Browse Security Advisories
Security Advisories for org.apache.tomcat.embed:tomcat-embed-core Clear Filters
High
3 months ago
Apache Tomcat - DoS in multipart upload
maven
org.apache.tomcat.embed:tomcat-embed-core, org.apache.tomcat:tomcat-catalina
Moderate
3 months ago
Apache Tomcat - Security constraint bypass for pre/post-resources
maven
org.apache.tomcat.embed:tomcat-embed-core, org.apache.tomcat:tomcat-catalina
Low
4 months ago
Apache Tomcat - CGI security constraint bypass
maven
org.apache.tomcat.embed:tomcat-embed-core, org.apache.tomcat:tomcat-catalina
Critical
7 months ago
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
maven
org.apache.tomcat.embed:tomcat-embed-core
High
9 months ago
Apache Tomcat Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability
maven
org.apache.tomcat.embed:tomcat-embed-core, org.apache.tomcat:tomcat-catalina
Moderate
10 months ago
Apache Tomcat Request and/or response mix-up
maven
org.apache.tomcat:tomcat-coyote, org.apache.tomcat.embed:tomcat-embed-core
High
about 1 year ago
Apache Tomcat - Denial of Service
maven
org.apache.tomcat.embed:tomcat-embed-core, org.apache.tomcat:tomcat-coyote
Moderate
over 1 year ago
Apache Tomcat vulnerable to Generation of Error Message Containing Sensitive Information
maven
org.apache.tomcat.embed:tomcat-embed-core, org.apache.tomcat:tomcat-coyote
Moderate
almost 2 years ago
Apache Tomcat Improper Input Validation vulnerability
maven
org.apache.tomcat.embed:tomcat-embed-core
High
about 2 years ago
Apache Tomcat - Fix for CVE-2023-24998 was incomplete
maven
org.apache.tomcat:tomcat-coyote, org.apache.tomcat.embed:tomcat-embed-core
High
over 2 years ago
Apache Tomcat vulnerable to information leak
maven
org.apache.tomcat:tomcat-coyote, org.apache.tomcat.embed:tomcat-embed-core
High
over 2 years ago
Apache Commons FileUpload denial of service vulnerability
maven
org.apache.tomcat.embed:tomcat-embed-core, org.apache.tomcat:tomcat-coyote
High
over 2 years ago
Apache Tomcat improperly escapes input from JsonErrorReportValve
maven
org.apache.tomcat:tomcat-util, org.apache.tomcat:tomcat-catalina, org.apache.tomcat.embed:tomcat-embed-core
High
almost 3 years ago
Apache Tomcat may reject request containing invalid Content-Length header
maven
org.apache.tomcat:tomcat-coyote, org.apache.tomcat.embed:tomcat-embed-core
Moderate
over 3 years ago
Denial of service in Apache Tomcat
maven
org.apache.tomcat.embed:tomcat-embed-core, org.apache.tomcat:tomcat-coyote
High
over 3 years ago
Unrestricted Upload of File with Dangerous Type Apache Tomcat
maven
org.apache.tomcat.embed:tomcat-embed-core, org.apache.tomcat:tomcat-catalina
Critical
over 3 years ago
Expected Behavior Violation in Apache Tomcat
maven
org.apache.tomcat.embed:tomcat-embed-core, org.apache.tomcat:tomcat-coyote
Critical
over 3 years ago
Exposure of Resource to Wrong Sphere in Apache Tomcat
maven
org.apache.tomcat.embed:tomcat-embed-core, org.apache.tomcat:tomcat-catalina
Moderate
over 3 years ago
Apache Tomcat Cross-site scripting (XSS) vulnerability
maven
org.apache.tomcat.embed:tomcat-embed-core, org.apache.tomcat:tomcat
High
over 4 years ago
Exposure of Sensitive Information to an Unauthorized Actor in Apache Tomcat
maven
org.apache.tomcat.embed:tomcat-embed-core
Moderate
over 4 years ago
Information Disclosure in Apache Tomcat
maven
org.apache.tomcat.embed:tomcat-embed-core
High
over 4 years ago
Potential remote code execution in Apache Tomcat
maven
org.apache.tomcat.embed:tomcat-embed-core
Critical
over 5 years ago
Improper Privilege Management in Tomcat
maven
org.apache.tomcat.embed:tomcat-embed-core
High
over 5 years ago
Apache Tomcat Denial of Service vulnerability
maven
org.apache.tomcat.embed:tomcat-embed-core
Moderate
over 5 years ago
Potential HTTP request smuggling in Apache Tomcat
maven
org.apache.tomcat:tomcat, org.apache.tomcat.embed:tomcat-embed-core
Moderate
over 5 years ago
Potential HTTP request smuggling in Apache Tomcat
maven
org.apache.tomcat:tomcat, org.apache.tomcat.embed:tomcat-embed-core
High
over 5 years ago
Insufficiently Protected Credentials in Apache Tomcat
maven
org.apache.tomcat.embed:tomcat-embed-core
High
over 5 years ago
In Apache Tomcat, when using FORM authentication there was a narrow window where an attacker could perform a session fixation attack
maven
org.apache.tomcat.embed:tomcat-embed-core
High
about 6 years ago
Improper Locking in Apache Tomcat
maven
org.apache.tomcat.embed:tomcat-embed-core
Moderate
over 6 years ago
Cross-site scripting in Apache Tomcat
maven
org.apache.tomcat.embed:tomcat-embed-core
High
over 6 years ago
Apache Tomcat OS Command Injection vulnerability
maven
org.apache.tomcat.embed:tomcat-embed-core
Moderate
almost 7 years ago
Apache Tomcat Race Condition vulnerability
maven
org.apache.tomcat.embed:tomcat-embed-core
High
almost 7 years ago
The host name verification missing in Apache Tomcat
maven
org.apache.tomcat.embed:tomcat-embed-core
Critical
almost 7 years ago
The defaults settings for the CORS filter provided in Apache Tomcat are insecure and enable 'supportsCredentials' for all origins
maven
org.apache.tomcat.embed:tomcat-embed-core
High
almost 7 years ago
In Apache Tomcat there is an improper handing of overflow in the UTF-8 decoder
maven
org.apache.tomcat.embed:tomcat-embed-core
Moderate
almost 7 years ago
Apache Tomcat information exposure vulnerability
maven
org.apache.tomcat.embed:tomcat-embed-core
Moderate
almost 7 years ago
Apache Tomcat unauthorized access vulnerability
maven
org.apache.tomcat.embed:tomcat-embed-core
Moderate
almost 7 years ago
Apache Tomcat Open Redirect vulnerability
maven
org.apache.tomcat.embed:tomcat-embed-core
High
almost 7 years ago
When running Apache Tomcat on Windows with HTTP PUTs enabled it was possible to upload a JSP file to the server
maven
org.apache.tomcat.embed:tomcat-embed-core
Filter by Severity
Filter by Ecosystem
maven
6,677
packagist
5,256
pypi
4,803
npm
4,256
go
2,855
nuget
1,610
cargo
1,061
rubygems
889
hex
38
actions
37
swift
33
pub
9
Filter by Package
tensorflow
431
moodle/moodle
418
tensorflow-cpu
402
tensorflow-gpu
393
magento/community-edition
294
Microsoft.ChakraCore
247
org.jenkins-ci.main:jenkins-core
242
typo3/cms
168
com.liferay.portal:release.portal.bom
141
org.apache.tomcat:tomcat
130
github.com/mattermost/mattermost/server/v8
121
pimcore/pimcore
120
dolibarr/dolibarr
116
com.liferay.portal:release.dxp.bom
115
phpmyadmin/phpmyadmin
107
typo3/cms-core
105
microweber/microweber
103
Django
100
drupal/core
99
silverstripe/framework
91
apache-airflow
85
librenms/librenms
83
drupal/drupal
77
thorsten/phpmyfaq
73
com.fasterxml.jackson.core:jackson-databind
69
github.com/usememos/memos
68
concrete5/concrete5
67
salt
65
magento/project-community-edition
65
Plone
64
ansible
63
apache-superset
61
actionpack
58
shopware/platform
58
symfony/symfony
57
org.apache.struts:struts2-core
56
github.com/grafana/grafana
56
mlflow
53
craftcms/cms
53
org.keycloak:keycloak-core
50
mautic/core
48
nova
48
github.com/hashicorp/vault
47
baserproject/basercms
47
shopware/core
46
nokogiri
45
github.com/rancher/rancher
45
github.com/mattermost/mattermost-server/v6
45
gradio
44
vyper
44
org.xwiki.platform:xwiki-platform-oldcore
43
rdiffweb
42
matrix-synapse
42
nilsteampassnet/teampass
42
org.keycloak:keycloak-services
42
showdoc/showdoc
41
mantisbt/mantisbt
41
k8s.io/kubernetes
41
org.elasticsearch:elasticsearch
41
froxlor/froxlor
40
intelliants/subrion
40
directus
39
org.apache.tomcat.embed:tomcat-embed-core
39
picklescan
39
snipe/snipe-it
38
github.com/mattermost/mattermost-server
37
com.thoughtworks.xstream:xstream
37
net.mingsoft:ms-mcms
36
com.jfinal:jfinal
36
io.undertow:undertow-core
35
moin
35
github.com/answerdev/answer
34
plone
34
parse-server
33
gogs.io/gogs
33
zendframework/zendframework1
33
org.jenkins-ci.plugins:script-security
32
github.com/hashicorp/nomad
31
shopware/shopware
31
github.com/argoproj/argo-cd
31
django
31
opencv-python
31
github.com/cilium/cilium
31
opencv-contrib-python
31
github.com/argoproj/argo-cd/v2
30
keystone
30
getgrav/grav
30
github.com/docker/docker
29
next
29
rack
29
github.com/hashicorp/consul
29
mediawiki/core
28
electron
28
org.apache.solr:solr-core
28
pillow
28
Pillow
28
org.opencms:opencms-core
27
contao/core-bundle
27
prestashop/prestashop
27
centreon/centreon
27
open-webui
25
github.com/traefik/traefik/v2
25
rubygems-update
25
pocketmine/pocketmine-mp
25
vllm
25
org.springframework.security:spring-security-core
25
org.eclipse.jetty:jetty-server
25
openssl-src
25
org.keycloak:keycloak-parent
24
getkirby/cms
24
surrealdb
24
flowise
24
puppet
23
pyload-ng
23
remdex/livehelperchat
23
magento/core
23
grumpydictator/firefly-iii
23
simplesamlphp/simplesamlphp
23
laravel/framework
22
tribalsystems/zenario
22
org.bouncycastle:bcprov-jdk15on
22
org.apache.tomcat:tomcat-catalina
22
org.apache.openmeetings:openmeetings-parent
22
ckb
22
contao/contao
22
activerecord
22
DotNetNuke.Core
22
org.apache.nifi:nifi
21
github.com/goharbor/harbor
21
glance
21
@openzeppelin/contracts-upgradeable
21
Microsoft.AspNetCore.App.Runtime.win-x64
21
org.cloudfoundry.identity:cloudfoundry-identity-server
20
aim
20
funadmin/funadmin
20
cockpit-hq/cockpit
20
ethyca-fides
20
typo3/cms-backend
20
@openzeppelin/contracts
20
github.com/ethereum/go-ethereum
20
code.gitea.io/gitea
20
wasmtime
20
org.xwiki.platform:xwiki-platform-web-templates
20
zendframework/zendframework
20
Microsoft.AspNetCore.App.Runtime.win-x86
19
neutron
19
deno
19
topthink/framework
19
langchain
19
Microsoft.AspNetCore.App.Runtime.win-arm
19
helm.sh/helm/v3
19
org.apache.tomcat:tomcat-coyote
19
forkcms/forkcms
18
org.springframework:spring-core
18
transformers
18
github.com/zitadel/zitadel
18
cobbler
18
com.vaadin:vaadin-bom
18
golang.org/x/net
18
phpoffice/phpexcel
18
org.apache.jspwiki:jspwiki-main
18
mercurial
18
Microsoft.AspNetCore.App.Runtime.linux-x64
18
mindsdb
18
genix/cms
18
org.apache.geode:geode-core
17
github.com/traefik/traefik/v3
17
openmage/magento-lts
17
notebook
17
calibreweb
17
Microsoft.AspNetCore.App.Runtime.osx-x64
17
Microsoft.AspNetCore.App.Runtime.linux-musl-x64
17
yetiforce/yetiforce-crm
17
francoisjacquet/rosariosis
17
cakephp/cakephp
17
Microsoft.AspNetCore.App.Runtime.linux-arm64
17
Microsoft.AspNetCore.App.Runtime.linux-arm
17
org.apache.inlong:manager-pojo
17
github.com/openfga/openfga
17
cryptography
17
ezsystems/ezpublish-kernel
17
OctoPrint
17
opencart/opencart
17
lollms
16
org.apache.activemq:activemq-client
16
sequelize
16
ghost
16
org.apache.ranger:ranger
16
phpbb/phpbb
16
tinymce
16
Microsoft.AspNetCore.App.Runtime.linux-musl-arm64
16
PaddlePaddle
16
paddlepaddle
16
org.apache.dubbo:dubbo
16
rusqlite
16
october/system
15
pimcore/admin-ui-classic-bundle
15
Microsoft.AspNetCore.App.Runtime.win-arm64
15
undici
15
bolt/bolt
15