Apache / Apache Tomcat
138 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2021-25122 | Apache Tomcat h2c request mix-up | HIGH | 7.5 | Mar 1, 2021 |
| CVE-2021-24122 | Apache Tomcat information disclosure | MEDIUM | 5.9 | Jan 14, 2021 |
| CVE-2020-17527 | Apache Tomcat: Request header mix-up between HTTP/2 streams | HIGH | 7.5 | Dec 3, 2020 |
| CVE-2020-11996 | tomcat: specially crafted sequence of HTTP/2 requests can lead to DoS | HIGH | 7.5 | Jun 26, 2020 |
| CVE-2020-1938 KEV | tomcat: Apache Tomcat AJP File Read/Inclusion Vulnerability | CRITICAL | 9.8 | Feb 24, 2020 |
| CVE-2020-1935 | tomcat: Mishandling of Transfer-Encoding header allows for HTTP request smuggling | MEDIUM | 4.8 | Feb 24, 2020 |
| CVE-2019-17569 | tomcat: Regression in handling of Transfer-Encoding header allows for HTTP request smuggling | MEDIUM | 4.8 | Feb 24, 2020 |
| CVE-2019-12418 | tomcat: local privilege escalation | HIGH | 7.4 | Dec 23, 2019 |
| CVE-2019-17563 | tomcat: Session fixation when using FORM authentication | HIGH | 7.5 | Dec 23, 2019 |
| CVE-2019-0221 | tomcat: XSS in SSI printenv | MEDIUM | 6.1 | May 28, 2019 |
| CVE-2018-11784 | tomcat: Open redirect in default servlet | MEDIUM | 5.3 | Oct 4, 2018 |
| CVE-2018-8037 | tomcat: Due to a mishandling of close in NIO/NIO2 connectors user sessions can get mixed up | CRITICAL | 9.1 | Aug 2, 2018 |
| CVE-2018-1336 | tomcat: A bug in the UTF-8 decoder can lead to DoS | HIGH | 7.5 | Aug 2, 2018 |
| CVE-2018-8034 | tomcat: Host name verification missing in WebSocket client | HIGH | 7.5 | Aug 1, 2018 |
| CVE-2018-8014 | tomcat: Insecure defaults in CORS filter enable 'supportsCredentials' for all origins | CRITICAL | 9.8 | May 16, 2018 |
| CVE-2018-1304 | tomcat: Incorrect handling of empty string URL in security constraints can lead to unintended exposure of resources | MEDIUM | 6.5 | Feb 28, 2018 |
| CVE-2018-1305 | tomcat: Late application of security constraints can lead to resource exposure for unauthorised users | MEDIUM | 6.5 | Feb 23, 2018 |
| CVE-2017-15706 | tomcat: Incorrect documentation of CGI Servlet search algorithm may lead to misconfiguration | MEDIUM | 5.3 | Jan 31, 2018 |
| CVE-2017-12617 KEV | tomcat: Remote Code Execution bypass for CVE-2017-12615 | HIGH | 8.1 | Oct 3, 2017 |
| CVE-2017-12616 | tomcat: Information Disclosure when using VirtualDirContext | HIGH | 7.5 | Sep 19, 2017 |
| CVE-2017-12615 KEV | tomcat: Remote Code Execution via JSP Upload | HIGH | 8.1 | Sep 19, 2017 |
| CVE-2017-7675 | tomcat: Security Constraint Bypass | HIGH | 7.5 | Aug 11, 2017 |
| CVE-2017-7674 | tomcat: Vary header not added by CORS filter leading to cache poisoning | MEDIUM | 5.9 | Aug 11, 2017 |
| CVE-2016-6796 | tomcat: security manager bypass via JSP Servlet config parameters | HIGH | 7.5 | Aug 11, 2017 |
| CVE-2016-8745 | tomcat: information disclosure due to incorrect Processor sharing | HIGH | 7.5 | Aug 10, 2017 |
Showing 101 to 125 of 138 CVEs