Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2020-13934 |
|
Vulnerability in org.apache.tomcat:tomcat (CVE-2020-13934)
vulnerability in org.apache.tomcat:tomcat (CVE-2020-13934). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `8.5.56` or later.
|
| CVE-2021-33037 |
|
Vulnerability in apache (CVE-2021-33037)
vulnerability in apache (CVE-2021-33037). Risk of unauthorized operations or information disclosure.
|
| CVE-2021-25122 |
|
Information Disclosure in org.apache.tomcat.embed:tomcat-embed-core (CVE-2021-25122)
vulnerability in org.apache.tomcat.embed:tomcat-embed-core (CVE-2021-25122). Confidential information can be exposed externally. Mitigation: upgrade to `9.0.43` or later.
|
| CVE-2021-25329 |
|
Vulnerability in apache (CVE-2021-25329)
vulnerability in apache (CVE-2021-25329). Successful exploitation can lead to full system takeover.
|
| CVE-2021-24122 |
|
Information Disclosure in apache (CVE-2021-24122)
vulnerability in apache (CVE-2021-24122). Confidential information can be exposed externally.
|
| CVE-2020-36182 |
|
Unsafe Deserialization in apache (CVE-2020-36182)
vulnerability in apache (CVE-2020-36182). Successful exploitation can lead to full system takeover.
|
| CVE-2020-36184 |
|
Unsafe Deserialization in apache (CVE-2020-36184)
vulnerability in apache (CVE-2020-36184). Successful exploitation can lead to full system takeover.
|
| CVE-2020-36185 |
|
Unsafe Deserialization in apache (CVE-2020-36185)
vulnerability in apache (CVE-2020-36185). Successful exploitation can lead to full system takeover.
|
| CVE-2020-36186 |
|
Unsafe Deserialization in apache (CVE-2020-36186)
vulnerability in apache (CVE-2020-36186). Successful exploitation can lead to full system takeover.
|
| CVE-2020-36187 |
|
Unsafe Deserialization in apache (CVE-2020-36187)
vulnerability in apache (CVE-2020-36187). Successful exploitation can lead to full system takeover.
|
| CVE-2020-36181 |
|
Unsafe Deserialization in apache (CVE-2020-36181)
vulnerability in apache (CVE-2020-36181). Successful exploitation can lead to full system takeover.
|
| CVE-2020-9484 |
|
Unsafe Deserialization in org.apache.tomcat:tomcat-catalina (CVE-2020-9484)
vulnerability in org.apache.tomcat:tomcat-catalina (CVE-2020-9484). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `7.0.104` or later.
|
| CVE-2019-17569 |
|
Vulnerability in apache (CVE-2019-17569)
vulnerability in apache (CVE-2019-17569). Risk of unauthorized operations or information disclosure.
|
| CVE-2017-13990 |
|
Information Disclosure in express (CVE-2017-13990)
vulnerability in express (CVE-2017-13990). Risk of unauthorized operations or information disclosure.
|
| CVE-2017-12616 |
|
Information Disclosure in apache (CVE-2017-12616)
vulnerability in apache (CVE-2017-12616). Confidential information can be exposed externally.
|
| CVE-2014-9635 |
|
Vulnerability in tomcat (CVE-2014-9635)
vulnerability in tomcat (CVE-2014-9635). Risk of unauthorized operations or information disclosure. Exploitable via `Cookie header`.
|
| CVE-2014-9634 |
|
Vulnerability in tomcat (CVE-2014-9634)
vulnerability in tomcat (CVE-2014-9634). Risk of unauthorized operations or information disclosure.
|
| CVE-2017-14105 |
|
Vulnerability in tomcat (CVE-2017-14105)
vulnerability in tomcat (CVE-2017-14105). Successful exploitation can lead to full system takeover.
|
| CVE-2017-7675 |
|
Path Traversal in apache (CVE-2017-7675)
path traversal in apache (CVE-2017-7675). Confidential information can be exposed externally.
|
| CVE-2016-6796 |
|
Vulnerability in apache (CVE-2016-6796)
vulnerability in apache (CVE-2016-6796). Data can be tampered with by attackers.
|
| CVE-2017-7674 |
|
Vulnerability in apache (CVE-2017-7674)
vulnerability in apache (CVE-2017-7674). Risk of unauthorized operations or information disclosure.
|
| CVE-2016-6797 |
|
Authorization Flaw in apache (CVE-2016-6797)
vulnerability in apache (CVE-2016-6797). Confidential information can be exposed externally.
|
| CVE-2016-6817 |
|
Buffer Overflow in apache (CVE-2016-6817)
vulnerability in apache (CVE-2016-6817). Risk of unauthorized operations or information disclosure.
|
| CVE-2016-8745 |
|
Vulnerability in apache (CVE-2016-8745)
vulnerability in apache (CVE-2016-8745). Confidential information can be exposed externally.
|
| CVE-2016-6794 |
|
Vulnerability in apache (CVE-2016-6794)
vulnerability in apache (CVE-2016-6794). Risk of unauthorized operations or information disclosure.
|
| CVE-2016-0762 |
|
Vulnerability in apache (CVE-2016-0762)
vulnerability in apache (CVE-2016-0762). Confidential information can be exposed externally.
|
| CVE-2016-5018 |
|
Vulnerability in apache (CVE-2016-5018)
vulnerability in apache (CVE-2016-5018). Confidential information can be exposed externally.
|
| CVE-2017-7683 |
|
Information Disclosure in apache (CVE-2017-7683)
vulnerability in apache (CVE-2017-7683). Confidential information can be exposed externally.
|
| CVE-2017-6712 |
|
OS Command Injection in tomcat (CVE-2017-6712)
OS command injection in tomcat (CVE-2017-6712). Successful exploitation can lead to full system takeover.
|
| CVE-2015-1778 |
|
Authentication Bypass in org.opendaylight.odlparent:opendaylight-karaf-resources (CVE-2015-1778)
authentication bypass in org.opendaylight.odlparent:opendaylight-karaf-resources (CVE-2015-1778). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `0.2.3-Helium-SR3` or later.
|
| CVE-2017-6682 |
|
OS Command Injection in tomcat (CVE-2017-6682)
OS command injection in tomcat (CVE-2017-6682). Successful exploitation can lead to full system takeover.
|
| CVE-2017-6683 |
|
OS Command Injection in tomcat (CVE-2017-6683)
OS command injection in tomcat (CVE-2017-6683). Successful exploitation can lead to full system takeover.
|
| CVE-2017-5664 |
|
Vulnerability in apache (CVE-2017-5664)
vulnerability in apache (CVE-2017-5664). Data can be tampered with by attackers.
|
| CVE-2017-7428 |
|
Vulnerability in tomcat (CVE-2017-7428)
vulnerability in tomcat (CVE-2017-7428). Risk of unauthorized operations or information disclosure.
|
| CVE-2017-5647 |
|
Information Disclosure in c (CVE-2017-5647)
vulnerability in c (CVE-2017-5647). Confidential information can be exposed externally.
|
| CVE-2017-5648 |
|
Vulnerability in apache (CVE-2017-5648)
vulnerability in apache (CVE-2017-5648). Confidential information can be exposed externally.
|
| CVE-2017-5650 |
|
Vulnerability in apache (CVE-2017-5650)
vulnerability in apache (CVE-2017-5650). Risk of unauthorized operations or information disclosure.
|
| CVE-2017-5651 |
|
Vulnerability in apache (CVE-2017-5651)
vulnerability in apache (CVE-2017-5651). Successful exploitation can lead to full system takeover.
|
| CVE-2016-6808 |
|
Buffer overflow in Apache Tomcat Connectors (mod_jk) before 1.2.42.
Buffer overflow in Apache Tomcat Connectors (mod_jk) before 1.2.42.
|
| CVE-2016-9774 |
|
Vulnerability in tomcat (CVE-2016-9774)
vulnerability in tomcat (CVE-2016-9774). Successful exploitation can lead to full system takeover.
|
| CVE-2016-9775 |
|
Vulnerability in tomcat (CVE-2016-9775)
vulnerability in tomcat (CVE-2016-9775). Successful exploitation can lead to full system takeover.
|
| CVE-2016-6816 |
|
Vulnerability in apache (CVE-2016-6816)
vulnerability in apache (CVE-2016-6816). Risk of unauthorized operations or information disclosure.
|
| CVE-2017-6056 |
|
Vulnerability in apache (CVE-2017-6056)
vulnerability in apache (CVE-2017-6056). Risk of unauthorized operations or information disclosure.
|