CVE-2026-53404
- EPSS 0.58%
- Veröffentlicht 29.06.2026 20:39:45
- Zuletzt bearbeitet 02.07.2026 19:22:23
Always-Incorrect Control Flow Implementation vulnerability in Apache Tomcat's rewrite valve meant that if the first condition in an OR chain matched, subsequent non-OR conditions were skipped. This issue affects Apache Tomcat: from 11.0.0-M1 through...
CVE-2026-50229
- EPSS 4.25%
- Veröffentlicht 29.06.2026 20:36:24
- Zuletzt bearbeitet 02.07.2026 19:24:34
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in the number guess example for Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.22, from 10.1.0-M1 through 10.1.55, from 9.0.0.M...
CVE-2026-43515
- EPSS 1.14%
- Veröffentlicht 12.05.2026 15:33:23
- Zuletzt bearbeitet 15.05.2026 15:52:05
Improper Authorization vulnerability when multiple method constraints define an HTTP method for the same extension in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.21, from 10.1.0-M1 through 10.1.54, from 9.0.0.M1 thro...
CVE-2026-43514
- EPSS 0.35%
- Veröffentlicht 12.05.2026 15:32:09
- Zuletzt bearbeitet 14.05.2026 18:46:41
Observable Timing Discrepancy vulnerability when comparing AJP secret in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.21, from 10.1.0-M1 through 10.1.54, from 9.0.0.M1 through 9.0.117, from 8.5.0 through 8.5.100, from...
CVE-2026-43513
- EPSS 0.47%
- Veröffentlicht 12.05.2026 15:26:25
- Zuletzt bearbeitet 15.05.2026 15:53:14
Improper Handling of Case Sensitivity vulnerability in LockOutRealm in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.21, from 10.1.0-M1 through 10.1.54, from 9.0.0.M1 through 9.0.117, from 8.5.0 through 8.5.100, from 7...
CVE-2026-43512
- EPSS 1.23%
- Veröffentlicht 12.05.2026 15:24:02
- Zuletzt bearbeitet 15.05.2026 15:54:37
DEPRECATED: Authentication Bypass Issues vulnerability in digest authentication in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.21, from 10.1.0-M1 through 10.1.54, from 9.0.0.M1 through 9.0.117, from 8.5.0 through 8.5...
CVE-2026-41293
- EPSS 1.56%
- Veröffentlicht 12.05.2026 15:19:35
- Zuletzt bearbeitet 15.05.2026 15:57:18
Improper Input Validation vulnerability in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.21, from 10.1.0-M1 through 10.1.54, from 9.0.0.M1 through 9.0.117, from 10.0.0-M1 through 10.0.27. Older, end of support versions...
CVE-2026-42498
- EPSS 0.6%
- Veröffentlicht 12.05.2026 15:17:56
- Zuletzt bearbeitet 14.05.2026 18:51:59
Exposure of HTTP Authentication Header to unexpected hosts during WebSocket authentication vulnerability in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.21, from 10.1.0-M1 through 10.1.54, from 9.0.2 through 9.0.117, ...
CVE-2026-41284
- EPSS 0.78%
- Veröffentlicht 12.05.2026 15:14:45
- Zuletzt bearbeitet 14.05.2026 18:59:48
Allocation of Resources Without Limits or Throttling vulnerability in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.21, from 10.1.0-M1 through 10.1.54, from 9.0.0.M1 through 9.0.117. Older, unsupported versions may als...
CVE-2026-40075
- EPSS 0.56%
- Veröffentlicht 05.05.2026 22:16:00
- Zuletzt bearbeitet 24.07.2026 21:10:00
OpenMRS Core is an open source electronic medical record system platform. In versions 2.7.8 and earlier and versions 2.8.0 through 2.8.5, the `/openmrs/moduleResources/{moduleid}` endpoint is vulnerable to a path traversal attack. The ModuleResources...