CVE-2025-66614
- EPSS 0.05%
- Veröffentlicht 17.02.2026 18:48:30
- Zuletzt bearbeitet 11.03.2026 16:16:20
Improper Input Validation vulnerability. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.14, from 10.1.0-M1 through 10.1.49, from 9.0.0-M1 through 9.0.112. The following versions were EOL at the time the CVE was created but are known...
CVE-2025-63690
- EPSS 1.72%
- Veröffentlicht 07.11.2025 00:00:00
- Zuletzt bearbeitet 08.12.2025 16:10:04
In pig-mesh Pig versions 3.8.2 and below, when setting up scheduled tasks in the Quartz management function under the system management module, it is possible to execute any Java class with a parameterless constructor and its methods with parameter t...
CVE-2025-61795
- EPSS 0.12%
- Veröffentlicht 27.10.2025 17:30:28
- Zuletzt bearbeitet 12.05.2026 13:17:23
Improper Resource Shutdown or Release vulnerability in Apache Tomcat. If an error occurred (including exceeding limits) during the processing of a multipart upload, temporary copies of the uploaded parts written to disc were not cleaned up immediate...
CVE-2025-55752
- EPSS 0.14%
- Veröffentlicht 27.10.2025 17:29:56
- Zuletzt bearbeitet 12.05.2026 13:17:22
Relative Path Traversal vulnerability in Apache Tomcat. The fix for bug 60013 introduced a regression where the rewritten URL was normalized before it was decoded. This introduced the possibility that, for rewrite rules that rewrite quer...
CVE-2025-55754
- EPSS 0.12%
- Veröffentlicht 27.10.2025 17:29:50
- Zuletzt bearbeitet 12.05.2026 13:17:22
Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in Apache Tomcat. Tomcat did not escape ANSI escape sequences in log messages. If Tomcat was running in a console on a Windows operating system, and the console supported AN...
CVE-2025-55668
- EPSS 0.02%
- Veröffentlicht 13.08.2025 13:21:35
- Zuletzt bearbeitet 04.11.2025 22:16:30
Session Fixation vulnerability in Apache Tomcat via rewrite valve. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.7, from 10.1.0-M1 through 10.1.41, from 9.0.0.M1 through 9.0.105. Older, EOL versions may also be affected. Users are r...
CVE-2025-48989
- EPSS 0.98%
- Veröffentlicht 13.08.2025 12:11:26
- Zuletzt bearbeitet 12.05.2026 13:17:20
Improper Resource Shutdown or Release vulnerability in Apache Tomcat made Tomcat vulnerable to the made you reset attack. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.9, from 10.1.0-M1 through 10.1.43 and from 9.0.0.M1 through 9.0.1...
CVE-2025-53506
- EPSS 1.25%
- Veröffentlicht 10.07.2025 19:14:23
- Zuletzt bearbeitet 04.11.2025 22:16:21
Uncontrolled Resource Consumption vulnerability in Apache Tomcat if an HTTP/2 client did not acknowledge the initial settings frame that reduces the maximum permitted concurrent streams. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0....
CVE-2025-52520
- EPSS 0.68%
- Veröffentlicht 10.07.2025 19:05:41
- Zuletzt bearbeitet 04.11.2025 22:16:20
For some unlikely configurations of multipart upload, an Integer Overflow vulnerability in Apache Tomcat could lead to a DoS via bypassing of size limits. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.8, from 10.1.0-M1 through 10.1.4...
CVE-2025-52434
- EPSS 1.21%
- Veröffentlicht 10.07.2025 19:03:47
- Zuletzt bearbeitet 04.11.2025 22:16:20
Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability in Apache Tomcat when using the APR/Native connector. This was particularly noticeable with client initiated closes of HTTP/2 connections. This...