Tomcat

Vendor:

First CVE: Jul 20, 2000 · Active for 26 years

265
Total CVEs
More Total CVEs than 100% of tracked products
10.2
Avg CVEs / Year
Higher CVE frequency than 96% of tracked products
6.1
Avg CVSS
Higher Avg CVSS than 24% of tracked products
2.3%
KEV Rate
Higher KEV Rate than 96% of tracked products

Trends Over Time

The number and severity of CVEs published that impact Tomcat over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jul 20, 2000
26 years ago
Most Recent CVE
Jul 14, 2026
10 days ago

CVE Severity & Scoring

Tomcat265 CVEs
All CVEs352,231 CVEs
LowMediumHighCritical
Attack Vector
Local12 (4.5%)
Network129 (48.7%)
Unknown124 (46.8%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low116 (43.8%)
High25 (9.4%)
Unknown124 (46.8%)
User Interaction
None127 (47.9%)
Unknown124 (46.8%)
Required14 (5.3%)
Privileges Required
Low19 (7.2%)
High1 (0.4%)
None121 (45.7%)
Unknown124 (46.8%)

Top CVEs

Signals from CVEs in this product scope (265 CVEs).

265 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Path Equivalence: 'file.Name' (Internal Dot) leading to Remote Code Execution and/or Information disclosure and/or malicious content added to uploaded files via write enabled Defau
Mar 10, 20259.899YESYES
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomcat treats AJP connections as having higher trust than, for e
Feb 24, 20209.899YESYES
When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTTP PUTs enabled (e.g. via setting the readonly initialisation
Oct 4, 20178.199YESYES
When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g. via setting the readonly initialisation parameter of the Default to false) it was possible to upl
Sep 19, 20178.198YESYES
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through
Oct 10, 20237.597YESYES
Remote code execution is possible with Apache Tomcat before 6.0.48, 7.x before 7.0.73, 8.x before 8.0.39, 8.5.x before 8.5.7, and 9.x before 9.0.0.M12 if JmxRemoteLifecycleListener
Apr 6, 20179.897YESYES
When running on Windows with enableCmdLineArguments enabled, the CGI Servlet in Apache Tomcat 9.0.0.M1 to 9.0.17, 8.5.0 to 8.5.39 and 7.0.0 to 7.0.93 is vulnerable to Remote Code E
Apr 15, 20198.193NOYES
MultipartStream.java in Apache Commons FileUpload before 1.3.1, as used in Apache Tomcat, JBoss Web, and other products, allows remote attackers to cause a denial of service (infin
Apr 1, 20147.585NOYES
Directory traversal vulnerability in Apache Tomcat 4.1.0 through 4.1.37, 5.5.0 through 5.5.26, and 6.0.0 through 6.0.16, when allowLinking and UTF-8 are enabled, allows remote atta
Aug 13, 20084.384NOYES
When the default servlet in Apache Tomcat versions 9.0.0.M1 to 9.0.11, 8.5.0 to 8.5.33 and 7.0.23 to 7.0.90 returned a redirect to a directory (e.g. redirecting to '/foo/' when the
Oct 4, 20184.383NOYES

Exploit Exposure

Signals from CVEs in this product scope (265 CVEs).

CISA KEV
6 CVEs
2.3% of CVEs· 96th percentile
Metasploit
12 CVEs
4.5% of CVEs· 96th percentile
Nuclei
16 CVEs
6.0% of CVEs· 97th percentile
ExploitDB
45 CVEs
17.0% of CVEs· 89th percentile

Social Chatter

Signals from CVEs in this product scope (265 CVEs).

Media Mentions

Signals from CVEs in this product scope (265 CVEs).

Top CNAs Publishing CVEs For Tomcat

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
9.0.9616.11.7%00
9.0.914.357.3%00
9.0.814.357.3%00
9.0.7417.51.1%00
9.0.714.357.3%00
9.0.614.357.3%00
9.0.514.357.3%00
9.0.4417.56.9%00
9.0.425.436.0%00
9.0.3917.524.6%00
9.0.3817.524.6%00
9.0.3725.940.9%00
9.0.3625.940.9%00
9.0.35-3.57.317.524.6%00
9.0.35-3.39.117.524.6%00
9.0.3514.357.3%00
9.0.3414.357.3%00
9.0.3314.357.3%00
9.0.3214.357.3%00
9.0.3114.357.3%00