Browse Security Advisories
Security Advisories for org.apache.tomcat:tomcat Clear Filters
Moderate
almost 2 years ago
Apache Tomcat Improper Input Validation vulnerability
maven
org.apache.tomcat.embed:tomcat-embed-core, org.apache.tomcat:tomcat
Moderate
almost 2 years ago
Apache Tomcat Incomplete Cleanup vulnerability
maven
org.apache.tomcat:tomcat-coyote, org.apache.tomcat.embed:tomcat-embed-core, org.apache.tomcat:tomcat
Moderate
almost 2 years ago
Apache Tomcat Open Redirect vulnerability
maven
org.apache.tomcat.embed:tomcat-embed-core, org.apache.tomcat:tomcat
Moderate
about 3 years ago
Apache Tomcat Exposes IP Addresses and HTTP Headers of Requests
maven
org.apache.tomcat:tomcat
High
about 3 years ago
Deserialization of Untrusted Data in Apache Tomcat
maven
org.apache.tomcat:tomcat
Moderate
about 3 years ago
Apache Tomcat Allows Replacing of XML Parser
maven
org.apache.tomcat:tomcat
Low
about 3 years ago
Exposure of Sensitive Information to an Unauthorized Actor in Apache Tomcat
maven
org.apache.tomcat:tomcat
Moderate
about 3 years ago
Apache Tomcat does not follow ServletSecurity annotations
maven
org.apache.tomcat:tomcat
Moderate
about 3 years ago
Apache Tomcat HTTP BIO Connector Error Discloses Information From Different Requests to Remote Users
maven
org.apache.tomcat:tomcat
Moderate
about 3 years ago
Cross-Site Request Forgery in Apache Tomcat
maven
org.apache.tomcat:tomcat
Moderate
about 3 years ago
Improper Input Validation in Apache Tomcat
maven
org.apache.tomcat:tomcat
High
about 3 years ago
Apache Tomcat allows remote attackers to bypass a CSRF protection mechanism by using a token
maven
org.apache.tomcat:tomcat
High
about 3 years ago
Improper Neutralization of Input During Web Page Generation in Apache Tomcat
maven
org.apache.tomcat:tomcat
High
about 3 years ago
Apache Tomcat does not enforce the maxHttpHeaderSize limit
maven
org.apache.tomcat:tomcat
Moderate
about 3 years ago
Apache Tomcat allows remote attackers to bypass intended access restrictions
maven
org.apache.tomcat:tomcat
Moderate
about 3 years ago
Access restriction bypass in Apache Tomcat
maven
org.apache.tomcat:tomcat
Moderate
about 3 years ago
Improper Neutralization of Input During Web Page Generation in Apache Tomcat
maven
org.apache.tomcat:tomcat
Moderate
about 3 years ago
Apache Tomcat has cookies without HTTPOnly flag in Set-Cookie header
maven
org.apache.tomcat:tomcat
Moderate
about 3 years ago
Apache Tomcat affected by infinite loop in Double.parseDouble method in Java Runtime Environment
maven
org.apache.tomcat:tomcat
Moderate
about 3 years ago
Improper Verification of Source of a Communication Channel in Apache Tomcat
maven
org.apache.tomcat:tomcat
Moderate
about 3 years ago
Improper Input Validation in Apache Tomcat
maven
org.apache.tomcat:tomcat
Moderate
about 3 years ago
Insertion of Sensitive Information into Log File in Apache Tomcat
maven
org.apache.tomcat:tomcat
Moderate
about 3 years ago
Apache Tomcat does not properly handle an invalid Transfer-Encoding header
maven
org.apache.tomcat:tomcat
Moderate
about 3 years ago
Use of Hard-coded Cryptographic Key in Apache Tomcat
maven
org.apache.tomcat:tomcat
Low
about 3 years ago
Improper Limitation of a Pathname to a Restricted Directory in Apache Tomcat
maven
org.apache.tomcat:tomcat
High
about 3 years ago
Apache Tomcat Allows Remote Attackers to Spoof AJP Requests
maven
org.apache.tomcat:tomcat
Moderate
about 3 years ago
Apache Tomcat is vulnerable to HTTP request-smuggling
maven
org.apache.tomcat:tomcat
Moderate
about 3 years ago
Apache Tomcat Vulnerable to Denial of Service (DoS) via Improper Handling of chunk extensions
maven
org.apache.tomcat:tomcat
Moderate
about 3 years ago
Apache Tomcat Denial of Service vulnerability
maven
org.apache.tomcat:tomcat
Moderate
about 3 years ago
Improper Input Validation in Apache Tomcat
maven
org.apache.tomcat:tomcat
Moderate
about 3 years ago
Exposure of Sensitive Information to an Unauthorized Actor in Apache Tomcat
maven
org.apache.tomcat:tomcat
Moderate
about 3 years ago
Integer Overflow or Wraparound in Apache Tomcat
maven
org.apache.tomcat:tomcat-coyote, org.apache.tomcat:tomcat
Moderate
about 3 years ago
Improper Input Validation in Apache Tomcat
maven
org.apache.tomcat:tomcat-catalina, org.apache.tomcat:tomcat
Moderate
about 3 years ago
Missing XML Validation in Apache Tomcat
maven
org.apache.tomcat:tomcat-jasper, org.apache.tomcat:tomcat-catalina, org.apache.tomcat:tomcat
High
about 3 years ago
Uncontrolled Resource Consumption in Apache Tomcat
maven
org.apache.tomcat:tomcat
Moderate
about 3 years ago
Improper Input Validation in Apache Tomcat
maven
org.apache.tomcat:tomcat
Moderate
about 3 years ago
Improper Neutralization of CRLF Sequences in HTTP Headers in Apache Tomcat
maven
org.apache.tomcat:tomcat-util, org.apache.tomcat:tomcat
Moderate
about 3 years ago
Exposure of Sensitive Information to an Unauthorized Actor in Apache Tomcat
maven
org.apache.tomcat:tomcat
Moderate
about 3 years ago
Improper Limitation of a Pathname to a Restricted Directory in Apache Tomcat
maven
org.apache.tomcat:tomcat
High
about 3 years ago
Concurrent Execution using Shared Resource with Improper Synchronization in Apache Tomcat
maven
org.apache.tomcat:tomcat
High
about 3 years ago
Improper Restriction of Operations within the Bounds of a Memory Buffer in Apache Tomcat
maven
org.apache.tomcat:tomcat
Moderate
about 3 years ago
Improper Limitation of a Pathname to a Restricted Directory in Apache Tomcat
maven
org.apache.tomcat:tomcat
High
about 3 years ago
Exposure of Sensitive Information to an Unauthorized Actor in Apache Tomcat
maven
org.apache.tomcat:tomcat
Moderate
about 3 years ago
Inconsistent documentation in Apache Tomcat
maven
org.apache.tomcat:tomcat
High
about 3 years ago
Apache Tomcat allows remote attackers to read data that was intended to be associated with a different request
maven
org.apache.tomcat:tomcat
Moderate
about 3 years ago
Insufficient Verification of Data Authenticity in Apache Tomcat
maven
org.apache.tomcat:tomcat
High
about 3 years ago
Unrestricted Upload of File with Dangerous Type Apache Tomcat
maven
org.apache.tomcat:tomcat
High
about 3 years ago
Improper Limitation of a Pathname to a Restricted Directory in Apache Tomcat
maven
org.apache.tomcat:tomcat
High
about 3 years ago
Improper Handling of Exceptional Conditions in Apache Tomcat
maven
org.apache.tomcat:tomcat
High
about 3 years ago
Improper Resource Shutdown or Release in Apache Tomcat
maven
org.apache.tomcat:tomcat
Moderate
about 3 years ago
Apache Tomcat Unrestricted file upload vulnerability
maven
org.apache.tomcat:tomcat
High
about 3 years ago
Apache Tomcat vulnerable to SecurityManager bypass
maven
org.apache.tomcat:tomcat
Moderate
about 3 years ago
System Property Disclosure in Apache Tomcat
maven
org.apache.tomcat:tomcat
High
about 3 years ago
Apache Tomcat EncryptInterceptor error leads to Uncontrolled Resource Consumption
maven
org.apache.tomcat:tomcat
Moderate
about 3 years ago
Improper Neutralization of Input During Web Page Generation in Apache Tomcat
maven
org.apache.tomcat:tomcat
Moderate
about 3 years ago
Exposure of Sensitive Information to an Unauthorized Actor in Apache Tomcat
maven
org.apache.tomcat:tomcat
Moderate
about 3 years ago
Apache Tomcat affected by vulnerability in TLS and SSL protocol
maven
org.apache.tomcat:tomcat
Moderate
about 3 years ago
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in Apache Tomcat
maven
org.apache.tomcat:tomcat
Moderate
about 3 years ago
Apache Tomcat Directory Traversal vulnerability
maven
org.apache.tomcat:tomcat
Moderate
about 3 years ago
Exposure of Sensitive Information to an Unauthorized Actor in Apache Tomcat
maven
org.apache.tomcat:tomcat
Moderate
about 3 years ago
Exposure of Sensitive Information in Apache Tomcat
maven
org.apache.tomcat:tomcat
Moderate
about 3 years ago
Apache Tomcat Denial of Service via Malformed Request Headers
maven
org.apache.tomcat:tomcat
Low
about 3 years ago
Apache Tomcat information disclosure vulnerability
maven
org.apache.tomcat:tomcat
Moderate
about 3 years ago
Apache Tomcat Directory Traversal vulnerability
maven
org.apache.tomcat:tomcat
Moderate
about 3 years ago
Apache Tomcat Path Traversal Vulnerability
maven
org.apache.tomcat:tomcat
Moderate
about 3 years ago
Apache Tomcat Cross-site scripting (XSS) vulnerability
maven
org.apache.tomcat.embed:tomcat-embed-core, org.apache.tomcat:tomcat
Moderate
about 3 years ago
Apache Tomcat Cross-site scripting (XSS) vulnerability
maven
org.apache.tomcat:tomcat
Moderate
about 3 years ago
Apache Tomcat Sensitive Information Disclosure
maven
org.apache.tomcat:tomcat
Moderate
about 3 years ago
Apache Tomcat Does Not Properly Handle Empty Requests
maven
org.apache.tomcat:tomcat
Moderate
about 3 years ago
Exposure of Sensitive Information in Apache Tomcat
maven
org.apache.tomcat:tomcat
Moderate
about 3 years ago
Apache Tomcat Example Application CSRF and XSS Vulnerabilities
maven
org.apache.tomcat:tomcat
Moderate
about 3 years ago
Apache Tomcat's CookieExample Vulnerable to XSS
maven
org.apache.tomcat:tomcat
Moderate
about 3 years ago
Apache Tomcat Mishandles Character Sequence in Cookies
maven
org.apache.tomcat:tomcat
Moderate
about 3 years ago
Apache Tomcat treats single quotes as delimiters in cookies
maven
org.apache.tomcat:tomcat
Low
about 3 years ago
Apache Tomcat vulnerable to Cross-site Scripting
maven
org.apache.tomcat:tomcat
Moderate
about 3 years ago
Apache Tomcat XSS Vulnerabilities in Examples Web Application
maven
org.apache.tomcat:tomcat
Filter by Severity
Filter by Ecosystem
maven
6,662
packagist
5,355
pypi
4,831
npm
4,188
go
2,795
nuget
1,700
cargo
1,065
rubygems
918
hex
37
swift
35
actions
32
pub
10
Filter by Package
tensorflow
433
tensorflow-gpu
427
tensorflow-cpu
423
moodle/moodle
418
magento/community-edition
300
Microsoft.ChakraCore
247
org.jenkins-ci.main:jenkins-core
239
typo3/cms
190
org.apache.tomcat:tomcat
138
pimcore/pimcore
120
dolibarr/dolibarr
116
github.com/mattermost/mattermost/server/v8
115
typo3/cms-core
111
com.liferay.portal:release.portal.bom
110
phpmyadmin/phpmyadmin
107
Django
107
com.liferay.portal:release.dxp.bom
105
drupal/core
103
magento/project-community-edition
100
microweber/microweber
99
silverstripe/framework
92
apache-airflow
85
drupal/drupal
83
librenms/librenms
82
thorsten/phpmyfaq
73
Plone
72
symfony/symfony
69
com.fasterxml.jackson.core:jackson-databind
69
concrete5/concrete5
65
github.com/usememos/memos
65
salt
65
ansible
63
actionpack
61
shopware/platform
57
apache-superset
57
org.apache.struts:struts2-core
57
github.com/grafana/grafana
56
mlflow
53
craftcms/cms
51
org.keycloak:keycloak-core
50
nova
48
baserproject/basercms
47
django
46
nokogiri
46
org.apache.tomcat.embed:tomcat-embed-core
46
shopware/core
45
mautic/core
44
github.com/rancher/rancher
44
vyper
44
gradio
44
matrix-synapse
42
nilsteampassnet/teampass
42
rdiffweb
42
plone
41
org.keycloak:keycloak-services
41
k8s.io/kubernetes
41
org.xwiki.platform:xwiki-platform-oldcore
41
org.elasticsearch:elasticsearch
41
mantisbt/mantisbt
41
showdoc/showdoc
41
github.com/hashicorp/vault
40
froxlor/froxlor
40
intelliants/subrion
39
github.com/mattermost/mattermost-server/v6
39
directus
38
com.thoughtworks.xstream:xstream
37
snipe/snipe-it
36
com.jfinal:jfinal
36
net.mingsoft:ms-mcms
36
moin
35
org.jenkins-ci.plugins:script-security
34
zendframework/zendframework1
34
github.com/answerdev/answer
34
io.undertow:undertow-core
34
parse-server
33
gogs.io/gogs
33
keystone
32
github.com/cilium/cilium
31
opencv-contrib-python
31
Pillow
31
github.com/argoproj/argo-cd
31
github.com/argoproj/argo-cd/v2
31
github.com/hashicorp/nomad
31
opencv-python
31
shopware/shopware
30
getgrav/grav
30
github.com/mattermost/mattermost-server
29
rack
29
github.com/docker/docker
29
github.com/hashicorp/consul
29
mediawiki/core
28
org.apache.solr:solr-core
28
electron
28
org.opencms:opencms-core
27
centreon/centreon
27
prestashop/prestashop
26
pillow
26
openssl-src
26
org.springframework.security:spring-security-core
26
next
26
rubygems-update
25
org.eclipse.jetty:jetty-server
25
contao/core-bundle
25
open-webui
25
pocketmine/pocketmine-mp
24
github.com/traefik/traefik/v2
24
org.keycloak:keycloak-parent
24
getkirby/cms
24
magento/core
24
surrealdb
24
grumpydictator/firefly-iii
23
simplesamlphp/simplesamlphp
23
phpoffice/phpexcel
23
laravel/framework
23
remdex/livehelperchat
23
puppet
23
zendframework/zendframework
23
vllm
23
Microsoft.AspNetCore.App.Runtime.win-x64
22
tribalsystems/zenario
22
org.bouncycastle:bcprov-jdk14
22
@openzeppelin/contracts-upgradeable
22
org.apache.openmeetings:openmeetings-parent
22
ckb
22
DotNetNuke.Core
22
Microsoft.AspNetCore.App.Runtime.win-x86
22
phpoffice/phpspreadsheet
21
activerecord
21
@openzeppelin/contracts
21
github.com/goharbor/harbor
21
github.com/ethereum/go-ethereum
21
org.apache.nifi:nifi
21
glance
21
Microsoft.AspNetCore.App.Runtime.win-arm
21
org.apache.tomcat:tomcat-catalina
21
org.cloudfoundry.identity:cloudfoundry-identity-server
20
aim
20
wasmtime
20
code.gitea.io/gitea
20
funadmin/funadmin
20
cockpit-hq/cockpit
20
golang.org/x/net
20
langchain
20
Microsoft.AspNetCore.App.Runtime.linux-musl-x64
19
org.apache.tomcat:tomcat-coyote
19
github.com/zitadel/zitadel
19
org.xwiki.platform:xwiki-platform-web-templates
19
helm.sh/helm/v3
19
Microsoft.AspNetCore.App.Runtime.linux-arm64
19
Microsoft.AspNetCore.App.Runtime.linux-x64
19
Microsoft.AspNetCore.App.Runtime.osx-x64
19
Microsoft.AspNetCore.App.Runtime.win-arm64
19
pyload-ng
19
Microsoft.AspNetCore.App.Runtime.linux-arm
19
deno
19
neutron
19
topthink/framework
18
com.vaadin:vaadin-bom
18
genix/cms
18
cobbler
18
forkcms/forkcms
18
contao/contao
18
mercurial
18
mindsdb
18
Microsoft.AspNetCore.App.Runtime.linux-musl-arm64
18
opencart/opencart
17
cryptography
17
typo3/cms-backend
17
org.springframework:spring-core
17
cakephp/cakephp
17
openmage/magento-lts
17
calibreweb
17
yetiforce/yetiforce-crm
17
org.apache.geode:geode-core
17
ezsystems/ezpublish-kernel
17
notebook
17
OctoPrint
17
symfony/security
17
francoisjacquet/rosariosis
17
org.apache.inlong:manager-pojo
17
paddlepaddle
16
org.apache.jspwiki:jspwiki-main
16
org.bouncycastle:bcprov-jdk15
16
org.apache.ranger:ranger
16
org.apache.activemq:activemq-client
16
rusqlite
16
Microsoft.NetCore.App.Runtime.win-x86
16
Microsoft.NetCore.App.Runtime.win-x64
16
tinymce
16
Microsoft.NetCore.App.Runtime.win-arm64
16
Microsoft.NetCore.App.Runtime.win-arm
16
lollms
16
sequelize
16
phpbb/phpbb
16
org.apache.dubbo:dubbo
16
github.com/traefik/traefik/v3
16
october/system
16
ethyca-fides
16
PaddlePaddle
16
github.com/openfga/openfga
16