Tomcat
Vendor:
First CVE: Jul 20, 2000 · Active for 26 years
265
Total CVEs
More Total CVEs than 100% of tracked products
10.2
Avg CVEs / Year
Higher CVE frequency than 96% of tracked products
6.1
Avg CVSS
Higher Avg CVSS than 24% of tracked products
2.3%
KEV Rate
Higher KEV Rate than 96% of tracked products
Trends Over Time
The number and severity of CVEs published that impact Tomcat over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jul 20, 2000
26 years ago
Most Recent CVE
Jul 14, 2026
10 days ago
CVE Severity & Scoring
Tomcat265 CVEs
53%
33%
All CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local12 (4.5%)
Network129 (48.7%)
Unknown124 (46.8%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low116 (43.8%)
High25 (9.4%)
Unknown124 (46.8%)
User Interaction
None127 (47.9%)
Unknown124 (46.8%)
Required14 (5.3%)
Privileges Required
Low19 (7.2%)
High1 (0.4%)
None121 (45.7%)
Unknown124 (46.8%)
Top CVEs
Signals from CVEs in this product scope (265 CVEs).
265 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-24813CRITICAL Path Equivalence: 'file.Name' (Internal Dot) leading to Remote Code Execution and/or Information disclosure and/or malicious content added to uploaded files via write enabled Defau | Mar 10, 2025 | 9.8 | 99 | YES | YES |
CVE-2020-1938CRITICAL When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomcat treats AJP connections as having higher trust than, for e | Feb 24, 2020 | 9.8 | 99 | YES | YES |
CVE-2017-12617HIGH When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTTP PUTs enabled (e.g. via setting the readonly initialisation | Oct 4, 2017 | 8.1 | 99 | YES | YES |
CVE-2017-12615HIGH When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g. via setting the readonly initialisation parameter of the Default to false) it was possible to upl | Sep 19, 2017 | 8.1 | 98 | YES | YES |
CVE-2023-44487HIGH The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through | Oct 10, 2023 | 7.5 | 97 | YES | YES |
CVE-2016-8735CRITICAL Remote code execution is possible with Apache Tomcat before 6.0.48, 7.x before 7.0.73, 8.x before 8.0.39, 8.5.x before 8.5.7, and 9.x before 9.0.0.M12 if JmxRemoteLifecycleListener | Apr 6, 2017 | 9.8 | 97 | YES | YES |
CVE-2019-0232HIGH When running on Windows with enableCmdLineArguments enabled, the CGI Servlet in Apache Tomcat 9.0.0.M1 to 9.0.17, 8.5.0 to 8.5.39 and 7.0.0 to 7.0.93 is vulnerable to Remote Code E | Apr 15, 2019 | 8.1 | 93 | NO | YES |
CVE-2014-0050HIGH MultipartStream.java in Apache Commons FileUpload before 1.3.1, as used in Apache Tomcat, JBoss Web, and other products, allows remote attackers to cause a denial of service (infin | Apr 1, 2014 | 7.5 | 85 | NO | YES |
CVE-2008-2938MEDIUM Directory traversal vulnerability in Apache Tomcat 4.1.0 through 4.1.37, 5.5.0 through 5.5.26, and 6.0.0 through 6.0.16, when allowLinking and UTF-8 are enabled, allows remote atta | Aug 13, 2008 | 4.3 | 84 | NO | YES |
CVE-2018-11784MEDIUM When the default servlet in Apache Tomcat versions 9.0.0.M1 to 9.0.11, 8.5.0 to 8.5.33 and 7.0.23 to 7.0.90 returned a redirect to a directory (e.g. redirecting to '/foo/' when the | Oct 4, 2018 | 4.3 | 83 | NO | YES |
Exploit Exposure
Signals from CVEs in this product scope (265 CVEs).
CISA KEV
6 CVEs
2.3% of CVEs· 96th percentile
Metasploit
12 CVEs
4.5% of CVEs· 96th percentile
Nuclei
16 CVEs
6.0% of CVEs· 97th percentile
ExploitDB
45 CVEs
17.0% of CVEs· 89th percentile
Social Chatter
Signals from CVEs in this product scope (265 CVEs).
Media Mentions
Signals from CVEs in this product scope (265 CVEs).
Top CNAs Publishing CVEs For Tomcat
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 9.0.96 | 1 | 6.1 | 1.7% | 0 | 0 |
| 9.0.9 | 1 | 4.3 | 57.3% | 0 | 0 |
| 9.0.8 | 1 | 4.3 | 57.3% | 0 | 0 |
| 9.0.74 | 1 | 7.5 | 1.1% | 0 | 0 |
| 9.0.7 | 1 | 4.3 | 57.3% | 0 | 0 |
| 9.0.6 | 1 | 4.3 | 57.3% | 0 | 0 |
| 9.0.5 | 1 | 4.3 | 57.3% | 0 | 0 |
| 9.0.44 | 1 | 7.5 | 6.9% | 0 | 0 |
| 9.0.4 | 2 | 5.4 | 36.0% | 0 | 0 |
| 9.0.39 | 1 | 7.5 | 24.6% | 0 | 0 |
| 9.0.38 | 1 | 7.5 | 24.6% | 0 | 0 |
| 9.0.37 | 2 | 5.9 | 40.9% | 0 | 0 |
| 9.0.36 | 2 | 5.9 | 40.9% | 0 | 0 |
| 9.0.35-3.57.3 | 1 | 7.5 | 24.6% | 0 | 0 |
| 9.0.35-3.39.1 | 1 | 7.5 | 24.6% | 0 | 0 |
| 9.0.35 | 1 | 4.3 | 57.3% | 0 | 0 |
| 9.0.34 | 1 | 4.3 | 57.3% | 0 | 0 |
| 9.0.33 | 1 | 4.3 | 57.3% | 0 | 0 |
| 9.0.32 | 1 | 4.3 | 57.3% | 0 | 0 |
| 9.0.31 | 1 | 4.3 | 57.3% | 0 | 0 |