12
8.0.11
8.0.10
8.0.9
8.0.8
8.0.7
8.0.6
8.0.5
8.0.4
8.0.3
8.0.2
8.0.1
8.0.0
7.0.68
7.0.67
7.0.66
7.0.65
7.0.64
7.0.63
7.0.62
7.0.61
7.0.60
7.0.59
7.0.58
7.0.57
7.0.56
7.0.55
7.0.54
7.0.53
7.0.52
7.0.51
7.0.50
7.0.49
7.0.48
7.0.47
7.0.46
7.0.45
7.0.44
7.0.43
7.0.42
7.0.41
7.0.40
7.0.39
7.0.38
7.0.37
7.0.36
7.0.35
7.0.34
7.0.33
7.0.32
7.0.31
7.0.30
7.0.29
7.0.28
7.0.27
7.0.26
7.0.25
7.0.24
7.0.23
7.0.22
7.0.21
7.0.20
7.0.19
7.0.18
7.0.17
7.0.16
7.0.15
7.0.14
7.0.13
7.0.12
7.0.11
7.0.10
7.0.9
7.0.8
7.0.7
7.0.6
7.0.5
7.0.4
7.0.3
7.0.2
7.0.1
7.0.0
6.0.45
6.0.44
6.0.43
6.0.42
6.0.41
6.0.40
6.0.39
6.0.38
6.0.37
6.0.36
6.0.35
6.0.34
6.0.33
6.0.32
6.0.31
6.0.30
6.0.29
6.0.28
6.0.27
6.0.26
6.0.25
6.0.24
6.0.23
6.0.22
6.0.21
6.0.20
6.0.19
6.0.18
6.0.17
6.0.16
6.0.15
6.0.14
6.0.13
6.0.12
6.0.11
6.0.10
6.0.9
6.0.8
6.0.7
6.0.6
6.0.5
6.0.4
6.0.3
6.0.2
6.0.1
6.0.0
9.0.0-M8
9.0.0-M6
8.5.3
8.5.2
8.0.36
8.0.35
7.0.70
7.0.69
Vulnerabilities (94)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU131177 - Improper Access Control CVE-2026-43515 |
CWE-284 | Medium | 9.0.118, 10.1.55, 11.0.22 | 12.05.2026 |
SB2026051281 SB2026051592 SB2026060605 and 22 more |
||
| #VU131178 - Information Exposure Through Timing Discrepancy CVE-2026-43514 |
CWE-208 | Low | 9.0.118, 10.1.55, 11.0.22 | 12.05.2026 |
SB2026051281 SB2026051592 SB2026060851 and 14 more |
||
| #VU131183 - Resource exhaustion CVE-2026-41284 |
CWE-400 | Medium | 9.0.118, 10.1.55, 11.0.22 | 12.05.2026 |
SB2026051281 SB2026051592 SB2026052607 and 23 more |
||
| #VU125747 - Improper Encoding or Escaping of Output CVE-2026-34483 |
CWE-116 | Medium | 9.0.117, 10.1.54, 11.0.21 | 09.04.2026 |
SB20260409110 SB20260417131 SB20260422214 and 20 more |
||
| #VU125744 - Improper Certificate Validation CVE-2026-34500 |
CWE-295 | Low | 9.0.117, 10.1.54, 11.0.21 | 09.04.2026 |
SB20260409110 SB20260417131 SB20260422214 and 14 more |
||
| #VU125745 - Information Exposure Through Log Files CVE-2026-34487 |
CWE-532 | Medium | 9.0.117, 10.1.54, 11.0.21 | 09.04.2026 |
SB20260409110 SB20260417131 SB20260422214 and 21 more |
||
| #VU125746 - Protection Mechanism Failure CVE-2026-34486 |
CWE-693 | Medium | 9.0.117, 10.1.54, 11.0.21 | 09.04.2026 |
SB20260409110 SB20260417131 SB20260422214 and 14 more |
||
| #VU125743 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') CVE-2026-24880 |
CWE-444 | Medium | 9.0.116, 10.1.53, 11.0.20 | 09.04.2026 |
SB20260409109 SB20260417131 SB20260422214 and 19 more |
||
| #VU125740 - Improper Certificate Validation CVE-2026-29145 |
CWE-295 | Low | 9.0.116, 10.1.53, 11.0.20 | 09.04.2026 |
SB20260409109 SB20260417131 SB20260422214 and 18 more |
||
| #VU125741 - Configuration CVE-2026-29129 |
CWE-16 | Medium | 9.0.116, 10.1.53, 11.0.20 | 09.04.2026 |
SB20260409109 SB20260417131 SB20260422214 and 13 more |
||
| #VU125742 - URL Redirection to Untrusted Site ('Open Redirect') CVE-2026-25854 |
CWE-601 | Low | 9.0.116, 10.1.53, 11.0.20 | 09.04.2026 |
SB20260409109 SB2026041565 SB20260417131 and 15 more |
||
| #VU125738 - Improper input validation CVE-2026-32990 |
CWE-20 | Medium | 9.0.116, 10.1.53, 11.0.20 | 09.04.2026 |
SB20260409109 SB20260417131 SB2026042329 and 10 more |
||
| #VU125739 - Use of a Broken or Risky Cryptographic Algorithm CVE-2026-29146 |
CWE-327 | Medium | 9.0.116, 10.1.53, 11.0.20 | 09.04.2026 |
SB20260409109 SB20260417131 SB20260422214 and 29 more |
||
| #VU122999 - Improper Authorization CVE-2026-24734 |
CWE-285 | Medium | 9.0.115, 10.1.52, 11.0.18 | 17.02.2026 |
SB2026021766 SB2026030536 SB2026031245 and 27 more |
||
| #VU122998 - Improper Authorization CVE-2025-66614 |
CWE-285 | High | 9.0.113, 10.1.50, 11.0.15 | 17.02.2026 |
SB2026021765 SB2026031245 SB2026031361 and 18 more |
||
| #VU122997 - Protection Mechanism Failure CVE-2026-24733 |
CWE-693 | Low | 9.0.113, 10.1.50, 11.0.15 | 17.02.2026 |
SB2026021765 SB2026031245 SB2026031361 and 10 more |
||
| #VU117682 - Resource exhaustion CVE-2025-61795 |
CWE-400 | Medium | 9.0.110, 10.1.47, 11.0.12 | 27.10.2025 |
SB2025102749 SB20251031122 SB20251031123 and 39 more |
||
| #VU117681 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') CVE-2025-55752 |
CWE-22 | High | 9.0.109, 10.1.45, 11.0.11 | 27.10.2025 |
SB2025102748 SB20251031122 SB20251031123 and 43 more |
||
| #VU117680 - Improper Output Neutralization for Logs CVE-2025-55754 |
CWE-117 | Low | 9.0.109, 10.1.45, 11.0.11 | 27.10.2025 |
SB2025102748 SB20251031122 SB20251031123 and 27 more |
||
| #VU114443 - Session Fixation CVE-2025-55668 |
CWE-384 | Medium | 9.0.106, 10.1.42, 11.0.8 | 26.08.2025 |
SB2025082650 SB2025082651 SB2025090566 and 15 more |
Showing elements 21 - 40 out of 94