Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 1 429

Количество 1 429

github логотип

GHSA-3gv7-3h64-78cm

около 4 лет назад

Exposure of Sensitive Information to an Unauthorized Actor in Apache Tomcat

CVSS3: 7.5
EPSS: Средний
github логотип

GHSA-372q-33vh-8mpc

около 4 лет назад

Inconsistent documentation in Apache Tomcat

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-36hp-4x3g-phrg

около 4 лет назад

Apache Tomcat's CookieExample Vulnerable to XSS

EPSS: Низкий
github логотип

GHSA-2w2w-cv3h-rr38

больше 4 лет назад

Apache Tomcat Reveals Path through Long URL

EPSS: Низкий
github логотип

GHSA-2c9m-w27f-53rm

больше 3 лет назад

Apache Tomcat vulnerable to Unprotected Transport of Credentials

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-28cq-6rmx-pjq4

около 4 лет назад

Improper Authentication in Apache Tomcat

EPSS: Средний
github логотип

GHSA-27hp-xhwr-wr2m

больше 1 года назад

Apache Tomcat Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability

EPSS: Низкий
github логотип

GHSA-25xr-qj8w-c4vf

около 1 года назад

Apache Tomcat Coyote vulnerable to Denial of Service via excessive HTTP/2 streams

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-24j9-x2wg-9qv6

4 месяца назад

Apache Tomcat: CLIENT_CERT authentication does not fail as expected

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-23hv-mwm6-g8jf

12 месяцев назад

Apache Tomcat Session Fixation vulnerability

CVSS3: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2026-59084

17 дней назад

Insufficient Technical Documentation vulnerability in Apache Tomcat since the requirements to securely configure the EncryptInterceptor were not clearly documented. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.23, from 10.1.0-M1 through 10.1.56, from 9.0.13 through 9.0.119, from 8.5.38 through 8.5.100, from 7.0.100 through 7.0.109. Other versions that have reached end of support may also be affected. Users are recommended to upgrade to version 11.0.24, 10.1.57 or 9.0.120 which fix the issue.

CVSS3: 9.1
EPSS: Низкий
redhat логотип

CVE-2026-59084

17 дней назад

Insufficient Technical Documentation vulnerability in Apache Tomcat since the requirements to securely configure the EncryptInterceptor were not clearly documented. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.23, from 10.1.0-M1 through 10.1.56, from 9.0.13 through 9.0.119, from 8.5.38 through 8.5.100, from 7.0.100 through 7.0.109. Other versions that have reached end of support may also be affected. Users are recommended to upgrade to version 11.0.24, 10.1.57 or 9.0.120 which fix the issue.

CVSS3: 3.8
EPSS: Низкий
nvd логотип

CVE-2026-59084

17 дней назад

Insufficient Technical Documentation vulnerability in Apache Tomcat since the requirements to securely configure the EncryptInterceptor were not clearly documented. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.23, from 10.1.0-M1 through 10.1.56, from 9.0.13 through 9.0.119, from 8.5.38 through 8.5.100, from 7.0.100 through 7.0.109. Other versions that have reached end of support may also be affected. Users are recommended to upgrade to version 11.0.24, 10.1.57 or 9.0.120 which fix the issue.

CVSS3: 9.1
EPSS: Низкий
debian логотип

CVE-2026-59084

17 дней назад

Insufficient Technical Documentation vulnerability in Apache Tomcat si ...

CVSS3: 9.1
EPSS: Низкий
ubuntu логотип

CVE-2026-59083

17 дней назад

Improper Handling of URL Encoding (Hex Encoding) vulnerability in Apache Tomcat's rewrite valve allowed security constraint bypass for some configurations. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.23, from 10.1.0-M1 through 10.1.56, from 9.0.0.M1 through 9.0.119, from 8.5.0 through 8.5.100. Other versions that have reached end of support may also be affected. Users are recommended to upgrade to version 11.0.24, 10.1.57 or 9.0.120, which fix the issue.

CVSS3: 9.1
EPSS: Низкий
redhat логотип

CVE-2026-59083

17 дней назад

Improper Handling of URL Encoding (Hex Encoding) vulnerability in Apache Tomcat's rewrite valve allowed security constraint bypass for some configurations. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.23, from 10.1.0-M1 through 10.1.56, from 9.0.0.M1 through 9.0.119, from 8.5.0 through 8.5.100. Other versions that have reached end of support may also be affected. Users are recommended to upgrade to version 11.0.24, 10.1.57 or 9.0.120, which fix the issue.

CVSS3: 3.7
EPSS: Низкий
nvd логотип

CVE-2026-59083

17 дней назад

Improper Handling of URL Encoding (Hex Encoding) vulnerability in Apache Tomcat's rewrite valve allowed security constraint bypass for some configurations. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.23, from 10.1.0-M1 through 10.1.56, from 9.0.0.M1 through 9.0.119, from 8.5.0 through 8.5.100. Other versions that have reached end of support may also be affected. Users are recommended to upgrade to version 11.0.24, 10.1.57 or 9.0.120, which fix the issue.

CVSS3: 9.1
EPSS: Низкий
debian логотип

CVE-2026-59083

17 дней назад

Improper Handling of URL Encoding (Hex Encoding) vulnerability in Apac ...

CVSS3: 9.1
EPSS: Низкий
ubuntu логотип

CVE-2026-55957

около 1 месяца назад

Missing Critical Step in Authentication vulnerability in Apache Tomcat when the JNDIRealm was configured to authenticate binds using GSSAPI allowed attackers to authenticate without provided the correct password. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.4, from 10.1.0-M1 through 10.1.36, from 9.0.0.M1 through 9.0.100, from 8.5.0 through 8.5.100, from 7.0.0 through 7.0.109. Users are recommended to upgrade to version 11.0.5, 10.1.37 or 9.0.101, which fixes the issue.

CVSS3: 7.3
EPSS: Низкий
nvd логотип

CVE-2026-55957

около 1 месяца назад

Missing Critical Step in Authentication vulnerability in Apache Tomcat when the JNDIRealm was configured to authenticate binds using GSSAPI allowed attackers to authenticate without provided the correct password. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.4, from 10.1.0-M1 through 10.1.36, from 9.0.0.M1 through 9.0.100, from 8.5.0 through 8.5.100, from 7.0.0 through 7.0.109. Users are recommended to upgrade to version 11.0.5, 10.1.37 or 9.0.101, which fixes the issue.

CVSS3: 7.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3gv7-3h64-78cm

Exposure of Sensitive Information to an Unauthorized Actor in Apache Tomcat

CVSS3: 7.5
17%
Средний
около 4 лет назад
github логотип
GHSA-372q-33vh-8mpc

Inconsistent documentation in Apache Tomcat

CVSS3: 5.3
6%
Низкий
около 4 лет назад
github логотип
GHSA-36hp-4x3g-phrg

Apache Tomcat's CookieExample Vulnerable to XSS

3%
Низкий
около 4 лет назад
github логотип
GHSA-2w2w-cv3h-rr38

Apache Tomcat Reveals Path through Long URL

8%
Низкий
больше 4 лет назад
github логотип
GHSA-2c9m-w27f-53rm

Apache Tomcat vulnerable to Unprotected Transport of Credentials

CVSS3: 4.3
2%
Низкий
больше 3 лет назад
github логотип
GHSA-28cq-6rmx-pjq4

Improper Authentication in Apache Tomcat

12%
Средний
около 4 лет назад
github логотип
GHSA-27hp-xhwr-wr2m

Apache Tomcat Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability

9%
Низкий
больше 1 года назад
github логотип
GHSA-25xr-qj8w-c4vf

Apache Tomcat Coyote vulnerable to Denial of Service via excessive HTTP/2 streams

CVSS3: 7.5
2%
Низкий
около 1 года назад
github логотип
GHSA-24j9-x2wg-9qv6

Apache Tomcat: CLIENT_CERT authentication does not fail as expected

CVSS3: 6.5
0%
Низкий
4 месяца назад
github логотип
GHSA-23hv-mwm6-g8jf

Apache Tomcat Session Fixation vulnerability

CVSS3: 6.5
1%
Низкий
12 месяцев назад
ubuntu логотип
CVE-2026-59084

Insufficient Technical Documentation vulnerability in Apache Tomcat since the requirements to securely configure the EncryptInterceptor were not clearly documented. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.23, from 10.1.0-M1 through 10.1.56, from 9.0.13 through 9.0.119, from 8.5.38 through 8.5.100, from 7.0.100 through 7.0.109. Other versions that have reached end of support may also be affected. Users are recommended to upgrade to version 11.0.24, 10.1.57 or 9.0.120 which fix the issue.

CVSS3: 9.1
1%
Низкий
17 дней назад
redhat логотип
CVE-2026-59084

Insufficient Technical Documentation vulnerability in Apache Tomcat since the requirements to securely configure the EncryptInterceptor were not clearly documented. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.23, from 10.1.0-M1 through 10.1.56, from 9.0.13 through 9.0.119, from 8.5.38 through 8.5.100, from 7.0.100 through 7.0.109. Other versions that have reached end of support may also be affected. Users are recommended to upgrade to version 11.0.24, 10.1.57 or 9.0.120 which fix the issue.

CVSS3: 3.8
1%
Низкий
17 дней назад
nvd логотип
CVE-2026-59084

Insufficient Technical Documentation vulnerability in Apache Tomcat since the requirements to securely configure the EncryptInterceptor were not clearly documented. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.23, from 10.1.0-M1 through 10.1.56, from 9.0.13 through 9.0.119, from 8.5.38 through 8.5.100, from 7.0.100 through 7.0.109. Other versions that have reached end of support may also be affected. Users are recommended to upgrade to version 11.0.24, 10.1.57 or 9.0.120 which fix the issue.

CVSS3: 9.1
1%
Низкий
17 дней назад
debian логотип
CVE-2026-59084

Insufficient Technical Documentation vulnerability in Apache Tomcat si ...

CVSS3: 9.1
1%
Низкий
17 дней назад
ubuntu логотип
CVE-2026-59083

Improper Handling of URL Encoding (Hex Encoding) vulnerability in Apache Tomcat's rewrite valve allowed security constraint bypass for some configurations. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.23, from 10.1.0-M1 through 10.1.56, from 9.0.0.M1 through 9.0.119, from 8.5.0 through 8.5.100. Other versions that have reached end of support may also be affected. Users are recommended to upgrade to version 11.0.24, 10.1.57 or 9.0.120, which fix the issue.

CVSS3: 9.1
0%
Низкий
17 дней назад
redhat логотип
CVE-2026-59083

Improper Handling of URL Encoding (Hex Encoding) vulnerability in Apache Tomcat's rewrite valve allowed security constraint bypass for some configurations. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.23, from 10.1.0-M1 through 10.1.56, from 9.0.0.M1 through 9.0.119, from 8.5.0 through 8.5.100. Other versions that have reached end of support may also be affected. Users are recommended to upgrade to version 11.0.24, 10.1.57 or 9.0.120, which fix the issue.

CVSS3: 3.7
0%
Низкий
17 дней назад
nvd логотип
CVE-2026-59083

Improper Handling of URL Encoding (Hex Encoding) vulnerability in Apache Tomcat's rewrite valve allowed security constraint bypass for some configurations. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.23, from 10.1.0-M1 through 10.1.56, from 9.0.0.M1 through 9.0.119, from 8.5.0 through 8.5.100. Other versions that have reached end of support may also be affected. Users are recommended to upgrade to version 11.0.24, 10.1.57 or 9.0.120, which fix the issue.

CVSS3: 9.1
0%
Низкий
17 дней назад
debian логотип
CVE-2026-59083

Improper Handling of URL Encoding (Hex Encoding) vulnerability in Apac ...

CVSS3: 9.1
0%
Низкий
17 дней назад
ubuntu логотип
CVE-2026-55957

Missing Critical Step in Authentication vulnerability in Apache Tomcat when the JNDIRealm was configured to authenticate binds using GSSAPI allowed attackers to authenticate without provided the correct password. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.4, from 10.1.0-M1 through 10.1.36, from 9.0.0.M1 through 9.0.100, from 8.5.0 through 8.5.100, from 7.0.0 through 7.0.109. Users are recommended to upgrade to version 11.0.5, 10.1.37 or 9.0.101, which fixes the issue.

CVSS3: 7.3
3%
Низкий
около 1 месяца назад
nvd логотип
CVE-2026-55957

Missing Critical Step in Authentication vulnerability in Apache Tomcat when the JNDIRealm was configured to authenticate binds using GSSAPI allowed attackers to authenticate without provided the correct password. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.4, from 10.1.0-M1 through 10.1.36, from 9.0.0.M1 through 9.0.100, from 8.5.0 through 8.5.100, from 7.0.0 through 7.0.109. Users are recommended to upgrade to version 11.0.5, 10.1.37 or 9.0.101, which fixes the issue.

CVSS3: 7.3
3%
Низкий
около 1 месяца назад

Уязвимостей на страницу