Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
By Recent Activity
apache struts 2.3.28.1 vulnerabilities and exploits
(subscribe to this query)
6.8
CVSSv2
CVE-2016-4430
Apache Struts 2 2.3.20 through 2.3.28.1 mishandles token validation, which allows remote attackers to conduct cross-site request forgery (CSRF) attacks via unspecified vectors....
Apache Struts 2.3.28.1
Apache Struts 2.3.20
Apache Struts 2.3.20.3
Apache Struts 2.3.20.1
Apache Struts 2.3.28
Apache Struts 2.3.24.3
Apache Struts 2.3.24.1
Apache Struts 2.3.24
5
CVSSv2
CVE-2016-4465
The URLValidator class in Apache Struts 2 2.3.20 through 2.3.28.1 and 2.5.x before 2.5.1 allows remote attackers to cause a denial of service via a null value for a URL field....
Apache Struts 2.5
Apache Struts 2.3.28.1
Apache Struts 2.3.20
Apache Struts 2.3.20.3
Apache Struts 2.3.20.1
Apache Struts 2.3.28
Apache Struts 2.3.24.3
Apache Struts 2.3.24.1
Apache Struts 2.3.24
7.5
CVSSv2
CVE-2016-6795
In the Convention plugin in Apache Struts 2.3.x before 2.3.31, and 2.5.x before 2.5.5, it is possible to prepare a special URL which will be used for path traversal and execution of arbitrary code on server side....
Apache Struts 2.3.20.2
Apache Struts 2.3.21
Apache Struts 2.3.28
Apache Struts 2.3.28.1
Apache Struts 2.3.20
Apache Struts 2.3.20.1
Apache Struts 2.3.25
Apache Struts 2.3.26
Apache Struts 2.3.27
Apache Struts 2.3.24
Apache Struts 2.3.22
Apache Struts 2.3.23
Apache Struts 2.3.29
Apache Struts 2.3.30
Apache Struts 2.3.24.1
Apache Struts 2.3.20.3
Apache Struts 2.3.24.2
Apache Struts 2.3.24.3
2 Github repositories available
7.5
CVSSv2
CVE-2017-9791
The Struts 1 plugin in Apache Struts 2.1.x and 2.3.x might allow remote code execution via a malicious field value passed in a raw message to the ActionMessage....
Apache Struts 2.3.1
Apache Struts 2.3.1.1
Apache Struts 2.3.1.2
Apache Struts 2.3.3
Apache Struts 2.3.4
Apache Struts 2.3.4.1
Apache Struts 2.3.7
Apache Struts 2.3.8
Apache Struts 2.3.12
Apache Struts 2.3.14
Apache Struts 2.3.14.1
Apache Struts 2.3.14.2
Apache Struts 2.3.14.3
Apache Struts 2.3.15
Apache Struts 2.3.15.1
Apache Struts 2.3.15.2
Apache Struts 2.3.15.3
Apache Struts 2.3.16
Apache Struts 2.3.16.1
Apache Struts 2.3.16.2
Apache Struts 2.3.16.3
Apache Struts 2.3.20
Apache Struts 2.3.20.1
Apache Struts 2.3.20.3
Apache Struts 2.3.24
Apache Struts 2.3.24.1
Apache Struts 2.3.24.3
Apache Struts 2.3.28
Apache Struts 2.3.28.1
Apache Struts 2.3.29
Apache Struts 2.3.30
Apache Struts 2.3.31
Apache Struts 2.3.32
2 EDB exploits available
1 Metasploit module available
48 Github repositories available
4 Articles available
10
CVSSv2
CVE-2016-3082
XSLTResult in Apache Struts 2.x before 2.3.20.2, 2.3.24.x before 2.3.24.2, and 2.3.28.x before 2.3.28.1 allows remote attackers to execute arbitrary code via the stylesheet location parameter....
Apache Struts 2.3.4.1
Apache Struts 2.3.4
Apache Struts 2.3.15.3
Apache Struts 2.3.15.2
Apache Struts 2.3.12
Apache Struts 2.3.1.2
Apache Struts 2.3.1.1
Apache Struts 2.1.8
Apache Struts 2.1.6
Apache Struts 2.0.9
Apache Struts 2.0.8
Apache Struts 2.0.13
Apache Struts 2.0.12
Apache Struts 2.3.8
Apache Struts 2.3.7
Apache Struts 2.3.16.1
Apache Struts 2.3.16
Apache Struts 2.3.14.1
Apache Struts 2.3.14
Apache Struts 2.2.1
Apache Struts 2.1.8.1
Apache Struts 2.1.1
Apache Struts 2.1.0
Apache Struts 2.0.3
Apache Struts 2.0.2
Apache Struts 2.0.14
Apache Struts 2.0.1
Apache Struts 2.0.0
Apache Struts 2.3.20.1
Apache Struts 2.3.20
Apache Struts 2.3.3
Apache Struts 2.3.28
Apache Struts 2.3.15.1
Apache Struts 2.3.15
Apache Struts 2.3.1
Apache Struts 2.2.3.1
Apache Struts 2.1.5
Apache Struts 2.1.4
Apache Struts 2.0.7
Apache Struts 2.0.6
Apache Struts 2.0.11.2
Apache Struts 2.0.11.1
Apache Struts 2.3.24
Apache Struts 2.3.24.1
Apache Struts 2.3.16.3
Apache Struts 2.3.16.2
Apache Struts 2.3.14.3
Apache Struts 2.3.14.2
Apache Struts 2.2.3
Apache Struts 2.2.1.1
Apache Struts 2.1.3
Apache Struts 2.1.2
Apache Struts 2.0.5
Apache Struts 2.0.4
Apache Struts 2.0.11
Apache Struts 2.0.10
5
CVSSv2
CVE-2016-4433
Apache Struts 2 2.3.20 through 2.3.28.1 allows remote attackers to bypass intended access restrictions and conduct redirection attacks via a crafted request....
Apache Struts 2.3.20.1
Apache Struts 2.3.20
Apache Struts 2.3.28
Apache Struts 2.3.24.3
Apache Struts 2.3.24.1
Apache Struts 2.3.24
Apache Struts 2.3.20.3
10
CVSSv2
CVE-2017-5638
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception handling and error-message generation during file-upload attempts, which allows remote attackers to execute arbitrary commands via a crafted Content-Type,...
Apache Struts 2.3.5
Apache Struts 2.3.28
Apache Struts 2.3.20.2
Apache Struts 2.3.15
Apache Struts 2.3.25
Apache Struts 2.3.14
Apache Struts 2.3.13
Apache Struts 2.3.16
Apache Struts 2.3.24.2
Apache Struts 2.3.17
Apache Struts 2.3.24.1
Apache Struts 2.3.22
Apache Struts 2.3.9
Apache Struts 2.3.16.3
Apache Struts 2.3.23
Apache Struts 2.3.6
Apache Struts 2.3.24.3
Apache Struts 2.3.15.2
Apache Struts 2.3.29
Apache Struts 2.3.14.3
Apache Struts 2.3.19
Apache Struts 2.3.20.1
Apache Struts 2.3.8
Apache Struts 2.3.30
Apache Struts 2.3.7
Apache Struts 2.3.24
Apache Struts 2.3.28.1
Apache Struts 2.3.14.2
Apache Struts 2.3.20.3
Apache Struts 2.3.10
Apache Struts 2.3.15.1
Apache Struts 2.3.16.2
Apache Struts 2.3.26
Apache Struts 2.3.12
Apache Struts 2.3.27
Apache Struts 2.3.31
Apache Struts 2.3.21
Apache Struts 2.3.20
Apache Struts 2.3.11
Apache Struts 2.3.15.3
Apache Struts 2.3.16.1
Apache Struts 2.3.14.1
Apache Struts 2.5.9
Apache Struts 2.5.2
Apache Struts 2.5.10
Apache Struts 2.5.6
Apache Struts 2.5.1
Apache Struts 2.5.4
Apache Struts 2.5.7
Apache Struts 2.5
Apache Struts 2.5.5
Apache Struts 2.5.3
Apache Struts 2.5.8
2 EDB exploits available
1 Metasploit module available
86 Github repositories available
5 Articles available
7.5
CVSSv2
CVE-2016-4436
Apache Struts 2 before 2.3.29 and 2.5.x before 2.5.1 allow attackers to have unspecified impact via vectors related to improper action name clean up....
Apache Struts 2.3.16.2
Apache Struts 2.3.16.1
Apache Struts 2.3.14.1
Apache Struts 2.3.14
Apache Struts 2.3.1.2
Apache Struts 2.3.1.1
Apache Struts 2.1.8
Apache Struts 2.1.6
Apache Struts 2.0.3
Apache Struts 2.0.4
Apache Struts 2.3.20.1
Apache Struts 2.3.20.3
Apache Struts 2.5
Apache Struts 2.3.15.2
Apache Struts 2.3.15
Apache Struts 2.3.8
Apache Struts 2.3.4.1
Apache Struts 2.2.3
Apache Struts 2.2.1.1
Apache Struts 2.0.11.2
Apache Struts 2.0.11.1
Apache Struts 2.0.0
Apache Struts 2.0.7
Apache Struts 2.0.8
Apache Struts 2.3.24.3
Apache Struts 2.3.28
Apache Struts 2.3.16
Apache Struts 2.3.15.3
Apache Struts 2.3.12
Apache Struts 2.3.7
Apache Struts 2.3.1
Apache Struts 2.2.3.1
Apache Struts 2.0.14
Apache Struts 2.0.12
Apache Struts 2.0.5
Apache Struts 2.0.6
Apache Struts 2.3.24
Apache Struts 2.3.24.1
Apache Struts 2.3.20
Apache Struts 2.3.16.3
Apache Struts 2.3.15.1
Apache Struts 2.3.14.3
Apache Struts 2.3.14.2
Apache Struts 2.3.3
Apache Struts 2.3.4
Apache Struts 2.2.1
Apache Struts 2.1.8.1
Apache Struts 2.0.1
Apache Struts 2.0.2
Apache Struts 2.0.9
Apache Struts 2.0.11
Apache Struts 2.3.28.1
5
CVSSv2
CVE-2017-9793
The REST Plugin in Apache Struts 2.1.x, 2.3.7 through 2.3.33 and 2.5 through 2.5.12 is using an outdated XStream library which is vulnerable and allow perform a DoS attack using malicious request with specially crafted XML payload....
Apache Struts 2.5.10.1
Apache Struts 2.3.12
Apache Struts 2.3.13
Apache Struts 2.3.15.2
Apache Struts 2.3.15.3
Apache Struts 2.3.16
Apache Struts 2.3.20.1
Apache Struts 2.3.20.2
Apache Struts 2.3.26
Apache Struts 2.3.27
Apache Struts 2.5
Apache Struts 2.5.5
Apache Struts 2.5.6
Apache Struts 2.3.8
Apache Struts 2.3.9
Apache Struts 2.3.14.2
Apache Struts 2.3.14.3
Apache Struts 2.3.16.3
Apache Struts 2.3.17
Apache Struts 2.3.23
Apache Struts 2.3.24.2
Apache Struts 2.3.29
Apache Struts 2.3.30
Apache Struts 2.5.1
Apache Struts 2.5.2
Apache Struts 2.5.9
Apache Struts 2.5.10
Apache Struts 2.5.12
Apache Struts 2.3.7
Apache Struts 2.3.14
Apache Struts 2.3.14.1
Apache Struts 2.3.16.1
Apache Struts 2.3.16.2
Apache Struts 2.3.21
Apache Struts 2.3.22
Apache Struts 2.3.28
Apache Struts 2.3.28.1
Apache Struts 2.5.7
Apache Struts 2.5.8
Apache Struts 2.3.10
Apache Struts 2.3.11
Apache Struts 2.3.15
Apache Struts 2.3.15.1
Apache Struts 2.3.19
Apache Struts 2.3.20
Apache Struts 2.3.24.3
Apache Struts 2.3.25
Apache Struts 2.3.31
Apache Struts 2.3.32
Apache Struts 2.3.33
Apache Struts 2.5.3
Apache Struts 2.5.4
5 Github repositories available
3 Articles available
5
CVSSv2
CVE-2016-4431
Apache Struts 2 2.3.20 through 2.3.28.1 allows remote attackers to bypass intended access restrictions and conduct redirection attacks by leveraging a default method....
Apache Struts 2.3.28
Apache Struts 2.3.20.1
Apache Struts 2.3.20
Apache Struts 2.3.24.3
Apache Struts 2.3.24.1
Apache Struts 2.3.24
Apache Struts 2.3.20.3
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
brute force
log injection
CVE-2023-6510
CVE-2023-49248
CVE-2023-49374
CVE-2023-26360
XSS
CVE-2023-46674
CVE-2023-49105
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
NEXT »