Vulnerability Name CVE Severity
Apache OFBiz SSRF (CVE-2023-50968) CVE-2023-50968
Apache OFBiz XMLRPC Deserialization RCE (CVE-2020-9496/CVE-2023-49070) CVE-2020-9496 CVE-2023-49070
Apache REST RCE CVE-2018-11770 CVE-2018-11770
Apache Roller OGNL injection CVE-2013-4212
Apache Shiro authentication bypass CVE-2020-17523
Apache Shiro Deserialization RCE CVE-2016-4437
Apache Solr Deserialization of untrusted data via jmx.serviceUrl CVE-2019-0192
Apache Solr Log4Shell RCE CVE-2021-44228
Apache solr service exposed
Apache Spark Master Unauthorized Access Vulnerability
Apache Struts 2 ClassLoader manipulation and denial of service CVE-2014-0112 CVE-2014-0113 CVE-2014-0114
Apache Struts 2 ClassLoader manipulation and denial of service (S2-020) CVE-2014-0094 CVE-2014-0050
Apache Struts2 Remote Command Execution (S2-048) CVE-2017-9791
Apache Struts2 Remote Command Execution (S2-052) CVE-2017-9805
Apache Struts Remote Code Execution (S2-057) CVE-2018-11776
Apache Tapestry Unauthenticated RCE (CVE-2019-0195, CVE-2021-27850) CVE-2021-27850
Apache Tapestry weak secret key
Apache Tomcat 7PK - Errors Vulnerability (CVE-2016-8745) CVE-2016-8745
Apache Tomcat 7PK - Security Features Vulnerability (CVE-2002-0493) CVE-2002-0493
Apache Tomcat Allocation of Resources Without Limits or Throttling Vulnerability (CVE-2024-38286) CVE-2024-38286
Apache Tomcat Allocation of Resources Without Limits or Throttling Vulnerability (CVE-2025-48988) CVE-2025-48988
Apache Tomcat Allocation of Resources Without Limits or Throttling Vulnerability (CVE-2026-41284) CVE-2026-41284
Apache Tomcat Authentication Bypass Using an Alternate Path or Channel Vulnerability (CVE-2025-49125) CVE-2025-49125
Apache Tomcat Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') Vulnerability (CVE-2025-52434) CVE-2025-52434
Apache Tomcat Credentials Management Errors Vulnerability (CVE-2009-3548) CVE-2009-3548
Apache Tomcat Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2015-5351) CVE-2015-5351
Apache Tomcat CVE-2020-0822 Vulnerability (CVE-2020-0822) CVE-2020-0822
Apache Tomcat CVE-2022-29885 Vulnerability (CVE-2022-29885) CVE-2022-29885
Apache Tomcat CVE-2023-34981 Vulnerability (CVE-2023-34981) CVE-2023-34981
Apache Tomcat CVE-2023-44487 Vulnerability (CVE-2023-44487) CVE-2023-44487
Apache Tomcat CVE-2024-24549 Vulnerability (CVE-2024-24549) CVE-2024-24549
Apache Tomcat CVE-2026-24734 Vulnerability (CVE-2026-24734) CVE-2026-24734
Apache Tomcat Deserialization of Untrusted Data Vulnerability (CVE-2020-9484) CVE-2020-9484
Apache Tomcat Deserialization of Untrusted Data Vulnerability (CVE-2021-25329) CVE-2021-25329
Apache Tomcat Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2005-4836) CVE-2005-4836
Apache Tomcat Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2016-8747) CVE-2016-8747
Apache Tomcat Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2017-5647) CVE-2017-5647
Apache Tomcat Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2017-12616) CVE-2017-12616
Apache Tomcat Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2020-17527) CVE-2020-17527
Apache Tomcat Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2021-25122) CVE-2021-25122
Apache Tomcat Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2026-42498) CVE-2026-42498
Apache Tomcat Generation of Error Message Containing Sensitive Information Vulnerability (CVE-2026-29146) CVE-2026-29146
Apache Tomcat Improper Access Control Vulnerability (CVE-2016-5388) CVE-2016-5388
Apache Tomcat Improper Certificate Validation Vulnerability (CVE-2018-8034) CVE-2018-8034
Apache Tomcat Improper Encoding or Escaping of Output Vulnerability (CVE-2022-45143) CVE-2022-45143
Apache Tomcat Improper Encoding or Escaping of Output Vulnerability (CVE-2026-34483) CVE-2026-34483
Apache Tomcat Improper Handling of Case Sensitivity Vulnerability (CVE-2025-46701) CVE-2025-46701
Apache Tomcat Improper Handling of Case Sensitivity Vulnerability (CVE-2026-43513) CVE-2026-43513
Apache Tomcat Improper Handling of Exceptional Conditions Vulnerability (CVE-2017-5664) CVE-2017-5664
Apache Tomcat Improper Handling of Exceptional Conditions Vulnerability (CVE-2021-30639) CVE-2021-30639
Apache Tomcat Improper Input Validation Vulnerability (CVE-2013-2185) CVE-2013-2185
Apache Tomcat Improper Input Validation Vulnerability (CVE-2016-1240) CVE-2016-1240
Apache Tomcat Improper Input Validation Vulnerability (CVE-2016-3092) CVE-2016-3092
Apache Tomcat Improper Input Validation Vulnerability (CVE-2016-6816) CVE-2016-6816
Apache Tomcat Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Vulnerability (CVE-2017-7675) CVE-2017-7675
Apache Tomcat Improper Link Resolution Before File Access ('Link Following') Vulnerability (CVE-2016-9774) CVE-2016-9774
Apache Tomcat Improper Locking Vulnerability (CVE-2019-10072) CVE-2019-10072
Apache Tomcat Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') Vulnerability (CVE-2019-0232) CVE-2019-0232
Apache Tomcat Improper Resource Shutdown or Release Vulnerability (CVE-2017-5650) CVE-2017-5650
Apache Tomcat Improper Resource Shutdown or Release Vulnerability (CVE-2022-25762) CVE-2022-25762
Apache Tomcat Improper Resource Shutdown or Release Vulnerability (CVE-2025-48989) CVE-2025-48989
Apache Tomcat Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability (CVE-2002-2272) CVE-2002-2272
Apache Tomcat Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability (CVE-2016-6817) CVE-2016-6817
Apache Tomcat Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability (CVE-2020-13934) CVE-2020-13934
Apache Tomcat Incomplete Cleanup Vulnerability (CVE-2025-31650) CVE-2025-31650
Apache Tomcat Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') Vulnerability (CVE-2022-42252) CVE-2022-42252
Apache Tomcat Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') Vulnerability (CVE-2023-46589) CVE-2023-46589
Apache Tomcat Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') Vulnerability (CVE-2026-24880) CVE-2026-24880
Apache Tomcat Incorrect Authorization Vulnerability (CVE-2016-6797) CVE-2016-6797
Apache Tomcat Incorrect Default Permissions Vulnerability (CVE-2020-8022) CVE-2020-8022
Apache Tomcat Information Disclosure CVE-2017-7674 CVE-2017-12616
Apache Tomcat insecure default administrative password CVE-2009-3548
Apache Tomcat Insertion of Sensitive Information into Log File Vulnerability (CVE-2026-34487) CVE-2026-34487
Apache Tomcat Insufficiently Protected Credentials Vulnerability (CVE-2019-12418) CVE-2019-12418
Apache Tomcat Integer Overflow or Wraparound Vulnerability (CVE-2015-8751) CVE-2015-8751