Known vulnerabilities in Apache Tomcat - page 2
Vendor:
Apache Foundation
Software:
Apache Tomcat
Software CPE:
cpe:2.3:a:apache_foundation:apache_tomcat:*:*:*:*:*:*:*:*
Website:
https://www.apache.org
Total vulnerabilities:
151
Public exploits:
29
Known exploited (KEV):
8
Highest CVSSv4 Score:
9.3
Breakdown by Severity Chart
10.1.59
11.0.25
9.0.121
10.1.58
11.0.24
10.1.57
9.0.120
9.0.119
11.0.23
10.1.56
10.1.55
11.0.22
9.0.118
11.0.21
10.1.54
9.0.117
10.1.53
11.0.20
9.0.116
11.0.19
10.1.52
11.0.18
10.1.51
9.0.115
11.0.17
9.0.114
11.0.16
10.1.50
11.0.15
9.0.113
10.1.49
9.0.112
11.0.14
9.1.109
11.0.13
10.1.48
9.0.111
10.1.47
11.0.12
9.0.110
10.1.46
10.1.45
11.0.11
9.0.109
10.1.44
11.0.10
9.0.108
9.0.107
11.0.9
10.1.43
11.0.8
10.1.42
9.0.106
10.1.41
9.0.105
11.0.7
9.0.104
11.0.6
10.1.40
9.0.103
10.1.39
10.1.38
9.0.102
9.0.101
10.1.37
11.0.5
11.0.4
10.1.36
9.0.100
10.1.35
9.0.99
11.0.3
9.0.98
11.0.2
10.1.34
10.1.33
10.1.32
11.0.1
9.0.97
11.0.0
10.1.31
9.0.96
10.1.30
11.0.0-M26
9.0.95
10.1.29
11.0.0-M25
9.0.94
9.0.93
10.1.28
11.0.0-M24
10.1.27
9.0.92
11.0.0-M23
10.1.26
11.0.0-M22
9.0.91
10.1.25
11.0.0-M21
9.0.90
10.1.24
9.0.89
11.0.0-M20
10.1.23
10.1.22
10.1.21
11.0.0-M19
9.0.88
8.5.100
10.1.20
9.0.87
11.0.0-M18
10.1.19
8.5.99
9.0.86
11.0.0-M17
10.1.18
8.5.98
9.0.85
11.0.0-M16
10.1.17
9.0.84
8.5.97
11.0.0-M15
10.1.16
8.5.96
11.0.0-M14
9.0.83
10.1.15
8.5.95
11.0.0-M13
9.0.82
11.0.0-M12
10.1.14
9.0.81
8.5.94
11.0.0-M11
10.1.13
9.0.80
8.5.93
8.5.92
10.1.12
9.0.79
11.0.0-M10
10.1.11
8.5.91
11.0.0-M9
9.0.78
9.0.77
11.0.0-M8
9.0.76
10.1.10
8.5.90
11.0.0-M7
10.1.9
8.5.89
9.0.75
11.0.0-M6
8.5.88
10.1.8
9.0.74
11.0.0-M5
11.0.0-M4
10.1.7
8.5.87
9.0.73
10.1.6
8.5.86
9.0.72
11.0.0-M3
8.5.85
9.0.71
10.1.5
11.0.0-M2
10.1.4
11.0.0-M1
10.1.3
9.0.70
8.5.84
10.1.2
9.0.69
8.5.83
9.0.68
10.0.27
10.1.1
10.0.26
9.0.67
10.1.0
10.0.25
9.0.66
10.1.0-M20
10.0.24
10.1.0-M19
10.1.0-M18
10.1.0-M17
10.0.23
9.0.65
8.5.82
8.0.0-RC10
5.5
5.5.36
8.5.81
8.5.80
9.0.64
10.1.0-M16
10.0.22
9.0.63
10.1.0-M15
10.0.21
8.5.79
10.1.0-M14
10.0.20
9.0.62
8.5.78
9.0.61
10.1.0-M13
10.0.19
8.5.77
10.1.0-M12
10.0.18
9.0.60
8.5.76
10.1.0-M11
10.0.17
9.0.59
8.5.75
10.1.0-M10
10.0.16
9.0.58
10.1.0-M9
10.0.15
9.0.57
8.5.74
10.0.14
10.1.0-M8
9.0.56
8.5.73
9.0.55
10.0.13
10.1.0-M7
8.6.72
8.5.72
9.0.54
10.0.12
10.1.0-M6
8.5.71
9.0.53
10.0.11
10.1.0-M5
8.5.70
10.1.0-M4
9.0.52
10.0.10
9.0.51
10.0.9
10.1.0-M3
8.5.69
9.0.50
9.0.49
10.0.8
10.1.0-M2
8.5.68
8.5.67
9.0.48
9.0.47
10.0.7
10.1.0-M1
8.5.66
9.0.46
10.0.6
7.0.109
8.5.65
9.0.45
10.0.5
10.0.4
8.5.64
9.0.44
10.0.3
8.5.63
9.0.43
10.0.2
7.0.108
8.5.62
9.0.42
10.0.1
8.5.61
9.0.41
10.0.0
7.0.107
8.5.60
9.0.40
10.0.0-M10
8.5.59
9.0.39
10.0.0-M9
7.0.106
8.5.58
9.0.38
10.0.0-M8
7.0.105
8.5.57
9.0.37
10.0.0-M7
8.5.56
9.0.36
10.0.0-M6
7.0.104
8.5.55
9.0.35
10.0.0-M5
8.5.54
9.0.34
10.0.0-M4
7.0.103
7.0.102
8.5.53
9.0.33
10.0.0-M3
7.0.101
8.5.52
9.0.32
10.0.0-M2
10.0.0-M1
7.0.100
9.0.0-M27
9.0.0-M26
9.0.0-M25
9.0.0-M24
9.0.0-M23
10.0.0.0-M1
8.5.51
9.0.31
7.0.99
8.5.50
9.0.30
7.0.98
8.5.49
8.5.48
9.0.28
9.0.29
7.0.97
8.5.47
9.0.27
8.5.46
9.0.26
9.0.25
8.5.44
8.5.45
9.0.23
9.0.24
7.0.96
7.0.95
8.5.43
9.0.22
1.2.3
1.2.17
1.2.46
1.2.43
1.2.42
1.2.41
1.2.27
1.2.23
1.2.21
1.2.16
9.0.21
9.0.20
9.0.18
9.0.17
9.0.15
9.0.3
9.0.0
8.5.42
8.5.41
8.5.39
8.5.27
8.5.26
8.5.25
8.5.15
8.5.8
8.5.7
7.0.93
7.0.92
7.0.89
7.0.83
7.0.74
9.0.19
8.5.40
7.0.94
8.5.38
8.5.37
8.5.36
8.5.35
9.0.16
9.0.14
9.0.13
7.0.91
8.5.34
8.5.33
9.0.12
9.0.11
6.0.53
6.0.52
6.0.51
6.0.50
6.0.49
7.0.90
9.0.10
9.0.8
9.0.7
9.0.6
8.5.31
8.5.30
8.5.29
8.0.52
8.0.51
7.0.88
7.0.87
7.0.86
9.0.9
8.5.32
8.5.28
8.5.24
8.0.53
8.0.50
8.0.48
8.0.46
8.0.45
8.5.22
8.5.21
8.5.20
8.5.19
8.5.18
8.5.17
8.5.16
9.0.0-M14
9.0.0-M16
9.0.0-M22
8.0.49
7.0.85
7.0.84
9.0.5
9.0.4
9.0.2
9.0.1
8.5.23
8.0.47
7.0.82
7.0.80
7.0.81
7.0.79
9.0.0-M21
9.0.0-M20
9.0.0-M19
9.0.0-M18
9.0.0-M17
7.0.78
8.0.44
8.5.14
8.5.13
8.5.12
8.5.11
8.5.10
8.0.43
8.0.42
7.0.77
7.0.76
9.0.0-M15
7.0.75
8.5.9
8.0.41
8.5.6
6.0.48
6.0.46
7.0.71
7.0.73
9.0.0-M13
9.0.0-M12
9.0.0-M11
8.0.39
8.0.38
9.0.0-M10
8.5.5
8.0.37
7.0.72
6.0.47
8.0.0.RC1
8.5.4
9.0.0-M9
9.0.0-M7
9.0.0-M5
9.0.0-M4
9.0.0-M3
9.0.0-M2
9.0.0-M1
8.5.1
8.5.0
8.0.34
8.0.33
8.0.32
8.0.31
8.0.30
8.0.29
8.0.28
8.0.27
8.0.26
8.0.25
8.0.24
8.0.23
8.0.22
8.0.21
8.0.20
8.0.19
8.0.18
8.0.17
8.0.16
8.0.15
8.0.14
8.0.13
8.0.12
8.0.11
8.0.10
8.0.9
8.0.8
8.0.7
8.0.6
8.0.5
8.0.4
8.0.3
8.0.2
8.0.1
8.0.0
7.0.68
7.0.67
7.0.66
7.0.65
7.0.64
7.0.63
7.0.62
7.0.61
7.0.60
7.0.59
7.0.58
7.0.57
7.0.56
7.0.55
7.0.54
7.0.53
7.0.52
7.0.51
7.0.50
7.0.49
7.0.48
7.0.47
7.0.46
7.0.45
7.0.44
7.0.43
7.0.42
7.0.41
7.0.40
7.0.39
7.0.38
7.0.37
7.0.36
7.0.35
7.0.34
7.0.33
7.0.32
7.0.31
7.0.30
7.0.29
7.0.28
7.0.27
7.0.26
7.0.25
7.0.24
7.0.23
7.0.22
7.0.21
7.0.20
7.0.19
7.0.18
7.0.17
7.0.16
7.0.15
7.0.14
7.0.13
7.0.12
7.0.11
7.0.10
7.0.9
7.0.8
7.0.7
7.0.6
7.0.5
7.0.4
7.0.3
7.0.2
7.0.1
7.0.0
6.0.45
6.0.44
6.0.43
6.0.42
6.0.41
6.0.40
6.0.39
6.0.38
6.0.37
6.0.36
6.0.35
6.0.34
6.0.33
6.0.32
6.0.31
6.0.30
6.0.29
6.0.28
6.0.27
6.0.26
6.0.25
6.0.24
6.0.23
6.0.22
6.0.21
6.0.20
6.0.19
6.0.18
6.0.17
6.0.16
6.0.15
6.0.14
6.0.13
6.0.12
6.0.11
6.0.10
6.0.9
6.0.8
6.0.7
6.0.6
6.0.5
6.0.4
6.0.3
6.0.2
6.0.1
6.0.0
9.0.0-M8
9.0.0-M6
8.5.3
8.5.2
8.0.36
8.0.35
7.0.70
7.0.69
Vulnerabilities (151)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU131177 - Improper Access Control CVE-2026-43515 |
CWE-284 | Medium | 9.0.118, 10.1.55, 11.0.22 | 12.05.2026 |
SB2026051281 SB2026051592 SB2026060605 and 21 more |
||
| #VU131178 - Information Exposure Through Timing Discrepancy CVE-2026-43514 |
CWE-208 | Low | 9.0.118, 10.1.55, 11.0.22 | 12.05.2026 |
SB2026051281 SB2026051592 SB2026060851 and 13 more |
||
| #VU131179 - Improper Handling of Case Sensitivity CVE-2026-43513 |
CWE-178 | Medium | 9.0.118, 10.1.55, 11.0.22 | 12.05.2026 |
SB2026051281 SB2026051592 SB2026060605 and 19 more |
||
| #VU131180 - Improper Authentication CVE-2026-43512 |
CWE-287 | Medium | 9.0.118, 10.1.55, 11.0.22 | 12.05.2026 |
SB2026051281 SB2026051592 SB2026052607 and 21 more |
||
| #VU131181 - Exposure of sensitive information to an unauthorized actor CVE-2026-42498 |
CWE-200 | Low | 9.0.118, 10.1.55, 11.0.22 | 12.05.2026 |
SB2026051281 SB2026051592 SB2026052607 and 18 more |
||
| #VU131182 - Improper input validation CVE-2026-41293 |
CWE-20 | Medium | 9.0.118, 10.1.55, 11.0.22 | 12.05.2026 |
SB2026051281 SB2026051592 SB2026052607 and 21 more |
||
| #VU131183 - Resource exhaustion CVE-2026-41284 |
CWE-400 | Medium | 9.0.118, 10.1.55, 11.0.22 | 12.05.2026 |
SB2026051281 SB2026051592 SB2026052607 and 21 more |
||
| #VU125747 - Improper Encoding or Escaping of Output CVE-2026-34483 |
CWE-116 | Medium | 9.0.117, 10.1.54, 11.0.21 | 09.04.2026 |
SB20260409110 SB20260417131 SB20260422214 and 19 more |
||
| #VU125744 - Improper Certificate Validation CVE-2026-34500 |
CWE-295 | Low | 9.0.117, 10.1.54, 11.0.21 | 09.04.2026 |
SB20260409110 SB20260417131 SB20260422214 and 13 more |
||
| #VU125745 - Information Exposure Through Log Files CVE-2026-34487 |
CWE-532 | Medium | 9.0.117, 10.1.54, 11.0.21 | 09.04.2026 |
SB20260409110 SB20260417131 SB20260422214 and 20 more |
||
| #VU125746 - Protection Mechanism Failure CVE-2026-34486 |
CWE-693 | Medium | 9.0.117, 10.1.54, 11.0.21 | 09.04.2026 |
SB20260409110 SB20260417131 SB20260422214 and 14 more |
||
| #VU125743 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') CVE-2026-24880 |
CWE-444 | Medium | 9.0.116, 10.1.53, 11.0.20 | 09.04.2026 |
SB20260409109 SB20260417131 SB20260422214 and 18 more |
||
| #VU125740 - Improper Certificate Validation CVE-2026-29145 |
CWE-295 | Low | 9.0.116, 10.1.53, 11.0.20 | 09.04.2026 |
SB20260409109 SB20260417131 SB20260422214 and 17 more |
||
| #VU125741 - Configuration CVE-2026-29129 |
CWE-16 | Medium | 9.0.116, 10.1.53, 11.0.20 | 09.04.2026 |
SB20260409109 SB20260417131 SB20260422214 and 12 more |
||
| #VU125742 - URL Redirection to Untrusted Site ('Open Redirect') CVE-2026-25854 |
CWE-601 | Low | 9.0.116, 10.1.53, 11.0.20 | 09.04.2026 |
SB20260409109 SB2026041565 SB20260417131 and 14 more |
||
| #VU125738 - Improper input validation CVE-2026-32990 |
CWE-20 | Medium | 9.0.116, 10.1.53, 11.0.20 | 09.04.2026 |
SB20260409109 SB20260417131 SB2026042329 and 9 more |
||
| #VU125739 - Use of a Broken or Risky Cryptographic Algorithm CVE-2026-29146 |
CWE-327 | Medium | 9.0.116, 10.1.53, 11.0.20 | 09.04.2026 |
SB20260409109 SB20260417131 SB20260422214 and 28 more |
||
| #VU122999 - Improper Authorization CVE-2026-24734 |
CWE-285 | Medium | 9.0.115, 10.1.52, 11.0.18 | 17.02.2026 |
SB2026021766 SB2026030536 SB2026031245 and 24 more |
||
| #VU122998 - Improper Authorization CVE-2025-66614 |
CWE-285 | High | 9.0.113, 10.1.50, 11.0.15 | 17.02.2026 |
SB2026021765 SB2026031245 SB2026031361 and 16 more |
||
| #VU122997 - Protection Mechanism Failure CVE-2026-24733 |
CWE-693 | Low | 9.0.113, 10.1.50, 11.0.15 | 17.02.2026 |
SB2026021765 SB2026031245 SB2026031361 and 9 more |
Showing elements 21 - 40 out of 151