Vulmon
Recent Vulnerabilities
Product List
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
apache struts 2.3.28 vulnerabilities and exploits
(subscribe to this query)
445
VMScore
CVE-2016-4433
Apache Struts 2 2.3.20 up to and including 2.3.28.1 allows remote malicious users to bypass intended access restrictions and conduct redirection attacks via a crafted request.
Apache Struts 2.3.28
Apache Struts 2.3.24.1
Apache Struts 2.3.24.3
Apache Struts 2.3.20.1
Apache Struts 2.3.24
Apache Struts 2.3.20.3
Apache Struts 2.3.20
605
VMScore
CVE-2016-4430
Apache Struts 2 2.3.20 up to and including 2.3.28.1 mishandles token validation, which allows remote malicious users to conduct cross-site request forgery (CSRF) attacks via unspecified vectors.
Apache Struts 2.3.28
Apache Struts 2.3.24.1
Apache Struts 2.3.24.3
Apache Struts 2.3.20.1
Apache Struts 2.3.24
Apache Struts 2.3.28.1
Apache Struts 2.3.20.3
Apache Struts 2.3.20
445
VMScore
CVE-2016-4465
The URLValidator class in Apache Struts 2 2.3.20 up to and including 2.3.28.1 and 2.5.x prior to 2.5.1 allows remote malicious users to cause a denial of service via a null value for a URL field.
Apache Struts 2.3.28
Apache Struts 2.5
Apache Struts 2.3.24.1
Apache Struts 2.3.24.3
Apache Struts 2.3.20.1
Apache Struts 2.3.24
Apache Struts 2.3.28.1
Apache Struts 2.3.20.3
Apache Struts 2.3.20
670
VMScore
CVE-2016-4438
The REST plugin in Apache Struts 2 2.3.19 up to and including 2.3.28.1 allows remote malicious users to execute arbitrary code via a crafted expression.
Apache Struts 2.3.28
Apache Struts 2.3.24.1
Apache Struts 2.3.24.3
Apache Struts 2.3.20.1
Apache Struts 2.3.24
Apache Struts 2.3.20.3
Apache Struts 2.3.20
761
VMScore
CVE-2016-3087
Apache Struts 2.3.19 to 2.3.20.2, 2.3.21 to 2.3.24.1, and 2.3.25 to 2.3.28, when Dynamic Method Invocation is enabled, allow remote malicious users to execute arbitrary code via vectors related to an ! (exclamation mark) operator to the REST Plugin.
Apache Struts 2.3.28
Apache Struts 2.3.24.1
Apache Struts 2.3.20.1
Apache Struts 2.3.24
Apache Struts 2.3.20
2 EDB exploits
3 Github repositories
936
VMScore
CVE-2016-3081
Apache Struts 2.3.19 to 2.3.20.2, 2.3.21 to 2.3.24.1, and 2.3.25 to 2.3.28, when Dynamic Method Invocation is enabled, allow remote malicious users to execute arbitrary code via method: prefix, related to chained expressions.
Apache Struts 2.3.1.1
Apache Struts 2.0.9
Apache Struts 2.0.12
Apache Struts 2.2.3.1
Apache Struts 2.3.28
Apache Struts 2.1.0
Apache Struts 2.3.15
Apache Struts 2.0.0
Apache Struts 2.3.14
Apache Struts 2.0.8
Apache Struts 2.0.7
Apache Struts 2.0.4
Apache Struts 2.2.1
Apache Struts 2.3.16
Apache Struts 2.3.24.1
Apache Struts 2.1.8.1
Apache Struts 2.3.3
Apache Struts 2.3.16.3
Apache Struts 2.3.4
Apache Struts 2.1.3
Apache Struts 2.1.2
Apache Struts 2.1.5
1 EDB exploit
2 Github repositories
890
VMScore
CVE-2016-3082
XSLTResult in Apache Struts 2.x prior to 2.3.20.2, 2.3.24.x prior to 2.3.24.2, and 2.3.28.x prior to 2.3.28.1 allows remote malicious users to execute arbitrary code via the stylesheet location parameter.
Apache Struts 2.3.1.1
Apache Struts 2.0.9
Apache Struts 2.0.12
Apache Struts 2.2.3.1
Apache Struts 2.3.28
Apache Struts 2.1.0
Apache Struts 2.3.15
Apache Struts 2.0.0
Apache Struts 2.3.14
Apache Struts 2.0.8
Apache Struts 2.0.7
Apache Struts 2.0.4
Apache Struts 2.2.1
Apache Struts 2.3.16
Apache Struts 2.3.24.1
Apache Struts 2.1.8.1
Apache Struts 2.3.3
Apache Struts 2.3.16.3
Apache Struts 2.3.4
Apache Struts 2.1.3
Apache Struts 2.1.2
Apache Struts 2.1.5
802
VMScore
CVE-2016-0785
Apache Struts 2.x prior to 2.3.28 allows remote malicious users to execute arbitrary code via a "%{}" sequence in a tag attribute, aka forced double OGNL evaluation.
Apache Struts
383
VMScore
CVE-2016-4003
Cross-site scripting (XSS) vulnerability in the URLDecoder function in JRE prior to 1.8, as used in Apache Struts 2.x prior to 2.3.28, when using a single byte page encoding, allows remote malicious users to inject arbitrary web script or HTML via multi-byte characters in a url-e...
Apache Struts
VMScore
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-37316
firmware
CVE-2024-30078
CVE-2024-5995
remote code execution
logic flaw
CVE-2024-20693
CVE-2024-37315
CVE-2024-5464
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2