Vulnerabilities

Last updated 2 hours ago
Filters
Severity
Critical Severity
CVSS Score Range: 9.0–10.0
Critical severity vulnerabilities (CVSS 9.0–10.0). These represent the highest impact issues.
High Severity
CVSS Score Range: 7.0–8.9
High severity vulnerabilities (CVSS 7.0–8.9). Serious vulnerabilities that should be prioritized soon after critical fixes.
Medium Severity
CVSS Score Range: 4.0–6.9
Medium severity vulnerabilities (CVSS 4.0–6.9). Important issues that meaningfully reduce security confidence.
Low Severity
CVSS Score Range: < 4.0
Low severity vulnerabilities (CVSS < 4.0). Hygiene issues that can accumulate but pose lower immediate risk.
Unknown Severity
CVSS Score Range: No score
Vulnerabilities without an assigned CVSS score. Severity is not determinable from available data.
Package Summary Severity Published Modified
org.apache.tomcat.embed:tomcat-embed-core Apache Tomcat Improper Input Validation vulnerability High Risk 7.5 2 years ago 5 hours ago
org.apache.tomcat.embed:tomcat-embed-core Apache Tomcat's DIGEST authenticator has an Authentication Bypass by Capture-replay vulnerability Critical 9.8 1 month ago 21 days ago
org.apache.tomcat.embed:tomcat-embed-core Apache Tomcat vulnerable to Insertion of Sensitive Information into Log File High Risk 7.5 5 months ago 21 days ago
org.apache.tomcat.embed:tomcat-embed-core Apache Tomcat - Client certificate verification bypass Critical 9.1 7 months ago 21 days ago
org.apache.tomcat.embed:tomcat-embed-core Apache Tomcat has an Improper Encoding or Escaping of Output vulnerability in the JsonAccessLogValve High Risk 7.5 5 months ago 21 days ago
org.apache.tomcat.embed:tomcat-embed-core Apache Tomcat has an Improper Access Control, Incorrect Authorization vulnerability Critical 9.1 1 month ago 21 days ago
org.apache.tomcat.embed:tomcat-embed-core Apache Tomcat's FORM authentication process has an Incorrect Authorization vulnerability Critical 9.1 1 month ago 21 days ago
org.apache.tomcat.embed:tomcat-embed-core Apache Tomcat has an HTTP Request/Response Smuggling vulnerability High Risk 7.5 5 months ago 21 days ago
org.apache.tomcat.embed:tomcat-embed-core Apache Tomcat: Unbounded read in WebDAV LOCK and PROPFIND handling High Risk 7.5 4 months ago 21 days ago
org.apache.tomcat.embed:tomcat-embed-core Apache Tomcat has an Open Redirect vulnerability Medium Risk 6.1 5 months ago 21 days ago
org.apache.tomcat.embed:tomcat-embed-core Apache Tomcat - AJP secret compared in non-constant time Low Risk 3.7 4 months ago 21 days ago
org.apache.tomcat.embed:tomcat-embed-core Apache Tomcat: LockOutRealm treats user names as case-sensitive High Risk 7.5 4 months ago 21 days ago
org.apache.tomcat.embed:tomcat-embed-core Apache Tomcat - Digest authenticator will authenticate any unknown user Critical 9.8 4 months ago 21 days ago
org.apache.tomcat.embed:tomcat-embed-core Apache Tomcat - Security constraints not correctly applied Critical 9.1 4 months ago 21 days ago
org.apache.tomcat.embed:tomcat-embed-core Apache Tomcat - WebSocket authentication header exposure High Risk 7.3 4 months ago 22 days ago
org.apache.tomcat.embed:tomcat-embed-core Apache Tomcat has an Improper Input Validation vulnerability Medium Risk 5.3 5 months ago 22 days ago
org.apache.tomcat.embed:tomcat-embed-core Apache Tomcat Denial of Service via invalid HTTP priority header Medium Risk 6.0 1 year ago 22 days ago
org.apache.tomcat.embed:tomcat-embed-core Apache Tomcat - CGI security constraint bypass Low Risk 3.0 1 year ago 22 days ago
org.apache.tomcat.embed:tomcat-embed-core Apache Tomcat Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability High Risk 8.0 1 year ago 22 days ago
org.apache.tomcat.embed:tomcat-embed-core Apache Tomcat - HTTP/2 request headers not validated Critical 9.8 4 months ago 22 days ago
org.apache.tomcat.embed:tomcat-embed-core Apache Tomcat: Configured cipher preference order not preserved High Risk 7.5 5 months ago 22 days ago
org.apache.tomcat.embed:tomcat-embed-core Apache Tomcat has an Improper Input Validation vulnerability High Risk 7.5 7 months ago 22 days ago
org.apache.tomcat.embed:tomcat-embed-core Apache Tomcat Vulnerable to Improper Resource Shutdown or Release Medium Risk 5.3 11 months ago 22 days ago
org.apache.tomcat.embed:tomcat-embed-core Apache Tomcat Vulnerable to Improper Neutralization of Escape, Meta, or Control Sequences Critical 9.6 11 months ago 22 days ago
org.apache.tomcat.embed:tomcat-embed-core Apache Tomcat Vulnerable to Relative Path Traversal High Risk 7.5 11 months ago 22 days ago
org.apache.tomcat.embed:tomcat-embed-core Apache Tomcat - Security constraint bypass for pre/post-resources Medium Risk 6.0 1 year ago 22 days ago
org.apache.tomcat.embed:tomcat-embed-core Apache Tomcat Coyote vulnerable to Denial of Service via excessive HTTP/2 streams High Risk 7.5 1 year ago 22 days ago
org.apache.tomcat.embed:tomcat-embed-core Apache Tomcat - DoS in multipart upload High Risk 7.5 1 year ago 22 days ago
org.apache.tomcat.embed:tomcat-embed-core Apache Tomcat Rewrite rule bypass Low Risk 3.0 1 year ago 22 days ago
org.apache.tomcat.embed:tomcat-embed-core Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT Critical 9.8 1 year ago 22 days ago
org.apache.tomcat.embed:tomcat-embed-core Apache Tomcat Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability Critical 9.8 1 year ago 22 days ago
org.apache.tomcat.embed:tomcat-embed-core Apache Tomcat - Denial of Service High Risk 7.5 2 years ago 22 days ago
org.apache.tomcat.embed:tomcat-embed-core HTTP/2 Stream Cancellation Attack Medium Risk 5.3 2 years ago 22 days ago
org.apache.tomcat.embed:tomcat-embed-core Apache Tomcat Open Redirect vulnerability Medium Risk 6.1 3 years ago 22 days ago
org.apache.tomcat.embed:tomcat-embed-core Exposure of Sensitive Information to an Unauthorized Actor in Apache Tomcat High Risk 7.5 5 years ago 1 month ago
org.apache.tomcat.embed:tomcat-embed-core Potential remote code execution in Apache Tomcat High Risk 7.0 6 years ago 1 month ago
org.apache.tomcat.embed:tomcat-embed-core Apache Tomcat Allocation of Resources Without Limits or Throttling vulnerability High Risk 8.6 1 year ago 1 month ago
org.apache.tomcat.embed:tomcat-embed-core Apache Tomcat Denial of Service due to improper input validation vulnerability for HTTP/2 requests High Risk 7.5 2 years ago 1 month ago
org.apache.tomcat.embed:tomcat-embed-core Potential remote code execution in Apache Tomcat High Risk 7.0 5 years ago 1 month ago
org.apache.tomcat.embed:tomcat-embed-core Information Disclosure in Apache Tomcat Medium Risk 5.9 5 years ago 1 month ago
org.apache.tomcat.embed:tomcat-embed-core Potential HTTP request smuggling in Apache Tomcat Medium Risk 4.8 6 years ago 1 month ago
org.apache.tomcat.embed:tomcat-embed-core Apache Commons FileUpload denial of service vulnerability High Risk 7.5 3 years ago 1 month ago
org.apache.tomcat.embed:tomcat-embed-core Improper Privilege Management in Tomcat Critical 9.8 6 years ago 1 month ago
org.apache.tomcat.embed:tomcat-embed-core In Apache Tomcat, when using FORM authentication there was a narrow window where an attacker could perform a session fixation attack High Risk 7.5 6 years ago 1 month ago
org.apache.tomcat.embed:tomcat-embed-core Insufficiently Protected Credentials in Apache Tomcat High Risk 7.0 6 years ago 1 month ago
org.apache.tomcat.embed:tomcat-embed-core Apache Tomcat Session Fixation vulnerability Medium Risk 6.5 1 year ago 3 months ago
org.apache.tomcat.embed:tomcat-embed-core Apache Tomcat is vulnerable to resource exhaustion when using the APR/Native connector High Risk 7.5 1 year ago 3 months ago
org.apache.tomcat.embed:tomcat-embed-core Apache Tomcat vulnerable to Generation of Error Message Containing Sensitive Information Medium Risk 5.3 2 years ago 3 months ago
org.apache.tomcat.embed:tomcat-embed-core Cross-site scripting in Apache Tomcat Medium Risk 6.1 7 years ago 3 months ago
org.apache.tomcat.embed:tomcat-embed-core Apache Tomcat Improper Input Validation vulnerability Medium Risk 5.3 2 years ago 3 months ago