225 exploited vulnerabilities in Apache Tomcat
- Vendors
- Apache, Atlassian, Linux Mint, Red Os, Canonical, Debian
- With known exploits
- 225
- Affected Apache Tomcat versions
- β€ 7.0.109, 8.5.100, 9.0.118, 10.1.55, 11.0.22, 9.0.110, 10.0.27, 10.1.47, 11.0.12, 9.0.109, 10.1.45, 11.0.11, 9.0.0, 9.0.106, 10.1.42, 11.0.8, 9.0.107, 10.1.43, 11.0.9, 9.0.105, 10.1.41, 11.0.7, 8.5.64, 9.0.44, 10.0.2, 8.5.72, 9.0.54, 10.0.12, 10.0.0, 10.1.0, 10.0.3, 10.0.4, 8.5.61, 9.0.41, 8.5.59, 9.0.35, 9.0.35-3.39.1, 9.0.35-3.57.3, 9.0.36, 9.0.37, 9.0.38, 9.0.39, 7.0.86, 8.0.51, 8.5.30, 9.0.7, 8.0.0, 7.0.0, 7.0.1, 7.0.2, 7.0.3, 7.0.4, 7.0.5, 7.0.6, 7.0.7, 7.0.8, 7.0.9, 7.0.10, 7.0.11, 7.0.12, 7.0.13, 7.0.14, 7.0.15, 7.0.16, 7.0.17, 7.0.18, 7.0.19, 7.0.20, 7.0.21, 7.0.22, 7.0.23, 7.0.24, 7.0.25, 7.0.26, 7.0.27, 7.0.28, 7.0.29, 7.0.30, 7.0.31, 7.0.32, 7.0.33, 7.0.34, 7.0.35, 7.0.36, 7.0.37, 7.0.38, 7.0.39, 6.0.0, 6.0.1, 6.0.2, 6.0.3, 6.0.4, 6.0.5, 6.0.6, 6.0.7, 6.0.8, 6.0.9, 6.0.10, 6.0.11, 6.0.12, 6.0.13, 6.0.14, 6.0.15, 6.0.16, 6.0.17, 6.0.18, 6.0.19, 6.0.20, 6.0.21, 6.0.22, 6.0.23, 6.0.24, 6.0.25, 6.0.26, 6.0.27, 6.0.28, 6.0.29, 6.0.30, 6.0.31, 6.0.32, 6.0.33, 6.0.34, 6.0.35, 6.0.36, 6.0.37, 6.0.38, 6.0.39, 3.0, 3.1, 3.1.1, 3.2, 3.2.1, 3.2.2, 3.2.3, 3.2.4, 3.3, 3.3.1, 3.3.1a, 3.3.2, 4.0.0, 4.0.1, 4.0.2, 4.0.3, 4.0.4, 4.0.5, 4.0.6, 4.1.0, 4.1.1, 4.1.2, 4.1.3, 4.1.4, 4.1.5, 4.1.6, 4.1.7, 4.1.8, 4.1.9, 4.1.10, 4.1.11, 4.1.12, 4.1.13, 4.1.14, 4.1.15, 4.1.16, 4.1.17, 4.1.18, 4.1.19, 4.1.20, 7.0.84, 8.0.49, 8.5.27, 9.0.4, 8.5.73, 9.0.56, 10.0.14, 7.0.107, 7.0.108, 8.5.63, 9.0.43, 7.0.97, 8.5.47, 9.0.28, 5.5.25, 1.1.3, 4, 4.1.24, 4.1.28, 4.1.29, 4.1.31, 4.1.36, 5, 5.0.0, 5.0.1, 5.0.2, 5.0.3, 9.0.117, 10.1.54, 11.0.21, 11.0.0, 9.0.96, 10.1.31, 8.5.66, 9.0.46, 10.0.6
- Affected Linecorp Armeria versions
- < 1.24.3
- Affected Openmrs versions
- < 2.1.5, 2.2.1, 2.3.5, 2.4.5, 2.5.3
- Affected Jivesoftware Jive versions
- All versions
- Affected Oracle Retail Applications versions
- = 12.0, 12.0in, 13.0, 13.1, 13.2, 13.3, 13.4, 14.0
- Affected Apache Tomcat Jk Web Server Connector versions
- = 1.2.19, 1.2.20
- Affected Liferay Liferay Portal versions
- β€ 5.1.2, 6.0.5
- Affected Theforeman Foreman versions
- < 3.8.0
Vulnerabilities with exploits
Highest CVSS first β 21 of these already have exploit code on Sploitus
CVE-2026-42498
CVE-2025-61795
CVE-2025-55752 3 exploits
CVE-2025-53506
CVE-2025-52520
CVE-2025-52434
CVE-2025-46701 1 exploit
CVE-2023-38493
CVE-2022-23612
CVE-2021-45968
CVE-2021-41079
CVE-2021-42340
CVE-2021-30639
CVE-2021-25122 1 exploit
CVE-2020-17527
CVE-2018-1336
CVE-2017-5664 1 exploit
CVE-2017-5647
CVE-2017-12616 4 exploits
CVE-2014-0050 7 exploits
CVE-2011-3190
CVE-2009-3548 12 exploits
CVE-2007-0774 9 exploits
CVE-2002-0682 1 exploit
CVE-2018-1304
CVE-2016-6816 6 exploits
CVE-2022-23181 1 exploit
CVE-2021-25329
CVE-2020-9484 17 exploits
CVE-2019-12418
CVE-2011-1571 5 exploits
CVE-2002-2009
CVE-2018-1305 2 exploits
CVE-2013-6357 6 exploits
CVE-2002-1567 1 exploit
CVE-2023-4886
CVE-2026-34500
CVE-2024-52317 1 exploit
CVE-2022-44008
CVE-2021-30640
CVE-2026-25854
CVE-2010-2227 2 exploits
CVE-2000-0760 1 exploit
CVE-2000-0759 1 exploit
CVE-2023-41080
CVE-2019-0221 3 exploits
CVE-2021-23336
CVE-2018-8037
CVE-2019-17569
CVE-2020-1935