gregk4sec
11 exploits
Active since Mar 2025
Apache Tomcat 9.0.0-9.0.102, 10.1.0-M1-10.1.39, 11.0.0-M1-11.0.5 - Security Constraint Bypass
Apache Tomcat <11.0.6 - Security Constraint Bypass
Apache Tomcat <11.0.6 - Security Constraint Bypass
Apache Tomcat 9.0.0-9.0.102, 10.1.0-M1-10.1.39, 11.0.0-M1-11.0.5 - Security Constraint Bypass
Tomcat Partial PUT Java Deserialization
Apache Tomcat, Apache Tomcat Native: OCSP checks sometimes soft-fail even when soft-fail is disabled
CVSS 9.1
Apache Tomcat: Occasionally open redirect
CVSS 6.1
Oracle HTTP Server & WebLogic Proxy Plug-in 12.2.1.4.0/14.1.1.0.0/14.1.2.0.0 - Unauthenticated Access Control
CVSS 10.0
Oracle HTTP Server & WebLogic Proxy Plug-in 12.2.1.4.0/14.1.1.0.0/14.1.2.0.0 - Unauthenticated Access Control
CVSS 10.0
Apache Tomcat <11.0.7, <10.1.41, <9.0.105 - Session Fixation
CVSS 6.5
Apache Tomcat 9.0.0-9.0.105, 10.1.0-M1-10.1.41, 11.0.0-M1-11.0.7 - Authentication Bypass
CVSS 7.5