Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-66422 |
|
Vulnerability in apache (CVE-2026-66422)
vulnerability in apache (CVE-2026-66422). Data can be tampered with by attackers.
|
| CVE-2026-65637 |
|
Vulnerability in apache (CVE-2026-65637)
vulnerability in apache (CVE-2026-65637). Successful exploitation can lead to full system takeover.
|
| CVE-2026-68763 |
|
Vulnerability in apache (CVE-2026-68763)
vulnerability in apache (CVE-2026-68763). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-65183 |
|
Vulnerability in apache (CVE-2026-65183)
vulnerability in apache (CVE-2026-65183). Successful exploitation can lead to full system takeover.
|
| CVE-2026-65927 |
|
Vulnerability in apache (CVE-2026-65927)
vulnerability in apache (CVE-2026-65927). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-65905 |
|
Vulnerability in apache (CVE-2026-65905)
vulnerability in apache (CVE-2026-65905). Successful exploitation can lead to full system takeover.
|
| CVE-2026-65182 |
|
Vulnerability in apache (CVE-2026-65182)
vulnerability in apache (CVE-2026-65182). Confidential information can be exposed externally.
|
| CVE-2026-73180 |
|
Vulnerability in apache (CVE-2026-73180)
vulnerability in apache (CVE-2026-73180). Confidential information can be exposed externally.
|
| CVE-2026-68569 |
|
Authentication Bypass in apache (CVE-2026-68569)
authentication bypass in apache (CVE-2026-68569). Confidential information can be exposed externally.
|
| CVE-2026-68525 |
|
Authorization Flaw in apache (CVE-2026-68525)
vulnerability in apache (CVE-2026-68525). Confidential information can be exposed externally.
|
| CVE-2026-48528 |
|
SQL Injection in tomcat (CVE-2026-48528)
SQL injection in tomcat (CVE-2026-48528). Successful exploitation can lead to full system takeover. Exploitable via ``nodeId``.
|
| CVE-2026-47754 |
|
Path Traversal in tomcat (CVE-2026-47754)
path traversal in tomcat (CVE-2026-47754). Confidential information can be exposed externally. Exploitable via ``archiveEntryName``.
|
| CVE-2026-66713 |
|
Unsafe Deserialization in apache (CVE-2026-66713)
vulnerability in apache (CVE-2026-66713). Successful exploitation can lead to full system takeover.
|
| CVE-2026-66299 |
|
Vulnerability in apache (CVE-2026-66299)
vulnerability in apache (CVE-2026-66299). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-18047 |
|
Vulnerability in tomcat (CVE-2026-18047)
vulnerability in tomcat (CVE-2026-18047). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-59084 |
|
Vulnerability in apache (CVE-2026-59084)
vulnerability in apache (CVE-2026-59084). Confidential information can be exposed externally.
|
| CVE-2026-59083 |
|
Vulnerability in apache (CVE-2026-59083)
vulnerability in apache (CVE-2026-59083). Confidential information can be exposed externally.
|
| CVE-2026-55955 |
|
Authentication Bypass in tomcat (CVE-2026-55955)
authentication bypass in tomcat (CVE-2026-55955). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `9.0.119, 10.1.56, 11.0.23` or later.
|
| CVE-2026-55957 |
|
Vulnerability in tomcat (CVE-2026-55957)
vulnerability in tomcat (CVE-2026-55957). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `9.0.101, 10.1.37, 11.0.5` or later.
|
| CVE-2026-55276 |
|
Vulnerability in tomcat (CVE-2026-55276)
vulnerability in tomcat (CVE-2026-55276). Confidential information can be exposed externally. Mitigation: upgrade to `9.0.119, 10.1.56, 11.0.23` or later.
|
| CVE-2026-55956 |
|
Vulnerability in tomcat (CVE-2026-55956)
vulnerability in tomcat (CVE-2026-55956). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `9.0.119, 10.1.56, 11.0.23` or later.
|
| CVE-2026-53404 |
|
Vulnerability in tomcat (CVE-2026-53404)
vulnerability in tomcat (CVE-2026-53404). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `9.0.101, 10.1.37, 11.0.5` or later.
|
| CVE-2026-50229 |
|
Vulnerability in tomcat (CVE-2026-50229)
vulnerability in tomcat (CVE-2026-50229). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `9.0.101, 10.1.37, 11.0.5` or later.
|
| CVE-2026-53434 |
|
Vulnerability in tomcat (CVE-2026-53434)
vulnerability in tomcat (CVE-2026-53434). Confidential information can be exposed externally. Mitigation: upgrade to `9.0.101, 10.1.37, 11.0.5` or later.
|
| CVE-2026-44257 |
|
Command Injection in tomcat (CVE-2026-44257)
command injection in tomcat (CVE-2026-44257). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `4.08.010` or later.
|
| CVE-2026-43515 |
|
Vulnerability in tomcat (CVE-2026-43515)
vulnerability in tomcat (CVE-2026-43515). Confidential information can be exposed externally. Mitigation: upgrade to `10.1.55, 11.0.22, 9.0.118` or later.
|
| CVE-2026-43514 |
|
Vulnerability in tomcat (CVE-2026-43514)
vulnerability in tomcat (CVE-2026-43514). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `10.1.55, 11.0.22, 9.0.118` or later.
|
| CVE-2026-43513 |
|
Vulnerability in tomcat (CVE-2026-43513)
vulnerability in tomcat (CVE-2026-43513). Confidential information can be exposed externally. Mitigation: upgrade to `10.1.55, 11.0.22, 9.0.118` or later.
|
| CVE-2026-43512 |
|
Authentication Bypass in tomcat (CVE-2026-43512)
authentication bypass in tomcat (CVE-2026-43512). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `10.1.55, 11.0.22, 9.0.118` or later.
|
| CVE-2026-42498 |
|
Information Disclosure in tomcat (CVE-2026-42498)
vulnerability in tomcat (CVE-2026-42498). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `10.1.55, 11.0.22, 9.0.118` or later.
|
| CVE-2026-41293 |
|
Vulnerability in tomcat (CVE-2026-41293)
vulnerability in tomcat (CVE-2026-41293). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `10.1.55, 11.0.22, 9.0.118` or later.
|
| CVE-2026-41284 |
|
Vulnerability in tomcat (CVE-2026-41284)
vulnerability in tomcat (CVE-2026-41284). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `10.1.55, 11.0.22, 9.0.118` or later.
|
| CVE-2026-40075 |
|
Path Traversal in org.openmrs.web:openmrs-web (CVE-2026-40075)
path traversal in org.openmrs.web:openmrs-web (CVE-2026-40075). Confidential information can be exposed externally. Exploitable via ``ModuleResourcesServlet``. Mitigation: upgrade to `2.8.6` or later.
|
| CVE-2026-34486 KEV |
|
[KEV] Vulnerability in Apache tomcat (CVE-2026-34486)
vulnerability in Apache tomcat (CVE-2026-34486). Confidential information can be exposed externally. Listed in CISA KEV — actively exploited. Mitigation: upgrade to `9.0.117, 10.1.54, 11.0.21` or later.
|
| CVE-2026-29146 |
|
Vulnerability in apache (CVE-2026-29146)
vulnerability in apache (CVE-2026-29146). Confidential information can be exposed externally.
|
| CVE-2016-20026 |
|
Vulnerability in apache (CVE-2016-20026)
vulnerability in apache (CVE-2016-20026). Successful exploitation can lead to full system takeover.
|
| CVE-2026-24734 |
|
Vulnerability in apache (CVE-2026-24734)
vulnerability in apache (CVE-2026-24734). Data can be tampered with by attackers.
|
| CVE-2025-61795 |
|
Vulnerability in org.apache.tomcat:tomcat (CVE-2025-61795)
vulnerability in org.apache.tomcat:tomcat (CVE-2025-61795). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `9.0.110, 10.1.47, 11.0.12` or later.
|
| CVE-2025-55752 |
|
Vulnerability in org.apache.tomcat:tomcat (CVE-2025-55752)
vulnerability in org.apache.tomcat:tomcat (CVE-2025-55752). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `9.0.109, 10.1.45, 11.0.11` or later.
|
| CVE-2025-55754 |
|
Vulnerability in org.apache.tomcat:tomcat (CVE-2025-55754)
vulnerability in org.apache.tomcat:tomcat (CVE-2025-55754). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `9.0.109, 10.1.45, 11.0.11` or later.
|
| CVE-2025-48989 |
|
Vulnerability in org.apache.tomcat:tomcat-coyote (CVE-2025-48989)
vulnerability in org.apache.tomcat:tomcat-coyote (CVE-2025-48989). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `9.0.108` or later.
|
| CVE-2025-24813 KEV |
|
[KEV] Vulnerability in Apache tomcat (CVE-2025-24813)
vulnerability in Apache tomcat (CVE-2025-24813). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2023-47246 KEV |
|
[KEV] Path Traversal in Sysaid tomcat (CVE-2023-47246)
path traversal in Sysaid tomcat (CVE-2023-47246). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2023-44487 KEV |
|
[KEV] Vulnerability in Ietf golang.org/x/net (CVE-2023-44487)
vulnerability in Ietf golang.org/x/net (CVE-2023-44487). Risk of unauthorized operations or information disclosure. Exploitable via ``Channel``. Listed in CISA KEV — actively exploited. Mitigation: upgrade to `0.17.0` or later.
|
| CVE-2016-8735 KEV |
|
[KEV] Vulnerability in Apache tomcat (CVE-2016-8735)
vulnerability in Apache tomcat (CVE-2016-8735). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2022-25762 |
|
Vulnerability in org.apache.tomcat:tomcat (CVE-2022-25762)
vulnerability in org.apache.tomcat:tomcat (CVE-2022-25762). Confidential information can be exposed externally. Mitigation: upgrade to `9.0.20` or later.
|
| CVE-2017-12615 KEV |
|
[KEV] Unrestricted File Upload in Apache tomcat (CVE-2017-12615)
vulnerability in Apache tomcat (CVE-2017-12615). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2017-12617 KEV |
|
[KEV] Unrestricted File Upload in Apache tomcat (CVE-2017-12617)
vulnerability in Apache tomcat (CVE-2017-12617). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2020-1938 KEV |
|
[KEV] Privilege Escalation in org.apache.tomcat.embed:tomcat-embed-core (CVE-2020-1938)
vulnerability in org.apache.tomcat.embed:tomcat-embed-core (CVE-2020-1938). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited. Mitigation: upgrade to `7.0.100` or later.
|
| CVE-2020-13935 |
|
Vulnerability in org.apache.tomcat:tomcat (CVE-2020-13935)
vulnerability in org.apache.tomcat:tomcat (CVE-2020-13935). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `7.0.105` or later.
|