Vulnerability Monitor

The vendors, products, and vulnerabilities you care about
tomcat Vendor: apache

About This Product

tomcat is a software product developed by apache, a major technology provider with a global presence in enterprise and consumer markets. This product is widely deployed in production environments, making vulnerability monitoring essential for organizations relying on it. Security vulnerabilities in products of this category can affect system availability, data confidentiality, and integrity across entire networks. The significant number of reported vulnerabilities indicates this product has received substantial security scrutiny and community focus over time. Regular assessment of known vulnerabilities and timely patching are fundamental components of responsible system administration for any deployment of this software.

Vulnerability Landscape Summary

SecUtils has identified 239 known vulnerabilities affecting apache tomcat. This includes 13 critical-severity issues and 76 high-severity issues that warrant immediate attention. Vulnerabilities in this product have been disclosed spanning from 2000 to 2026, indicating a sustained research interest and ongoing security attention. 135 medium-severity issues and 15 low-severity issues complete the vulnerability landscape. Organizations should prioritize patching based on deployment context, asset criticality, and exploitation likelihood rather than severity alone.

Known Vulnerabilities
ID Date Published Last Modified Severity (CVSSv3) Severity (CVSSv2) Exploit Available
CVE-2000-0672 2000-07-20 2025-04-03 - 5.0 Likely
CVE-2000-0759 2000-10-20 2025-04-03 - 6.4 Likely
CVE-2000-0760 2000-10-20 2025-04-03 - 6.4 Likely
CVE-2001-0590 2001-08-02 2025-04-03 - 5.0 Likely
CVE-2001-0917 2001-11-22 2025-04-03 - 5.0 Likely
CVE-2001-0829 2001-12-06 2025-04-03 - 5.1 Unknown
CVE-2001-1563 2001-12-31 2025-04-03 - 7.5 Likely
CVE-2000-1210 2002-03-22 2025-04-03 - 5.0 Likely
CVE-2002-0682 2002-07-23 2025-04-03 - 7.5 Likely
CVE-2002-0493 2002-08-12 2025-04-03 - 7.5 Likely
CVE-2002-0935 2002-10-04 2025-04-03 - 5.0 Likely
CVE-2002-0936 2002-10-04 2025-04-03 - 5.0 Likely
CVE-2002-1148 2002-10-11 2025-04-03 - 5.0 Likely
CVE-2002-1895 2002-12-31 2025-04-03 - 5.0 Likely
CVE-2002-2006 2002-12-31 2025-04-03 - 5.0 Likely
CVE-2002-2007 2002-12-31 2025-04-03 - 5.0 Likely
CVE-2002-2008 2002-12-31 2025-04-03 - 5.0 Likely
CVE-2002-2009 2002-12-31 2025-04-03 - 5.0 Likely
CVE-2002-2272 2002-12-31 2025-04-03 - 7.8 Likely
CVE-2002-1394 2003-01-17 2025-04-03 - 7.5 Likely
CVE-2003-0042 2003-02-07 2025-04-03 - 5.0 Likely
CVE-2003-0043 2003-02-07 2025-04-03 - 5.0 Likely
CVE-2003-0044 2003-02-07 2025-04-03 - 6.8 Likely
CVE-2003-0045 2003-02-07 2025-04-03 - 5.0 Likely
CVE-2002-1567 2003-10-06 2025-04-03 - 6.8 Likely
CVE-2003-0866 2003-11-17 2025-04-03 - 5.0 Likely
CVE-2005-0808 2005-05-02 2025-04-03 - 5.0 Likely
CVE-2005-2090 2005-07-05 2025-04-03 - 4.3 Likely
CVE-2005-3164 2005-10-06 2025-04-03 - 2.6 Unknown
CVE-2005-3510 2005-11-06 2025-04-03 - 5.0 Likely
CVE-2005-4703 2005-12-31 2025-04-03 - 5.0 Likely
CVE-2005-4836 2005-12-31 2025-04-03 - 7.8 Likely
CVE-2005-4838 2005-12-31 2025-04-03 - 4.3 Likely
CVE-2006-3835 2006-07-25 2025-04-03 - 5.0 Likely
CVE-2007-0450 2007-03-16 2025-04-09 - 5.0 Likely
CVE-2006-7197 2007-04-25 2025-04-09 - 7.8 Likely
CVE-2006-7195 2007-05-10 2025-04-09 - 4.3 Likely
CVE-2006-7196 2007-05-10 2025-04-09 - 4.3 Likely
CVE-2007-1358 2007-05-10 2025-04-09 - 2.6 Unknown
CVE-2007-1858 2007-05-10 2025-04-09 - 2.6 Unknown
CVE-2007-1355 2007-05-21 2025-04-09 - 4.3 Likely
CVE-2007-2449 2007-06-14 2025-04-09 - 4.3 Likely
CVE-2007-2450 2007-06-14 2025-04-09 - 3.5 Unknown
CVE-2007-3383 2007-07-25 2025-04-09 - 4.3 Likely
CVE-2007-3384 2007-08-08 2025-04-09 - 4.3 Likely
CVE-2007-3382 2007-08-14 2025-04-09 - 4.3 Likely
CVE-2007-3385 2007-08-14 2025-04-09 - 4.3 Likely
CVE-2007-3386 2007-08-14 2025-04-09 - 4.3 Likely
CVE-2007-4724 2007-09-05 2025-04-09 - 4.3 Likely
CVE-2007-5461 2007-10-15 2025-04-09 - 3.5 Unknown
CVE-2007-5342 2007-12-27 2025-04-09 - 6.4 Likely
CVE-2008-0128 2008-01-23 2025-04-09 - 5.0 Likely
CVE-2007-5333 2008-02-12 2025-04-09 - 5.0 Likely
CVE-2007-6286 2008-02-12 2025-04-09 - 4.3 Likely
CVE-2008-0002 2008-02-12 2025-04-09 - 5.8 Likely
CVE-2008-1947 2008-06-04 2025-04-09 - 4.3 Likely
CVE-2008-1232 2008-08-04 2025-04-09 - 4.3 Likely
CVE-2008-2370 2008-08-04 2025-04-09 - 5.0 Likely
CVE-2008-2938 2008-08-13 2025-04-09 - 4.3 Likely
CVE-2008-3271 2008-10-13 2025-04-09 - 4.3 Likely
CVE-2008-4308 2009-02-26 2025-04-09 - 2.6 Unknown
CVE-2009-0781 2009-03-09 2025-04-09 - 4.3 Likely
CVE-2008-5519 2009-04-09 2025-04-09 - 2.6 Unknown
CVE-2009-0033 2009-06-05 2025-04-09 - 5.0 Likely
CVE-2009-0580 2009-06-05 2025-04-09 - 4.3 Likely
CVE-2009-0783 2009-06-05 2025-04-09 4.2 4.6 Unknown
CVE-2008-5515 2009-06-16 2025-04-09 - 5.0 Likely
CVE-2009-3548 2009-11-12 2025-04-09 - 7.5 Likely
CVE-2009-2693 2010-01-28 2025-04-11 - 5.8 Likely
CVE-2009-2901 2010-01-28 2025-04-11 - 4.3 Likely
CVE-2009-2902 2010-01-28 2025-04-11 - 4.3 Likely
CVE-2010-1157 2010-04-23 2025-04-11 - 2.6 Unknown
CVE-2010-2227 2010-07-13 2025-04-11 - 6.4 Likely
CVE-2009-2696 2010-08-05 2025-04-11 - 4.3 Likely
CVE-2010-4172 2010-11-26 2025-04-11 - 4.3 Likely
CVE-2010-4312 2010-11-26 2025-04-11 - 6.4 Likely
CVE-2010-3718 2011-02-10 2025-04-11 - 1.2 Unknown
CVE-2011-0534 2011-02-10 2025-04-11 - 5.0 Likely
CVE-2011-0013 2011-02-19 2025-04-11 - 4.3 Likely
CVE-2011-1088 2011-03-14 2025-04-11 - 5.8 Likely
CVE-2011-1419 2011-03-14 2025-04-11 - 5.8 Likely
CVE-2011-1183 2011-04-08 2025-04-11 - 5.8 Likely
CVE-2011-1475 2011-04-08 2025-04-11 - 5.0 Likely
CVE-2011-1582 2011-05-20 2025-04-11 - 4.3 Likely
CVE-2011-2204 2011-06-29 2025-04-11 - 1.9 Unknown
CVE-2011-2526 2011-07-14 2025-04-11 - 4.4 Unknown
CVE-2011-2481 2011-08-15 2025-04-11 - 4.6 Unknown
CVE-2011-2729 2011-08-15 2025-04-11 - 5.0 Likely
CVE-2011-3190 2011-08-31 2025-04-11 - 7.5 Likely
CVE-2011-3376 2011-11-11 2025-04-11 - 4.4 Unknown
CVE-2011-4858 2012-01-05 2025-04-11 - 5.0 Likely
CVE-2011-1184 2012-01-14 2025-04-11 - 5.0 Likely
CVE-2011-5062 2012-01-14 2025-04-11 - 5.0 Likely
CVE-2011-5063 2012-01-14 2025-04-11 - 4.3 Likely
CVE-2011-5064 2012-01-14 2025-04-11 - 4.3 Likely
CVE-2011-3375 2012-01-19 2025-04-11 - 5.0 Likely
CVE-2012-0022 2012-01-19 2025-04-11 - 5.0 Likely
CVE-2012-2733 2012-11-16 2025-04-11 - 5.0 Likely
CVE-2012-5885 2012-11-17 2025-04-11 - 5.0 Likely
CVE-2012-5886 2012-11-17 2025-04-11 - 5.0 Likely
CVE-2012-5887 2012-11-17 2025-10-30 - 5.0 Likely
CVE-2012-5568 2012-11-30 2025-04-11 - 5.0 Likely
CVE-2012-3546 2012-12-19 2025-04-11 - 4.3 Likely
CVE-2012-4431 2012-12-19 2025-04-11 - 4.3 Likely
CVE-2012-4534 2012-12-19 2025-04-11 - 2.6 Unknown
CVE-2012-3544 2013-06-01 2025-04-11 - 5.0 Likely
CVE-2013-2067 2013-06-01 2025-04-11 - 6.8 Likely
CVE-2013-2071 2013-06-01 2025-04-11 - 2.6 Unknown
CVE-2013-6357 2013-11-13 2025-04-11 - 6.8 Likely
CVE-2013-2185 2014-01-19 2025-04-11 - 7.5 Likely
CVE-2013-0346 2014-02-15 2025-04-11 - 2.1 Unknown
CVE-2013-4286 2014-02-26 2025-04-11 - 5.8 Likely
CVE-2013-4322 2014-02-26 2025-04-11 - 4.3 Likely
CVE-2013-4590 2014-02-26 2025-04-11 - 4.3 Likely
CVE-2014-0033 2014-02-26 2025-04-12 - 4.3 Likely
CVE-2014-0050 2014-04-01 2025-04-12 - 7.5 Likely
CVE-2014-0075 2014-05-31 2025-04-12 - 5.0 Likely
CVE-2014-0095 2014-05-31 2025-04-12 - 5.0 Likely
CVE-2014-0096 2014-05-31 2025-04-12 - 4.3 Likely
CVE-2014-0099 2014-05-31 2025-04-12 - 4.3 Likely
CVE-2014-0119 2014-05-31 2025-04-12 - 4.3 Likely
CVE-2013-4444 2014-09-12 2025-04-12 - 6.8 Likely
CVE-2014-0227 2015-02-16 2025-04-12 - 6.4 Likely
CVE-2014-0230 2015-06-07 2025-04-12 - 7.8 Likely
CVE-2014-7810 2015-06-07 2025-04-12 - 5.0 Likely
CVE-2015-5174 2016-02-25 2025-04-12 4.3 4.0 Likely
CVE-2015-5345 2016-02-25 2025-04-12 5.3 5.0 Likely
CVE-2015-5346 2016-02-25 2025-04-12 8.1 6.8 Likely
CVE-2015-5351 2016-02-25 2025-04-12 8.8 6.8 Likely
CVE-2016-0706 2016-02-25 2025-04-12 4.3 4.0 Likely
CVE-2016-0714 2016-02-25 2025-04-12 8.8 6.5 Likely
CVE-2016-0763 2016-02-25 2025-04-12 6.3 6.5 Likely
CVE-2016-3092 2016-07-04 2025-04-12 7.5 7.8 Likely
CVE-2016-5388 2016-07-19 2025-04-12 8.1 5.1 Unknown
CVE-2016-1240 2016-10-03 2025-04-12 7.8 7.2 Unknown
CVE-2016-5425 2016-10-13 2025-04-12 7.8 7.2 Unknown
CVE-2016-6325 2016-10-13 2025-04-12 7.8 7.2 Unknown
CVE-2016-8747 2017-03-14 2025-04-20 7.5 5.0 Likely
CVE-2016-6816 2017-03-20 2025-04-20 7.1 6.8 Likely
CVE-2016-9774 2017-03-23 2025-04-20 7.8 7.2 Unknown
CVE-2016-9775 2017-03-23 2025-04-20 7.8 7.2 Unknown
CVE-2016-8735 2017-04-06 2025-10-22 9.8 7.5 Likely
CVE-2017-5647 2017-04-17 2025-04-20 7.5 5.0 Likely
CVE-2017-5648 2017-04-17 2025-04-20 9.1 6.4 Likely
CVE-2017-5650 2017-04-17 2025-04-20 7.5 5.0 Likely
CVE-2017-5651 2017-04-17 2025-04-20 9.8 7.5 Likely
CVE-2017-5664 2017-06-06 2025-04-20 7.5 5.0 Likely
CVE-2016-0762 2017-08-10 2025-04-20 5.9 4.3 Likely
CVE-2016-5018 2017-08-10 2025-04-20 9.1 6.4 Likely
CVE-2016-6794 2017-08-10 2025-04-20 5.3 5.0 Likely
CVE-2016-6797 2017-08-10 2025-04-20 7.5 5.0 Likely
CVE-2016-6817 2017-08-10 2025-04-20 7.5 5.0 Likely
CVE-2016-8745 2017-08-10 2025-04-20 7.5 5.0 Likely
CVE-2016-6796 2017-08-11 2025-04-20 7.5 5.0 Likely
CVE-2017-7674 2017-08-11 2025-04-20 4.3 4.3 Likely
CVE-2017-7675 2017-08-11 2025-04-20 7.5 5.0 Likely
CVE-2014-9634 2017-09-12 2025-04-20 5.3 5.0 Likely
CVE-2014-9635 2017-09-12 2025-04-20 5.3 5.0 Likely
CVE-2017-12615 2017-09-19 2025-10-22 8.1 6.8 Likely
CVE-2017-12616 2017-09-19 2025-04-20 7.5 5.0 Likely
CVE-2017-12617 2017-10-04 2025-10-22 8.1 6.8 Likely
CVE-2017-15706 2018-01-31 2024-11-21 5.3 5.0 Likely
CVE-2018-1305 2018-02-23 2024-11-21 6.5 4.0 Likely
CVE-2018-1304 2018-02-28 2024-11-21 5.9 4.3 Likely
CVE-2018-8014 2018-05-16 2024-11-21 9.8 7.5 Likely
CVE-2018-8034 2018-08-01 2024-11-21 7.5 5.0 Likely
CVE-2018-1336 2018-08-02 2024-11-21 7.5 5.0 Likely
CVE-2018-8037 2018-08-02 2024-11-21 5.9 4.3 Likely
CVE-2018-11784 2018-10-04 2024-11-21 4.3 4.3 Likely
CVE-2019-0199 2019-04-10 2024-11-21 7.5 5.0 Likely
CVE-2019-0232 2019-04-15 2024-11-21 8.1 9.3 Likely
CVE-2019-2684 2019-04-23 2024-11-21 5.9 4.3 Likely
CVE-2019-0221 2019-05-28 2024-11-21 6.1 4.3 Likely
CVE-2019-10072 2019-06-21 2024-11-21 7.5 5.0 Likely
CVE-2019-17563 2019-12-23 2024-11-21 7.5 5.1 Unknown
CVE-2019-12418 2019-12-23 2024-11-21 7.0 4.4 Unknown
CVE-2019-17569 2020-02-24 2024-11-21 4.8 5.8 Likely
CVE-2020-1935 2020-02-24 2024-11-21 4.8 5.8 Likely
CVE-2020-1938 2020-02-24 2025-10-27 9.8 7.5 Likely
CVE-2020-9484 2020-05-20 2024-11-21 7.0 4.4 Unknown
CVE-2020-11996 2020-06-26 2024-11-21 7.5 5.0 Likely
CVE-2020-8022 2020-06-29 2024-11-21 7.7 7.2 Unknown
CVE-2020-13934 2020-07-14 2024-11-21 7.5 5.0 Likely
CVE-2020-13935 2020-07-14 2024-11-21 7.5 5.0 Likely
CVE-2020-13943 2020-10-12 2024-11-21 4.3 4.0 Likely
CVE-2020-17527 2020-12-03 2024-11-21 7.5 5.0 Likely
CVE-2021-24122 2021-01-14 2024-11-21 5.9 4.3 Likely
CVE-2021-25122 2021-03-01 2024-11-21 7.5 5.0 Likely
CVE-2021-25329 2021-03-01 2024-11-21 7.0 4.4 Unknown
CVE-2021-30639 2021-07-12 2024-11-21 7.5 5.0 Likely
CVE-2021-30640 2021-07-12 2024-11-21 6.5 5.8 Likely
CVE-2021-33037 2021-07-12 2024-11-21 5.3 5.0 Likely
CVE-2021-41079 2021-09-16 2024-11-21 7.5 4.3 Likely
CVE-2021-42340 2021-10-14 2024-11-21 7.5 5.0 Likely
CVE-2022-23181 2022-01-27 2024-11-21 7.0 3.7 Unknown
CVE-2022-29885 2022-05-12 2024-11-21 7.5 5.0 Likely
CVE-2022-25762 2022-05-13 2024-11-21 8.6 7.5 Likely
CVE-2022-34305 2022-06-23 2024-11-21 6.1 4.3 Likely
CVE-2021-43980 2022-09-28 2025-05-21 3.7 - -
CVE-2022-42252 2022-11-01 2025-05-06 7.5 - -
CVE-2022-45143 2023-01-03 2024-11-21 7.5 - -
CVE-2023-28708 2023-03-22 2025-11-04 4.3 - -
CVE-2023-28709 2023-05-22 2025-02-13 7.5 - -
CVE-2023-34981 2023-06-21 2024-11-21 7.5 - -
CVE-2023-41080 2023-08-25 2025-08-07 6.1 - -
CVE-2023-44487 2023-10-10 2025-11-07 7.5 - -
CVE-2023-42794 2023-10-10 2025-10-29 5.9 - -
CVE-2023-42795 2023-10-10 2025-08-07 5.3 - -
CVE-2023-45648 2023-10-10 2025-08-07 5.3 - -
CVE-2023-46589 2023-11-28 2025-08-07 7.5 - -
CVE-2024-21733 2024-01-19 2025-11-03 5.3 - -
CVE-2024-23672 2024-03-13 2025-08-07 6.3 - -
CVE-2024-24549 2024-03-13 2025-10-29 7.5 - -
CVE-2024-34750 2024-07-03 2025-11-03 7.5 - -
CVE-2024-38286 2024-11-07 2025-11-03 8.6 - -
CVE-2024-52316 2024-11-18 2025-11-07 9.8 - -
CVE-2024-52317 2024-11-18 2025-05-15 6.5 - -
CVE-2024-52318 2024-11-18 2025-05-15 6.1 - -
CVE-2024-50379 2024-12-17 2025-11-03 9.8 - -
CVE-2024-54677 2024-12-17 2025-11-03 5.3 - -
CVE-2024-56337 2024-12-20 2025-11-03 9.8 - -
CVE-2025-24813 2025-03-10 2025-10-23 9.8 - -
CVE-2025-31650 2025-04-28 2025-11-03 7.5 - -
CVE-2025-31651 2025-04-28 2025-11-03 9.8 - -
CVE-2025-46701 2025-05-29 2025-11-03 7.3 - -
CVE-2025-48988 2025-06-16 2025-11-03 7.5 - -
CVE-2025-49124 2025-06-16 2025-10-29 8.4 - -
CVE-2025-49125 2025-06-16 2025-11-03 7.5 - -
CVE-2025-52434 2025-07-10 2025-11-04 7.5 - -
CVE-2025-52520 2025-07-10 2025-11-04 7.5 - -
CVE-2025-53506 2025-07-10 2025-11-04 7.5 - -
CVE-2025-48989 2025-08-13 2025-11-04 7.5 - -
CVE-2025-55668 2025-08-13 2025-11-04 6.5 - -
CVE-2025-55752 2025-10-27 2025-11-14 7.5 - -
CVE-2025-55754 2025-10-27 2025-11-14 9.6 - -
CVE-2025-61795 2025-10-27 2025-11-14 5.3 - -
CVE-2025-66614 2026-02-17 2026-03-11 9.1 - -
CVE-2026-24733 2026-02-17 2026-03-11 3.7 - -
CVE-2026-24734 2026-02-17 2026-03-11 7.5 - -

How SecUtils Interprets Product Data

SecUtils normalizes and enriches National Vulnerability Database (NVD) records for apache tomcat by standardizing vendor and product identifiers, aggregating vulnerability metadata from both NVD and MITRE sources, and structuring the data for rapid analysis and asset correlation. For every vulnerability listed, we extract Common Platform Enumeration (CPE) data, Common Weakness Enumeration (CWE) classifications, CVSS severity metrics, and reference information to enable organizations to prioritize patching and risk assessment efficiently. This record contains no exploit code, proof-of-concept instructions, or attack methodologies—only defensive intelligence necessary for vulnerability management and security operations.