Browse Security Advisories
Security Advisories for org.apache.tomcat.embed:tomcat-embed-core Clear Filters
High
about 2 months ago
Apache Tomcat - DoS in multipart upload
maven
org.apache.tomcat.embed:tomcat-embed-core, org.apache.tomcat:tomcat-catalina
Moderate
about 2 months ago
Apache Tomcat - Security constraint bypass for pre/post-resources
maven
org.apache.tomcat.embed:tomcat-embed-core, org.apache.tomcat:tomcat-catalina
Low
2 months ago
Apache Tomcat - CGI security constraint bypass
maven
org.apache.tomcat.embed:tomcat-embed-core, org.apache.tomcat:tomcat-catalina
Moderate
3 months ago
Apache Tomcat Denial of Service via invalid HTTP priority header
maven
org.apache.tomcat.embed:tomcat-embed-core, org.apache.tomcat:tomcat-coyote
Low
3 months ago
Apache Tomcat Rewrite rule bypass
maven
org.apache.tomcat.embed:tomcat-embed-core, org.apache.tomcat:tomcat-catalina
Critical
5 months ago
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
maven
org.apache.tomcat.embed:tomcat-embed-core, org.apache.tomcat:tomcat-catalina
High
8 months ago
Apache Tomcat Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability
maven
org.apache.tomcat.embed:tomcat-embed-core, org.apache.tomcat:tomcat-embed-core, org.apache.tomcat:tomcat-catalina
High
8 months ago
Apache Tomcat Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability
maven
org.apache.tomcat.embed:tomcat-embed-core, org.apache.tomcat:tomcat-catalina
Moderate
9 months ago
Apache Tomcat Request and/or response mix-up
maven
org.apache.tomcat:tomcat-coyote, org.apache.tomcat.embed:tomcat-embed-core
High
about 1 year ago
Apache Tomcat - Denial of Service
maven
org.apache.tomcat:tomcat-coyote, org.apache.tomcat.embed:tomcat-embed-core
Moderate
over 1 year ago
Apache Tomcat Denial of Service due to improper input validation vulnerability for HTTP/2 requests
maven
org.apache.tomcat:tomcat-coyote, org.apache.tomcat.embed:tomcat-embed-core
Moderate
over 1 year ago
Apache Tomcat vulnerable to Generation of Error Message Containing Sensitive Information
maven
org.apache.tomcat.embed:tomcat-embed-core, org.apache.tomcat:tomcat-coyote
High
over 1 year ago
Apache Tomcat Improper Input Validation vulnerability
maven
org.apache.tomcat.embed:tomcat-embed-core, org.apache.tomcat:tomcat-catalina
Moderate
almost 2 years ago
Apache Tomcat Improper Input Validation vulnerability
maven
org.apache.tomcat.embed:tomcat-embed-core, org.apache.tomcat:tomcat
Moderate
almost 2 years ago
HTTP/2 Stream Cancellation Attack
maven, swift, go
org.apache.tomcat:tomcat-coyote, com.typesafe.akka:akka-http-core_2.11, com.typesafe.akka:akka-http-core_2.12, com.typesafe.akka:akka-http-core_2.13, com.typesafe.akka:akka-http-core, org.eclipse.jetty.http2:jetty-http2-server, org.eclipse.jetty.http2:jetty-http2-common, org.eclipse.jetty.http2:http2-server, org.eclipse.jetty.http2:http2-common, github.com/apple/swift-nio-http2, org.apache.tomcat.embed:tomcat-embed-core, google.golang.org/grpc, golang.org/x/net
Moderate
almost 2 years ago
Apache Tomcat Incomplete Cleanup vulnerability
maven
org.apache.tomcat:tomcat-coyote, org.apache.tomcat.embed:tomcat-embed-core, org.apache.tomcat:tomcat
Moderate
almost 2 years ago
Apache Tomcat Open Redirect vulnerability
maven
org.apache.tomcat.embed:tomcat-embed-core, org.apache.tomcat:tomcat
High
about 2 years ago
Apache Tomcat - Fix for CVE-2023-24998 was incomplete
maven
org.apache.tomcat:tomcat-coyote, org.apache.tomcat.embed:tomcat-embed-core
High
about 2 years ago
Apache Tomcat vulnerable to information leak
maven
org.apache.tomcat:tomcat-coyote, org.apache.tomcat.embed:tomcat-embed-core
High
over 2 years ago
Apache Commons FileUpload denial of service vulnerability
maven
org.apache.tomcat.embed:tomcat-embed-core, org.apache.tomcat:tomcat-coyote, commons-fileupload:commons-fileupload
High
over 2 years ago
Apache Tomcat improperly escapes input from JsonErrorReportValve
maven
org.apache.tomcat:tomcat-util, org.apache.tomcat:tomcat-catalina, org.apache.tomcat.embed:tomcat-embed-core
High
almost 3 years ago
Apache Tomcat may reject request containing invalid Content-Length header
maven
org.apache.tomcat:tomcat-coyote, org.apache.tomcat.embed:tomcat-embed-core
Moderate
about 3 years ago
Denial of service in Apache Tomcat
maven
org.apache.tomcat.embed:tomcat-embed-core, org.apache.tomcat:tomcat-coyote
Critical
about 3 years ago
Expected Behavior Violation in Apache Tomcat
maven
org.apache.tomcat.embed:tomcat-embed-core, org.apache.tomcat:tomcat-coyote
Critical
about 3 years ago
Exposure of Resource to Wrong Sphere in Apache Tomcat
maven
org.apache.tomcat.embed:tomcat-embed-core, org.apache.tomcat:tomcat-catalina
Moderate
over 3 years ago
Apache Tomcat Cross-site scripting (XSS) vulnerability
maven
org.apache.tomcat.embed:tomcat-embed-core, org.apache.tomcat:tomcat
High
about 4 years ago
Exposure of Sensitive Information to an Unauthorized Actor in Apache Tomcat
maven
org.apache.tomcat.embed:tomcat-embed-core
Moderate
about 4 years ago
Information Disclosure in Apache Tomcat
maven
org.apache.tomcat.embed:tomcat-embed-core
High
over 4 years ago
Potential remote code execution in Apache Tomcat
maven
org.apache.tomcat.embed:tomcat-embed-core
Critical
about 5 years ago
Improper Privilege Management in Tomcat
maven
org.apache.tomcat.embed:tomcat-embed-core
High
about 5 years ago
Apache Tomcat Denial of Service vulnerability
maven
org.apache.tomcat.embed:tomcat-embed-core
Moderate
over 5 years ago
Potential HTTP request smuggling in Apache Tomcat
maven
org.apache.tomcat:tomcat, org.apache.tomcat.embed:tomcat-embed-core
Moderate
over 5 years ago
Potential HTTP request smuggling in Apache Tomcat
maven
org.apache.tomcat:tomcat, org.apache.tomcat.embed:tomcat-embed-core
High
over 5 years ago
Insufficiently Protected Credentials in Apache Tomcat
maven
org.apache.tomcat.embed:tomcat-embed-core
High
over 5 years ago
In Apache Tomcat, when using FORM authentication there was a narrow window where an attacker could perform a session fixation attack
maven
org.apache.tomcat.embed:tomcat-embed-core
High
about 6 years ago
Improper Locking in Apache Tomcat
maven
org.apache.tomcat.embed:tomcat-embed-core
Moderate
about 6 years ago
Cross-site scripting in Apache Tomcat
maven
org.apache.tomcat.embed:tomcat-embed-core
High
over 6 years ago
Apache Tomcat OS Command Injection vulnerability
maven
org.apache.tomcat.embed:tomcat-embed-core
Moderate
almost 7 years ago
Apache Tomcat Race Condition vulnerability
maven
org.apache.tomcat.embed:tomcat-embed-core
High
almost 7 years ago
The host name verification missing in Apache Tomcat
maven
org.apache.tomcat.embed:tomcat-embed-core
Critical
almost 7 years ago
The defaults settings for the CORS filter provided in Apache Tomcat are insecure and enable 'supportsCredentials' for all origins
maven
org.apache.tomcat.embed:tomcat-embed-core
High
almost 7 years ago
In Apache Tomcat there is an improper handing of overflow in the UTF-8 decoder
maven
org.apache.tomcat.embed:tomcat-embed-core
Moderate
almost 7 years ago
Apache Tomcat information exposure vulnerability
maven
org.apache.tomcat.embed:tomcat-embed-core
Moderate
almost 7 years ago
Apache Tomcat unauthorized access vulnerability
maven
org.apache.tomcat.embed:tomcat-embed-core
Moderate
almost 7 years ago
Apache Tomcat Open Redirect vulnerability
maven
org.apache.tomcat.embed:tomcat-embed-core
High
almost 7 years ago
When running Apache Tomcat on Windows with HTTP PUTs enabled it was possible to upload a JSP file to the server
maven
org.apache.tomcat.embed:tomcat-embed-core
Filter by Severity
Filter by Ecosystem
maven
6,666
packagist
5,357
pypi
4,846
npm
4,195
go
2,803
nuget
1,702
cargo
1,067
rubygems
919
hex
37
swift
35
actions
32
pub
10
Filter by Package
tensorflow
433
tensorflow-gpu
427
tensorflow-cpu
423
moodle/moodle
418
magento/community-edition
300
Microsoft.ChakraCore
247
org.jenkins-ci.main:jenkins-core
239
typo3/cms
190
org.apache.tomcat:tomcat
138
pimcore/pimcore
120
dolibarr/dolibarr
116
github.com/mattermost/mattermost/server/v8
115
typo3/cms-core
111
com.liferay.portal:release.portal.bom
110
Django
107
phpmyadmin/phpmyadmin
107
com.liferay.portal:release.dxp.bom
105
drupal/core
103
magento/project-community-edition
100
microweber/microweber
99
silverstripe/framework
92
apache-airflow
85
drupal/drupal
83
librenms/librenms
82
thorsten/phpmyfaq
73
Plone
72
com.fasterxml.jackson.core:jackson-databind
69
symfony/symfony
69
github.com/usememos/memos
66
salt
65
concrete5/concrete5
65
ansible
63
actionpack
61
shopware/platform
57
org.apache.struts:struts2-core
57
apache-superset
57
github.com/grafana/grafana
56
mlflow
53
craftcms/cms
51
org.keycloak:keycloak-core
50
nova
48
baserproject/basercms
47
nokogiri
46
django
46
org.apache.tomcat.embed:tomcat-embed-core
46
shopware/core
45
github.com/rancher/rancher
44
vyper
44
gradio
44
mautic/core
44
rdiffweb
42
matrix-synapse
42
nilsteampassnet/teampass
42
plone
41
org.elasticsearch:elasticsearch
41
showdoc/showdoc
41
k8s.io/kubernetes
41
org.xwiki.platform:xwiki-platform-oldcore
41
mantisbt/mantisbt
41
org.keycloak:keycloak-services
41
github.com/hashicorp/vault
40
froxlor/froxlor
40
github.com/mattermost/mattermost-server/v6
39
intelliants/subrion
39
directus
38
com.thoughtworks.xstream:xstream
37
com.jfinal:jfinal
36
net.mingsoft:ms-mcms
36
snipe/snipe-it
36
moin
35
zendframework/zendframework1
34
io.undertow:undertow-core
34
org.jenkins-ci.plugins:script-security
34
github.com/answerdev/answer
34
parse-server
33
gogs.io/gogs
33
keystone
32
github.com/argoproj/argo-cd
31
github.com/docker/docker
31
github.com/cilium/cilium
31
github.com/hashicorp/nomad
31
opencv-python
31
opencv-contrib-python
31
Pillow
31
github.com/argoproj/argo-cd/v2
31
shopware/shopware
30
getgrav/grav
30
rack
29
github.com/hashicorp/consul
29
github.com/mattermost/mattermost-server
29
org.apache.solr:solr-core
28
electron
28
mediawiki/core
28
centreon/centreon
27
org.opencms:opencms-core
27
pillow
26
next
26
openssl-src
26
org.springframework.security:spring-security-core
26
prestashop/prestashop
26
contao/core-bundle
25
org.eclipse.jetty:jetty-server
25
open-webui
25
rubygems-update
25
org.keycloak:keycloak-parent
24
pocketmine/pocketmine-mp
24
github.com/traefik/traefik/v2
24
surrealdb
24
getkirby/cms
24
magento/core
24
vllm
23
phpoffice/phpexcel
23
grumpydictator/firefly-iii
23
laravel/framework
23
zendframework/zendframework
23
simplesamlphp/simplesamlphp
23
remdex/livehelperchat
23
puppet
23
Microsoft.AspNetCore.App.Runtime.win-x86
22
org.bouncycastle:bcprov-jdk14
22
DotNetNuke.Core
22
tribalsystems/zenario
22
org.apache.openmeetings:openmeetings-parent
22
ckb
22
Microsoft.AspNetCore.App.Runtime.win-x64
22
@openzeppelin/contracts-upgradeable
22
phpoffice/phpspreadsheet
21
Microsoft.AspNetCore.App.Runtime.win-arm
21
@openzeppelin/contracts
21
activerecord
21
github.com/goharbor/harbor
21
org.apache.nifi:nifi
21
github.com/ethereum/go-ethereum
21
glance
21
org.apache.tomcat:tomcat-catalina
21
code.gitea.io/gitea
20
langchain
20
pyload-ng
20
org.cloudfoundry.identity:cloudfoundry-identity-server
20
golang.org/x/net
20
funadmin/funadmin
20
aim
20
cockpit-hq/cockpit
20
wasmtime
20
org.xwiki.platform:xwiki-platform-web-templates
19
Microsoft.AspNetCore.App.Runtime.linux-arm
19
Microsoft.AspNetCore.App.Runtime.osx-x64
19
neutron
19
github.com/zitadel/zitadel
19
helm.sh/helm/v3
19
Microsoft.AspNetCore.App.Runtime.linux-x64
19
Microsoft.AspNetCore.App.Runtime.linux-musl-x64
19
Microsoft.AspNetCore.App.Runtime.win-arm64
19
deno
19
Microsoft.AspNetCore.App.Runtime.linux-arm64
19
org.apache.tomcat:tomcat-coyote
19
com.vaadin:vaadin-bom
18
cobbler
18
Microsoft.AspNetCore.App.Runtime.linux-musl-arm64
18
contao/contao
18
mindsdb
18
mercurial
18
org.apache.jspwiki:jspwiki-main
18
forkcms/forkcms
18
topthink/framework
18
genix/cms
18
cakephp/cakephp
17
opencart/opencart
17
symfony/security
17
typo3/cms-backend
17
francoisjacquet/rosariosis
17
org.apache.inlong:manager-pojo
17
openmage/magento-lts
17
calibreweb
17
yetiforce/yetiforce-crm
17
cryptography
17
OctoPrint
17
notebook
17
org.springframework:spring-core
17
org.apache.geode:geode-core
17
ezsystems/ezpublish-kernel
17
org.apache.dubbo:dubbo
16
sequelize
16
lollms
16
Microsoft.NetCore.App.Runtime.win-x86
16
Microsoft.NetCore.App.Runtime.win-x64
16
Microsoft.NetCore.App.Runtime.win-arm64
16
Microsoft.NetCore.App.Runtime.win-arm
16
ethyca-fides
16
paddlepaddle
16
PaddlePaddle
16
github.com/traefik/traefik/v3
16
rusqlite
16
phpbb/phpbb
16
org.bouncycastle:bcprov-jdk15
16
github.com/openfga/openfga
16
tinymce
16
org.apache.activemq:activemq-client
16
october/system
16
org.apache.ranger:ranger
16