Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
315 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.4) | 0.36% | — | Apache Tomcat | 16/6/2025 | 17/6/2026 | Untrusted Search Path vulnerability in Apache Tomcat installer for Windows. During installation, the Tomcat installer for Windows used icacls.exe without specifying a full path. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.7, from 10.1.0 through 10.1.41, from 9.0.23 through 9.0.105. The following… | |
| Modificada | Alta (7.5) | 31% | 💥 PoC | Apache Tomcat | 16/6/2025 | 17/6/2026 | Allocation of Resources Without Limits or Throttling vulnerability in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.7, from 10.1.0-M1 through 10.1.41, from 9.0.0.M1 through 9.0.105. The following versions were EOL at the time the CVE was created but are known to be affected: 8.5.0 though… | |
| Modificada | Alta (7.3) | 2.9% | 💥 PoC | Apache Tomcat | 29/5/2025 | 17/6/2026 | Improper Handling of Case Sensitivity vulnerability in Apache Tomcat's GCI servlet allows security constraint bypass of security constraints that apply to the pathInfo component of a URI mapped to the CGI servlet. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.6, from 10.1.0-M1 through 10.1.40, from… | |
| Modificada | Crítica (9.8) | 4.2% | 💥 PoC | Apache Tomcat | 28/4/2025 | 17/6/2026 | Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in Apache Tomcat. For a subset of unlikely rewrite rule configurations, it was possible for a specially crafted request to bypass some rewrite rules. If those rewrite rules effectively enforced security constraints, those constraints could be… | |
| Modificada | Alta (7.5) | 61% | 💥 Exploit | Apache Tomcat | 28/4/2025 | 17/6/2026 | Improper Input Validation vulnerability in Apache Tomcat. Incorrect error handling for some invalid HTTP priority headers resulted in incomplete clean-up of the failed request which created a memory leak. A large number of such requests could trigger an OutOfMemoryException resulting in a denial of service. This issue… | |
| Analizada | Crítica (9.8) | 100% | ⚠ Explotación activa💥 Exploit | Apache TomcatDebian LinuxNetapp Bootstrap OS | 10/3/2025 | 17/6/2026 | Path Equivalence: 'file.Name' (Internal Dot) leading to Remote Code Execution and/or Information disclosure and/or malicious content added to uploaded files via write enabled Default Servlet in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.2, from 10.1.0-M1 through 10.1.34, from 9.0.0.M1… | |
| Modificada | Crítica (9.8) | 9.0% | — | Apache TomcatNetapp Bootstrap OS | 20/12/2024 | 17/6/2026 | Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.1, from 10.1.0-M1 through 10.1.33, from 9.0.0.M1 through 9.0.97. The following versions were EOL at the time the CVE was created but are known to be affected: 8.5.0 though… | |
| Modificada | Media (5.3) | 1.9% | — | Apache TomcatNetapp Bootstrap OS | 17/12/2024 | 17/6/2026 | Uncontrolled Resource Consumption vulnerability in the examples web application provided with Apache Tomcat leads to denial of service. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.1, from 10.1.0-M1 through 10.1.33, from 9.0.0.M1 through 9.9.97. The following versions were EOL at the time the CVE was… | |
| Modificada | Crítica (9.8) | 32% | 💥 PoC | Apache TomcatNetapp Bootstrap OS | 17/12/2024 | 17/6/2026 | Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability during JSP compilation in Apache Tomcat permits an RCE on case insensitive file systems when the default servlet is enabled for write (non-default configuration). This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.1, from 10.1.0-M1 through… | |
| Analizada | Media (6.1) | 1.7% | 💥 PoC | Apache Tomcat | 18/11/2024 | 17/6/2026 | Incorrect object recycling and reuse vulnerability in Apache Tomcat. This issue affects Apache Tomcat: 11.0.0, 10.1.31, 9.0.96. Users are recommended to upgrade to version 11.0.1, 10.1.32 or 9.0.97, which fixes the issue. | |
| Analizada | Media (6.5) | 2.1% | 💥 PoC | Apache Tomcat | 18/11/2024 | 17/6/2026 | Incorrect object re-cycling and re-use vulnerability in Apache Tomcat. Incorrect recycling of the request and response used by HTTP/2 requests could lead to request and/or response mix-up between users. This issue affects Apache Tomcat: from 11.0.0-M23 through 11.0.0-M26, from 10.1.27 through 10.1.30, from 9.0.92… | |
| Analizada | Crítica (9.8) | 6.2% | 💥 PoC | Apache TomcatDebian Linux | 18/11/2024 | 17/6/2026 | Unchecked Error Condition vulnerability in Apache Tomcat. If Tomcat is configured to use a custom Jakarta Authentication (formerly JASPIC) ServerAuthContext component which may throw an exception during the authentication process without explicitly setting an HTTP status to indicate failure, the authentication may not… | |
| Modificada | Alta (7.5) | 1.7% | — | Apache TomcatNetapp Ontap Tools | 7/11/2024 | 17/6/2026 | Allocation of Resources Without Limits or Throttling vulnerability in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.0-M20, from 10.1.0-M1 through 10.1.24, from 9.0.13 through 9.0.89. The following versions were EOL at the time the CVE was created but are known to be affected: 8.5.35… | |
| Aplazada | Alta (7.8) | 0.18% | — | Apache TomcatAI | 16/10/2024 | 17/6/2026 | Insecure permissions in the packaging of tomcat allow local users that win a race during package installation to escalate to root | |
| Analizada | Media (5.9) | 0.33% | — | Apache Tomcat ConnectorsDebian Linux | 23/9/2024 | 17/6/2026 | Incorrect Default Permissions vulnerability in Apache Tomcat Connectors allows local users to view and modify shared memory containing mod_jk configuration which may lead to information disclosure and/or denial of service. This issue affects Apache Tomcat Connectors: from 1.2.9-beta through 1.2.49. Only mod_jk on Unix… | |
| Aplazada | Alta (7.5) | 15% | 💥 Exploit | Apache TomcatAIEclipse JettyAIVmware FrameworkAI | 13/9/2024 | 17/6/2026 | Applications serving static resources through the functional web frameworks WebMvc.fn or WebFlux.fn are vulnerable to path traversal attacks. An attacker can craft malicious HTTP requests and obtain any file on the file system that is also accessible to the process in which the Spring application is running.… | |
| Modificada | Alta (7.5) | 4.6% | — | Apache TomcatNetapp Ontap Tools | 3/7/2024 | 17/6/2026 | Improper Handling of Exceptional Conditions, Uncontrolled Resource Consumption vulnerability in Apache Tomcat. When processing an HTTP/2 stream, Tomcat did not handle some cases of excessive HTTP headers correctly. This led to a miscounting of active HTTP/2 streams which in turn led to the use of an incorrect infinite… | |
| Aplazada | Alta (7.5) | 0.54% | — | Apache TomcatAIBradwenqiang HRAI | 19/3/2024 | 17/6/2026 | A Information Exposure Vulnerability has been found on Meta4 HR. This vulnerability allows an attacker to obtain a lot of information about the application such as the variables set in the process, the Tomcat versions, library versions and underlying operation system via HTTP GET '/sitetest/english/dumpenv.jsp'. | |
| Modificada | Alta (7.5) | 23% | 💥 PoC | Apache TomcatDebian LinuxFedoraproject Fedora | 13/3/2024 | 17/6/2026 | Denial of Service due to improper input validation vulnerability for HTTP/2 requests in Apache Tomcat. When processing an HTTP/2 request, if the request exceeded any of the configured limits for headers, the associated HTTP/2 stream was not reset until after all of the headers had been processed.This issue affects… | |
| Modificada | Media (6.3) | 2.3% | — | Apache TomcatDebian LinuxFedoraproject Fedora | 13/3/2024 | 17/6/2026 | Denial of Service via incomplete cleanup vulnerability in Apache Tomcat. It was possible for WebSocket clients to keep WebSocket connections open leading to increased resource consumption.This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.0-M16, from 10.1.0-M1 through 10.1.18, from 9.0.0-M1 through 9.0.85,… | |
| Modificada | Media (5.3) | 14% | 💥 PoC | Apache Tomcat | 19/1/2024 | 17/6/2026 | Generation of Error Message Containing Sensitive Information vulnerability in Apache Tomcat.This issue affects Apache Tomcat: from 8.5.7 through 8.5.63, from 9.0.0-M11 through 9.0.43. Other, EOL versions may also be affected. Users are recommended to upgrade to version 8.5.64 onwards or 9.0.44 onwards, which contain a… | |
| Modificada | Alta (7.5) | 2.7% | — | Apache Tomcat | 28/11/2023 | 17/6/2026 | Improper Input Validation vulnerability in Apache Tomcat.Tomcat from 11.0.0-M1 through 11.0.0-M10, from 10.1.0-M1 through 10.1.15, from 9.0.0-M1 through 9.0.82 and from 8.5.0 through 8.5.95 did not correctly parse HTTP trailer headers. A trailer header that exceeded the header size limit could cause Tomcat to treat a… | |
| Modificada | Media (5.3) | 5.8% | 💥 Exploit | Apache TomcatDebian Linux | 10/10/2023 | 17/6/2026 | Improper Input Validation vulnerability in Apache Tomcat.Tomcat from 11.0.0-M1 through 11.0.0-M11, from 10.1.0-M1 through 10.1.13, from 9.0.0-M1 through 9.0.81 and from 8.5.0 through 8.5.93 did not correctly parse HTTP trailer headers. A specially crafted, invalid trailer header could cause Tomcat to treat a single… | |
| Modificada | Media (5.3) | 2.2% | — | Apache TomcatDebian Linux | 10/10/2023 | 17/6/2026 | Incomplete Cleanup vulnerability in Apache Tomcat.When recycling various internal objects in Apache Tomcat from 11.0.0-M1 through 11.0.0-M11, from 10.1.0-M1 through 10.1.13, from 9.0.0-M1 through 9.0.80 and from 8.5.0 through 8.5.93, an error could cause Tomcat to skip some parts of the recycling process leading to… | |
| Modificada | Media (5.9) | 1.9% | — | Apache Tomcat | 10/10/2023 | 17/6/2026 | Incomplete Cleanup vulnerability in Apache Tomcat. The internal fork of Commons FileUpload packaged with Apache Tomcat 9.0.70 through 9.0.80 and 8.5.85 through 8.5.93 included an unreleased, in progress refactoring that exposed a potential denial of service on Windows if a web application opened a stream for an… |