Vulmon
Recent Vulnerabilities
Product List
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
apache struts 2.1 vulnerabilities and exploits
(subscribe to this query)
383
VMScore
CVE-2008-6682
Multiple cross-site scripting (XSS) vulnerabilities in Apache Struts 2.0.x prior to 2.0.11.1 and 2.1.x prior to 2.1.1 allow remote malicious users to inject arbitrary web script or HTML via vectors associated with improper handling of (1) " (double quote) characters in the h...
Apache Struts 2.0.9
Apache Struts 2.0.8
Apache Struts 2.1
Apache Struts 2.0.11
Apache Struts 2.0.6
383
VMScore
CVE-2016-2162
Apache Struts 2.x prior to 2.3.25 does not sanitize text in the Locale object constructed by I18NInterceptor, which might allow remote malicious users to conduct cross-site scripting (XSS) attacks via unspecified vectors involving language display.
Apache Struts 2.3.1.1
Apache Struts 2.0.9
Apache Struts 2.0.12
Apache Struts 2.2.3.1
Apache Struts 2.1.0
Apache Struts 2.3.15
Apache Struts 2.0.0
Apache Struts 2.3.14
Apache Struts 2.0.8
Apache Struts 2.0.7
Apache Struts 2.0.4
Apache Struts 2.2.1
Apache Struts 2.3.16
Apache Struts 2.3.24.1
Apache Struts 2.1.8.1
Apache Struts 2.3.3
Apache Struts 2.3.16.3
Apache Struts 2.3.4
Apache Struts 2.1.3
Apache Struts 2.1.2
Apache Struts 2.1.5
Apache Struts 2.0.1
762
VMScore
CVE-2017-9791
The Struts 1 plugin in Apache Struts 2.1.x and 2.3.x might allow remote code execution via a malicious field value passed in a raw message to the ActionMessage.
Apache Struts 2.3.1.1
Apache Struts 2.3.28
Apache Struts 2.3.15
Apache Struts 2.3.14
Apache Struts 2.3.32
Apache Struts 2.3.16
Apache Struts 2.3.24.1
Apache Struts 2.3.3
Apache Struts 2.3.16.3
Apache Struts 2.3.4
Apache Struts 2.3.24.3
Apache Struts 2.3.15.2
Apache Struts 2.3.29
Apache Struts 2.3.14.3
Apache Struts 2.3.4.1
Apache Struts 2.3.20.1
Apache Struts 2.3.8
Apache Struts 2.3.30
Apache Struts 2.3.7
Apache Struts 2.3.24
Apache Struts 2.3.28.1
Apache Struts 2.3.14.2
2 EDB exploits
8 Github repositories
1 Article
505
VMScore
CVE-2008-6505
Multiple directory traversal vulnerabilities in Apache Struts 2.0.x prior to 2.0.12 and 2.1.x prior to 2.1.3 allow remote malicious users to read arbitrary files via a ..%252f (encoded dot dot slash) in a URI with a /struts/ path, related to (1) FilterDispatcher in 2.0.x and (2) ...
Apache Struts 2.0.9
Apache Struts 2.0.8
Apache Struts 2.0.11.1
Apache Struts 2.1.2 Beta
Apache Struts 2.0.11
Apache Struts 2.0.11.2
Apache Struts 2.0.6
1 EDB exploit
505
VMScore
CVE-2008-6504
ParametersInterceptor in OpenSymphony XWork 2.0.x prior to 2.0.6 and 2.1.x prior to 2.1.2, as used in Apache Struts and other products, does not properly restrict # (pound sign) references to context objects, which allows remote malicious users to execute Object-Graph Navigation ...
Opensymphony Xwork 2.1.1
Opensymphony Xwork 2.0.4
Opensymphony Xwork 2.0.3
Opensymphony Xwork 2.0.5
Opensymphony Xwork 2.0.0
Opensymphony Xwork 2.0.2
Opensymphony Xwork 2.0.1
Opensymphony Xwork 2.1.0
Apache Struts 2.0.9
Apache Struts 2.0.0
Apache Struts 2.0.8
Apache Struts 2.0.7
Apache Struts 2.0.4
Apache Struts 2.0.2
Apache Struts 2.0.11.1
Apache Struts 2.0.3
Apache Struts 2.0.11
Apache Struts 2.0.5
Apache Struts 2.0.11.2
Apache Struts 2.0.6
1 EDB exploit
446
VMScore
CVE-2017-9793
The REST Plugin in Apache Struts 2.1.x, 2.3.7 up to and including 2.3.33 and 2.5 up to and including 2.5.12 is using an outdated XStream library which is vulnerable and allow perform a DoS attack using malicious request with specially crafted XML payload.
Apache Struts 2.5.9
Apache Struts 2.3.28
Apache Struts 2.3.20.2
Apache Struts 2.5
Apache Struts 2.3.15
Apache Struts 2.3.25
Apache Struts 2.5.2
Apache Struts 2.3.14
Apache Struts 2.3.32
Apache Struts 2.3.13
Apache Struts 2.3.16
Apache Struts 2.3.24.2
Apache Struts 2.3.17
Apache Struts 2.5.10
Apache Struts 2.3.22
Apache Struts 2.5.6
Apache Struts 2.3.9
Apache Struts 2.3.16.3
Apache Struts 2.3.23
Apache Struts 2.3.24.3
Apache Struts 2.3.15.2
Apache Struts 2.3.29
3 Github repositories
1 Article
605
VMScore
CVE-2009-1275
Apache Tiles 2.1 prior to 2.1.2, as used in Apache Struts and other products, evaluates Expression Language (EL) expressions twice in certain circumstances, which allows remote malicious users to conduct cross-site scripting (XSS) attacks or obtain sensitive information via unspe...
Apache Tiles 2.1.0
Apache Tiles 2.1.1
VMScore
CVSSv2
CVSSv3
VMScore
Recommendations:
buffer overflow
type confusion
server-side request forgery
CVE-2024-38440
CVE-2024-27801
CVE-2024-5868
CVE-2024-0582
CVE-2024-37643
CVE-2024-3105
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started