Known vulnerabilities in tomcat-webapps - page 2
Vendor:
SUSE
Software:
tomcat-webapps
Software CPE:
cpe:2.3:o:suse:tomcat-webapps:*:*:*:*:*:suse_linux:*:*
Website:
https://www.suse.com/
Total vulnerabilities:
69
Public exploits:
13
Known exploited (KEV):
2
Highest CVSSv4 Score:
9.2
Breakdown by Severity Chart
9.0.120-3.174.1
9.0.120-150200.114.1
9.0.119-3.169.1
9.0.119-150200.111.1
9.0.118-150200.108.1
9.0.118-3.166.1
9.0.117-150200.105.1
9.0.117-3.163.2
9.0.115-3.160.1
9.0.115-150200.102.1
9.0.36-3.156.1
9.0.111-150200.99.1
9.0.36-3.153.2
9.0.111-150200.96.1
9.0.108-150200.91.1
9.0.36-3.148.1
9.0.36-3.142.1
9.0.104-150200.81.1
9.0.102-150200.78.1
9.0.36-3.139.1
9.0.36-3.136.1
9.0.98-150200.74.1
9.0.97-150200.71.1
9.0.36-3.133.1
9.0.36-3.130.1
9.0.36-3.127.1
9.0.91-150200.68.1
9.0.36-3.124.1
9.0.85-150200.57.1
9.0.36-3.118.1
9.0.36-150100.4.105.1
9.0.36-150100.4.98.1
9.0.36-3.111.1
9.0.82-150200.46.1
9.0.36-3.108.1
9.0.36-150100.4.93.1
9.0.75-150200.41.1
9.0.36-3.105.1
8.0.53-29.66.1
9.0.43-150200.38.1
9.0.43-150200.35.1
9.0.36-3.102.1
9.0.36-150100.4.90.1
9.0.36-150200.22.1
8.0.53-29.54.1
9.0.36-150100.4.76.1
9.0.36-150000.3.96.1
9.0.36-3.87.1
9.0.36-4.70.1
8.0.53-29.46.1
9.0.36-3.79.1
9.0.36-3.64.1
8.0.53-29.63.1
9.0.36-3.99.1
9.0.36-150100.4.87.1
9.0.36-3.93.1
9.0.36-150100.4.81.1
9.0.36-150000.3.101.2
8.0.53-29.57.1
9.0.36-3.90.1
9.0.36-13.1
9.0.36-3.84.1
9.0.36-4.63.1
9.0.36-3.71.1
9.0.36-4.58.1
9.0.36-3.24.1
Vulnerabilities (69)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU125747 - Improper Encoding or Escaping of Output CVE-2026-34483 |
CWE-116 | Medium | 9.0.117-3.163.2, 9.0.117-150200.105.1 | 09.04.2026 |
SB20260409110 SB20260417131 SB20260422214 and 19 more |
||
| #VU125744 - Improper Certificate Validation CVE-2026-34500 |
CWE-295 | Low | 9.0.117-3.163.2, 9.0.117-150200.105.1 | 09.04.2026 |
SB20260409110 SB20260417131 SB20260422214 and 13 more |
||
| #VU125745 - Information Exposure Through Log Files CVE-2026-34487 |
CWE-532 | Medium | 9.0.117-3.163.2, 9.0.117-150200.105.1 | 09.04.2026 |
SB20260409110 SB20260417131 SB20260422214 and 20 more |
||
| #VU125746 - Protection Mechanism Failure CVE-2026-34486 |
CWE-693 | Medium | 9.0.117-3.163.2, 9.0.117-150200.105.1 | 09.04.2026 |
SB20260409110 SB20260417131 SB20260422214 and 14 more |
||
| #VU125739 - Use of a Broken or Risky Cryptographic Algorithm CVE-2026-29146 |
CWE-327 | Medium | 9.0.117-3.163.2, 9.0.117-150200.105.1 | 09.04.2026 |
SB20260409109 SB20260417131 SB20260422214 and 28 more |
||
| #VU122999 - Improper Authorization CVE-2026-24734 |
CWE-285 | Medium | 9.0.115-150200.102.1 | 17.02.2026 |
SB2026021766 SB2026030536 SB2026031245 and 24 more |
||
| #VU122998 - Improper Authorization CVE-2025-66614 |
CWE-285 | High | 9.0.115-150200.102.1, 9.0.117-3.163.2, 9.0.117-150200.105.1 | 17.02.2026 |
SB2026021765 SB2026031245 SB2026031361 and 16 more |
||
| #VU122997 - Protection Mechanism Failure CVE-2026-24733 |
CWE-693 | Low | 9.0.36-3.156.1, 9.0.115-150200.102.1 | 17.02.2026 |
SB2026021765 SB2026031245 SB2026031361 and 9 more |
||
| #VU117682 - Resource exhaustion CVE-2025-61795 |
CWE-400 | Medium | 9.0.36-3.153.2, 9.0.111-150200.96.1 | 27.10.2025 |
SB2025102749 SB20251031122 SB20251031123 and 39 more |
||
| #VU117681 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') CVE-2025-55752 |
CWE-22 | High | 9.0.36-3.153.2, 9.0.111-150200.96.1 | 27.10.2025 |
SB2025102748 SB20251031122 SB20251031123 and 43 more |
||
| #VU117680 - Improper Output Neutralization for Logs CVE-2025-55754 |
CWE-117 | Low | 9.0.36-3.153.2, 9.0.111-150200.96.1 | 27.10.2025 |
SB2025102748 SB20251031122 SB20251031123 and 27 more |
||
| #VU114024 - Resource exhaustion CVE-2025-48989 |
CWE-400 | Medium | 9.0.108-150200.91.1 | 13.08.2025 |
SB2025081375 SB2025081376 SB20250820127 and 49 more |
||
| #VU112276 - Resource exhaustion CVE-2025-53506 |
CWE-400 | Medium | 9.0.36-3.148.1, 9.0.108-150200.91.1 | 04.07.2025 |
SB20250704167 SB2025072535 SB2025072536 and 41 more |
||
| #VU112275 - Resource Management Errors CVE-2025-52520 |
CWE-399 | Medium | 9.0.36-3.148.1, 9.0.108-150200.91.1 | 04.07.2025 |
SB20250704167 SB2025072535 SB2025072536 and 42 more |
||
| #VU112274 - Improper input validation CVE-2025-52434 |
CWE-20 | Medium | 9.0.108-150200.91.1 | 04.07.2025 |
SB20250704167 SB2025072535 SB2025072536 and 32 more |
||
| #VU111159 - Improper Protection of Alternate Path CVE-2025-49125 |
CWE-424 | Medium | 9.0.108-150200.91.1 | 16.06.2025 |
SB2025061634 SB2025061927 SB20250620145 and 35 more |
||
| #VU107996 - Error Handling CVE-2025-31650 |
CWE-388 | Medium | 9.0.104-150200.81.1 | 28.04.2025 |
SB2025042851 SB2025050943 SB2025050982 and 38 more |
||
| #VU107995 - Improper input validation CVE-2025-31651 |
CWE-20 | Medium | 9.0.36-3.142.1, 9.0.104-150200.81.1 | 28.04.2025 |
SB2025042851 SB2025050943 SB2025050982 and 46 more |
||
| #VU105485 - Improper input validation CVE-2025-24813 |
CWE-20 | Critical | 9.0.36-3.139.1, 9.0.102-150200.78.1 | 10.03.2025 |
SB2025031069 SB2025031976 SB2025032642 and 48 more |
||
| #VU101893 - Permissions, Privileges, and Access Controls CVE-2024-56337 |
CWE-264 | High | 9.0.102-150200.78.1 | 20.12.2024 |
SB2024122063 SB2025011311 SB2025011801 and 45 more |
Showing elements 21 - 40 out of 69