apache / tomcat
26 known vulnerabilities in apache tomcat.
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2017-12617 | Act now | 100.0% | 8.1 | ● | When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC… |
| CVE-2017-12615 | Act now | 99.6% | 8.1 | ● | When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.… |
| CVE-2020-1938 | Act now | 99.3% | 9.8 | ● | When using the Apache JServ Protocol (AJP), care must be taken when trusting inc… |
| CVE-2026-34486 | Act now | 98.6% | 7.5 | ● | Missing Encryption of Sensitive Data vulnerability in Apache Tomcat due to the f… |
| CVE-2016-8735 | Act now | 90.3% | 9.8 | ● | Remote code execution is possible with Apache Tomcat before 6.0.48, 7.x before 7… |
| CVE-2020-13935 | High | 86.6% | 7.5 | The payload length in a WebSocket frame was not correctly validated in Apache To… | |
| CVE-2021-33037 | High | 75.4% | 5.3 | Apache Tomcat 10.0.0-M1 to 10.0.6, 9.0.0.M1 to 9.0.46 and 8.5.0 to 8.5.66 did no… | |
| CVE-2020-13934 | High | 64.1% | 7.5 | An h2c direct connection to Apache Tomcat 10.0.0-M1 to 10.0.0-M6, 9.0.0.M5 to 9.… | |
| CVE-2020-9484 | High | 56.6% | 7.0 | When using Apache Tomcat versions 10.0.0-M1 to 10.0.0-M4, 9.0.0.M1 to 9.0.34, 8.… | |
| CVE-2021-24122 | Medium | 22.9% | 5.9 | When serving resources from a network location using the NTFS file system, Apach… | |
| CVE-2021-25122 | Medium | 18.1% | 7.5 | When responding to new h2c connection requests, Apache Tomcat versions 10.0.0-M1… | |
| CVE-2021-25329 | Medium | 9.5% | 7.0 | The fix for CVE-2020-9484 was incomplete. When using Apache Tomcat 10.0.0-M1 to … | |
| CVE-2026-29146 | Medium | 8.9% | 7.5 | Padding Oracle vulnerability in Apache Tomcat's EncryptInterceptor with default … | |
| CVE-2022-25762 | Medium | 8.4% | 8.6 | If a web application sends a WebSocket message concurrently with the WebSocket c… | |
| CVE-2026-68763 | Medium | 0.8% | 7.5 | Uncontrolled Resource Consumption vulnerability in Apache Tomcat via an allocati… | |
| CVE-2026-65927 | Medium | 0.8% | 7.5 | Off-by-one Error vulnerability in Apache Tomcat impacting the [N] flag on the re… | |
| CVE-2026-65905 | Medium | 0.8% | 9.8 | Authentication Bypass by Capture-replay vulnerability in Apache Tomcat's DIGEST … | |
| CVE-2026-65637 | Medium | 0.8% | 9.8 | Improper Input Validation vulnerability in Apache Tomcat due to incomplete fix f… | |
| CVE-2026-68525 | Medium | 0.6% | 9.1 | Incorrect Authorization vulnerability in Apache Tomcat's FORM authentication pro… | |
| CVE-2026-65182 | Medium | 0.6% | 9.1 | Improper Access Control, Incorrect Authorization vulnerability in Apache Tomcat … | |
| CVE-2026-66422 | Medium | 0.6% | 8.1 | Improper Authorization vulnerability in Apache Tomcat cause by security-role-ref… | |
| CVE-2026-68569 | Medium | 0.5% | 8.1 | Improper Authentication vulnerability in Apache Tomcat meant that in some circum… | |
| CVE-2026-65183 | Medium | 0.5% | 8.1 | Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Apache Tomcat… | |
| CVE-2019-17569 | Low | 8.9% | 4.8 | The refactoring present in Apache Tomcat 9.0.28 to 9.0.30, 8.5.48 to 8.5.50 and … | |
| CVE-2026-73180 | Low | 0.5% | 6.8 | Insufficient Session Expiration vulnerability in Apache Tomcat meant that if the… | |
| CVE-2026-66299 | Low | 0.5% | 5.3 | Uncontrolled Resource Consumption vulnerability in Apache Tomcat's WebSocket cha… |