CRITICAL9.8CVE-2025-24813⚠ KEVApache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT >= 11.0.0-M1, < 11.0.3
CRITICAL9.8CVE-2020-1938⚠ KEVImproper Privilege Management in Tomcat >= 9.0.0, < 9.0.31
HIGH8.1⚠ KEVtomcat7 - security update
>= 9.0.0.M1, < 9.0.1
HIGH8.1⚠ KEVWhen running Apache Tomcat on Windows with HTTP PUTs enabled it was possible to upload a JSP file to the server
>= 7.0.0, < 7.0.79
CRITICAL9.8Apache Tomcat: Digest authenticator will authenticate any unknown user
from 0, < 9.0.118
CRITICAL9.8Apache Tomcat: HTTP/2 request headers not validated
from 0, < 9.0.118
CRITICAL9.8Apache Tomcat: Bypass of rules in Rewrite Valve
>= 9.0.76, < 9.0.104
CRITICAL9.8Apache Tomcat: RCE due to TOCTOU issue in JSP compilation - CVE-2024-50379 mitigation was incomplete
>= 11.0.0-M1, < 11.0.2
CRITICAL9.8Apache Tomcat: RCE due to TOCTOU issue in JSP compilation
>= 11.0.0-M1, < 11.0.2
CRITICAL9.8Expected Behavior Violation in Apache Tomcat
>= 9.0.0.M1, < 9.0.0.M19
CRITICAL9.8The defaults settings for the CORS filter provided in Apache Tomcat are insecure and enable 'supportsCredentials' for all origins
>= 9.0.0.M1, < 9.0.9
CRITICAL9.6Apache Tomcat: console manipulation via escape sequences in log messages
>= 11.0.0-M1, < 11.0.11
CRITICAL9.1Apache Tomcat: Security constraints not correctly applied
from 0, < 9.0.118
CRITICAL9.1Apache Tomcat: Client certificate verification bypass due to virtual host mapping
>= 11.0.0-M1, < 11.0.15
CRITICAL9.1Exposure of Resource to Wrong Sphere in Apache Tomcat
>= 9.0.0.M1, < 9.0.0.M18
HIGH8.6Apache Tomcat: Denial of Service
>= 11.0.0-M1, < 11.0.0-M21
HIGH8.4Apache Tomcat: exe side-loading via icalcs.exe in Tomcat installer for Windows
>= 11.0.0-M1, < 11.0.8
HIGH8.1Apache Tomcat OS Command Injection vulnerability
>= 9.0.0.M1, < 9.0.17
HIGH7.5Apache Tomcat: LockOutRealm treats user names as case-sensitive
from 0, < 9.0.118
HIGH7.5Apache Tomcat: Unbounded read in WebDAV LOCK and PROPFIND handling
from 0, < 9.0.118
HIGH7.5Apache Tomcat: Incomplete escaping of JSON access logs
>= 9.0.40, < 9.0.116
HIGH7.5Apache Tomcat: Request smuggling via invalid chunk extension
>= 7.0.0, < 9.0.116
HIGH7.5Apache Tomcat: TLS cipher order is not preserved
>= 9.0.114, < 9.0.116
HIGH7.5Apache Tomcat: Directory traversal via rewrite with possible RCE if PUT is enabled
>= 11.0.0-M1, < 11.0.11
HIGH7.5Apache Tomcat: h2 DoS - Made You Reset
>= 11.0.0-M1, < 11.0.10
HIGH7.5Apache Tomcat: DoS via excessive h2 streams at connection start
>= 8.5.0, <= 8.5.100
HIGH7.5Apache Tomcat: DoS via integer overflow in multipart file upload
>= 11.0.0-M1, < 11.0.9
HIGH7.5Apache Tomcat: APR/Native Connector crash leading to DoS
>= 9.0.0.M1, < 9.0.107
HIGH7.5Apache Tomcat: FileUpload large number of parts with headers DoS
>= 11.0.0-M1, < 11.0.8
HIGH7.5Apache Tomcat: Security constraint bypass for pre/post-resources
>= 11.0.0-M1, < 11.0.8
HIGH7.5Apache Tomcat: DoS via malformed HTTP/2 PRIORITY_UPDATE frame
>= 9.0.76, < 9.0.104
HIGH7.5Apache Tomcat: HTTP/2 excess header handling DoS
>= 11.0.0-M1, < 11.0.0-M21
HIGH7.5Apache Tomcat: HTTP/2 header handling DoS
>= 8.5.0, < 8.5.99
HIGH7.5Apache Tomcat: HTTP request smuggling via malformed trailer headers
>= 11.0.0-M1, < 11.0.0-M11
HIGH7.5Apache Tomcat: Fix for CVE-2023-24998 is incomplete
>= 11.0.0-M2, < 11.0.0-M5
HIGH7.5Apache Tomcat: AJP response header mix-up
>= 11.0.0-M5, < 11.0.0-M6
HIGH7.5tomcat9 - security update
>= 10.1.0-M1, < 10.1.5
HIGH7.5Apache Tomcat: JsonErrorReportValve escaping
>= 8.5.83, < 8.5.84
HIGH7.5Apache Tomcat request smuggling via malformed content-length
>= 8.5.0, < 8.5.83
HIGH7.5tomcat9 - security update
>= 10.0.0-M1, < 10.0.0-M5
HIGH7.5Apache Tomcat h2c request mix-up
>= 10.0.0-M1, < 10.0.2
HIGH7.5Apache Tomcat Denial of Service vulnerability
>= 9.0.0, < 9.0.16
HIGH7.5tomcat8 - security update
from 0, < 7.0.99
HIGH7.5tomcat9 - security update
>= 9.0.0.M1, < 9.0.20
HIGH7.5tomcat7 - security update
>= 9.0.0, < 9.0.10
HIGH7.5tomcat8 - security update
>= 9.0.0.M9, < 9.0.8
HIGH7.3Apache Tomcat: WebSocket authentication header exposure
from 0, < 9.0.118
HIGH7.3Apache Tomcat: Security constraint bypass for CGI scripts
>= 9.0.0.M1, < 9.0.105
HIGH7.0Incomplete fix for CVE-2020-9484
>= 10.0.0-M1, < 10.0.2
HIGH7.0tomcat7 - security update
>= 10.0.0-M1, < 10.0.0-M5
HIGH7.0tomcat8 - security update
from 0, < 7.0.99
MEDIUM6.5Apache Tomcat: session fixation via rewrite valve
>= 11.0.0-M1, < 11.0.8
MEDIUM6.5Apache Tomcat: Request/response mix-up with HTTP/2
>= 9.0.92, < 9.0.96
MEDIUM6.5Apache Tomcat information exposure vulnerability
>= 9.0.0M1, < 9.0.5
MEDIUM6.1Apache Tomcat: Occasionally open redirect
>= 8.5.30, < 9.0.116
MEDIUM6.1Apache Tomcat: Open redirect with FORM authentication
>= 8.5.0, < 8.5.93
MEDIUM6.1tomcat7 - security update
>= 9.0.0, < 9.0.17
MEDIUM5.9Apache Tomcat information disclosure
>= 10.0.0-M1, < 10.0.0-M10
MEDIUM5.9Apache Tomcat Race Condition vulnerability
>= 9.0.0.M9, < 9.0.10
MEDIUM5.9tomcat8 - security update
>= 9.0.0, < 9.0.5
MEDIUM5.3Apache Tomcat: Fix for CVE-2025-66614 is incomplete
>= 9.0.113, < 9.0.116
MEDIUM5.3Apache Tomcat: Delayed cleaning of multi-part upload temporary files may lead to DoS
>= 11.0.0-M1, < 11.0.12
MEDIUM5.3Apache Tomcat: Leaking of unrelated request bodies in default error page
>= 8.5.7, < 8.5.64
MEDIUM5.3Apache Tomcat: Trailer header parsing too lenient
>= 11.0.0-M1, < 11.0.0-M12
MEDIUM5.3Apache Tomcat: Failure during request clean-up leads to sensitive data leaking to subsequent requests
>= 10.1.0-M1, < 10.1.14
MEDIUM4.8tomcat8 - security update
>= 7.0.98, < 7.0.100
MEDIUM4.8Potential HTTP request smuggling in Apache Tomcat
from 0, < 7.0.100
MEDIUM4.3tomcat8 - security update
>= 8.5.0, < 8.5.34
LOW3.7Apache Tomcat: AJP secret compared in non-constant time
from 0, < 9.0.118
—Denial of service in Apache Tomcat
>= 8.0.0-RC1, < 8.0.4
—tomcat5.5
>= 5.5.9, < 5.5.27