Vulmon
Recent Vulnerabilities
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
By Recent Activity
struts vulnerabilities and exploits
(subscribe to this query)
4.3
CVSSv2
CVE-2017-7672
If an application allows enter an URL in a form field and built-in URLValidator is used, it is possible to prepare a special URL which will be used to overload server process when performing validation of the URL. Solution is to upgrade to Apache Struts version 2.5.12....
Apache Struts 2.5
Apache Struts 2.5.1
Apache Struts 2.5.2
Apache Struts 2.5.5
Apache Struts 2.5.8
Apache Struts 2.5.10
Apache Struts 2.5.10.1
1 Github repository available
2 Articles available
10
CVSSv2
CVE-2017-5638
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception handling and error-message generation during file-upload attempts, which allows remote attackers to execute arbitrary commands via a crafted Content-Type,...
Apache Struts 2.3.5
Apache Struts 2.3.6
Apache Struts 2.3.7
Apache Struts 2.3.8
Apache Struts 2.3.9
Apache Struts 2.3.10
Apache Struts 2.3.11
Apache Struts 2.3.12
Apache Struts 2.3.13
Apache Struts 2.3.14
Apache Struts 2.3.14.1
Apache Struts 2.3.14.2
Apache Struts 2.3.14.3
Apache Struts 2.3.15
Apache Struts 2.3.15.1
Apache Struts 2.3.15.2
Apache Struts 2.3.15.3
Apache Struts 2.3.16
Apache Struts 2.3.16.1
Apache Struts 2.3.16.2
Apache Struts 2.3.16.3
Apache Struts 2.3.17
Apache Struts 2.3.19
Apache Struts 2.3.20
Apache Struts 2.3.20.1
Apache Struts 2.3.20.2
Apache Struts 2.3.20.3
Apache Struts 2.3.21
Apache Struts 2.3.22
Apache Struts 2.3.23
Apache Struts 2.3.24
Apache Struts 2.3.24.1
Apache Struts 2.3.24.2
Apache Struts 2.3.24.3
Apache Struts 2.3.25
Apache Struts 2.3.26
Apache Struts 2.3.27
Apache Struts 2.3.28
Apache Struts 2.3.28.1
Apache Struts 2.3.29
Apache Struts 2.3.30
Apache Struts 2.3.31
Apache Struts 2.5
Apache Struts 2.5.1
Apache Struts 2.5.2
Apache Struts 2.5.3
Apache Struts 2.5.4
Apache Struts 2.5.5
Apache Struts 2.5.6
Apache Struts 2.5.7
Apache Struts 2.5.8
Apache Struts 2.5.9
Apache Struts 2.5.10
2 EDB exploits available
1 Metasploit module available
64 Github repositories available
21 Articles available
6.8
CVSSv2
CVE-2017-9805
The REST Plugin in Apache Struts 2.1.1 through 2.3.x before 2.3.34 and 2.5.x before 2.5.13 uses an XStreamHandler with an instance of XStream for deserialization without any type filtering, which can lead to Remote Code Execution when deserializing XML payloads....
Apache Struts 2.1.2
Apache Struts 2.1.3
Apache Struts 2.1.4
Apache Struts 2.1.5
Apache Struts 2.1.6
Apache Struts 2.1.8
Apache Struts 2.1.8.1
Apache Struts 2.2.1
Apache Struts 2.2.1.1
Apache Struts 2.2.3
Apache Struts 2.2.3.1
Apache Struts 2.3.1
Apache Struts 2.3.1.1
Apache Struts 2.3.1.2
Apache Struts 2.3.3
Apache Struts 2.3.4
Apache Struts 2.3.4.1
Apache Struts 2.3.7
Apache Struts 2.3.8
Apache Struts 2.3.12
Apache Struts 2.3.14
Apache Struts 2.3.14.1
Apache Struts 2.3.14.2
Apache Struts 2.3.14.3
Apache Struts 2.3.15
Apache Struts 2.3.15.1
Apache Struts 2.3.15.2
Apache Struts 2.3.15.3
Apache Struts 2.3.16
Apache Struts 2.3.16.1
Apache Struts 2.3.16.2
Apache Struts 2.3.16.3
Apache Struts 2.3.20
Apache Struts 2.3.20.1
Apache Struts 2.3.20.3
Apache Struts 2.3.24
Apache Struts 2.3.24.1
Apache Struts 2.3.24.3
Apache Struts 2.3.28
Apache Struts 2.3.28.1
Apache Struts 2.3.29
Apache Struts 2.3.30
Apache Struts 2.3.31
Apache Struts 2.3.32
Apache Struts 2.3.33
Apache Struts 2.5.1
Apache Struts 2.5.2
Apache Struts 2.5.3
Apache Struts 2.5.4
Apache Struts 2.5.5
Apache Struts 2.5.6
Apache Struts 2.5.7
Apache Struts 2.5.8
Apache Struts 2.5.9
Apache Struts 2.5.10
Apache Struts 2.5.10.1
Apache Struts 2.5.11
Apache Struts 2.5.12
1 EDB exploit available
1 Metasploit module available
62 Github repositories available
10 Articles available
5.8
CVSSv2
CVE-2014-0116
CookieInterceptor in Apache Struts 2.x before 2.3.20, when a wildcard cookiesName value is used, does not properly restrict access to the getClass method, which allows remote attackers to "manipulate" the ClassLoader and modify session state via a crafted request....
Apache Struts 2.0.0
Apache Struts 2.0.1
Apache Struts 2.0.2
Apache Struts 2.0.3
Apache Struts 2.0.4
Apache Struts 2.0.5
Apache Struts 2.0.6
Apache Struts 2.0.7
Apache Struts 2.0.8
Apache Struts 2.0.9
Apache Struts 2.0.10
Apache Struts 2.0.11
Apache Struts 2.0.11.1
Apache Struts 2.0.11.2
Apache Struts 2.0.12
Apache Struts 2.0.13
Apache Struts 2.0.14
Apache Struts 2.1.0
Apache Struts 2.1.1
Apache Struts 2.1.2
Apache Struts 2.1.3
Apache Struts 2.1.4
Apache Struts 2.1.5
Apache Struts 2.1.6
Apache Struts 2.1.8
Apache Struts 2.1.8.1
Apache Struts 2.2.1
Apache Struts 2.2.1.1
Apache Struts 2.2.3
Apache Struts 2.2.3.1
Apache Struts 2.3.1
Apache Struts 2.3.1.1
Apache Struts 2.3.1.2
Apache Struts 2.3.3
Apache Struts 2.3.4
Apache Struts 2.3.4.1
Apache Struts 2.3.7
Apache Struts 2.3.8
Apache Struts 2.3.12
Apache Struts 2.3.14
Apache Struts 2.3.14.1
Apache Struts 2.3.14.2
Apache Struts 2.3.14.3
Apache Struts 2.3.15
Apache Struts 2.3.15.1
Apache Struts 2.3.15.2
Apache Struts 2.3.15.3
Apache Struts 2.3.16
Apache Struts 2.3.16.1
Apache Struts 2.3.16.2
2 Github repositories available
7.5
CVSSv2
CVE-2016-4436
Apache Struts 2 before 2.3.29 and 2.5.x before 2.5.1 allow attackers to have unspecified impact via vectors related to improper action name clean up....
Apache Struts 2.0.0
Apache Struts 2.0.1
Apache Struts 2.0.2
Apache Struts 2.0.3
Apache Struts 2.0.4
Apache Struts 2.0.5
Apache Struts 2.0.6
Apache Struts 2.0.7
Apache Struts 2.0.8
Apache Struts 2.0.9
Apache Struts 2.0.11
Apache Struts 2.0.11.1
Apache Struts 2.0.11.2
Apache Struts 2.0.12
Apache Struts 2.0.14
Apache Struts 2.1.6
Apache Struts 2.1.8
Apache Struts 2.1.8.1
Apache Struts 2.2.1
Apache Struts 2.2.1.1
Apache Struts 2.2.3
Apache Struts 2.2.3.1
Apache Struts 2.3.1
Apache Struts 2.3.1.1
Apache Struts 2.3.1.2
Apache Struts 2.3.3
Apache Struts 2.3.4
Apache Struts 2.3.4.1
Apache Struts 2.3.7
Apache Struts 2.3.8
Apache Struts 2.3.12
Apache Struts 2.3.14
Apache Struts 2.3.14.1
Apache Struts 2.3.14.2
Apache Struts 2.3.14.3
Apache Struts 2.3.15
Apache Struts 2.3.15.1
Apache Struts 2.3.15.2
Apache Struts 2.3.15.3
Apache Struts 2.3.16
Apache Struts 2.3.16.1
Apache Struts 2.3.16.2
Apache Struts 2.3.16.3
Apache Struts 2.3.20
Apache Struts 2.3.20.1
Apache Struts 2.3.20.3
Apache Struts 2.3.24
Apache Struts 2.3.24.1
Apache Struts 2.3.24.3
Apache Struts 2.3.28
Apache Struts 2.3.28.1
Apache Struts 2.5
5
CVSSv2
CVE-2017-9793
The REST Plugin in Apache Struts 2.1.x, 2.3.7 through 2.3.33 and 2.5 through 2.5.12 is using an outdated XStream library which is vulnerable and allow perform a DoS attack using malicious request with specially crafted XML payload....
Apache Struts 2.3.7
Apache Struts 2.3.8
Apache Struts 2.3.9
Apache Struts 2.3.10
Apache Struts 2.3.11
Apache Struts 2.3.12
Apache Struts 2.3.13
Apache Struts 2.3.14
Apache Struts 2.3.14.1
Apache Struts 2.3.14.2
Apache Struts 2.3.14.3
Apache Struts 2.3.15
Apache Struts 2.3.15.1
Apache Struts 2.3.15.2
Apache Struts 2.3.15.3
Apache Struts 2.3.16
Apache Struts 2.3.16.1
Apache Struts 2.3.16.2
Apache Struts 2.3.16.3
Apache Struts 2.3.17
Apache Struts 2.3.19
Apache Struts 2.3.20
Apache Struts 2.3.20.1
Apache Struts 2.3.20.2
Apache Struts 2.3.21
Apache Struts 2.3.22
Apache Struts 2.3.23
Apache Struts 2.3.24.2
Apache Struts 2.3.24.3
Apache Struts 2.3.25
Apache Struts 2.3.26
Apache Struts 2.3.27
Apache Struts 2.3.28
Apache Struts 2.3.28.1
Apache Struts 2.3.29
Apache Struts 2.3.30
Apache Struts 2.3.31
Apache Struts 2.3.32
Apache Struts 2.3.33
Apache Struts 2.5
Apache Struts 2.5.1
Apache Struts 2.5.2
Apache Struts 2.5.3
Apache Struts 2.5.4
Apache Struts 2.5.5
Apache Struts 2.5.6
Apache Struts 2.5.7
Apache Struts 2.5.8
Apache Struts 2.5.9
Apache Struts 2.5.10
Apache Struts 2.5.10.1
Apache Struts 2.5.12
1 Github repository available
3 Articles available
5
CVSSv2
CVE-2016-4433
Apache Struts 2 2.3.20 through 2.3.28.1 allows remote attackers to bypass intended access restrictions and conduct redirection attacks via a crafted request....
Apache Struts 2.3.20
Apache Struts 2.3.20.1
Apache Struts 2.3.20.3
Apache Struts 2.3.24
Apache Struts 2.3.24.1
Apache Struts 2.3.24.3
Apache Struts 2.3.28
7.5
CVSSv2
CVE-2017-9791
The Struts 1 plugin in Apache Struts 2.1.x and 2.3.x might allow remote code execution via a malicious field value passed in a raw message to the ActionMessage....
Apache Struts 2.3.1
Apache Struts 2.3.1.1
Apache Struts 2.3.1.2
Apache Struts 2.3.3
Apache Struts 2.3.4
Apache Struts 2.3.4.1
Apache Struts 2.3.7
Apache Struts 2.3.8
Apache Struts 2.3.12
Apache Struts 2.3.14
Apache Struts 2.3.14.1
Apache Struts 2.3.14.2
Apache Struts 2.3.14.3
Apache Struts 2.3.15
Apache Struts 2.3.15.1
Apache Struts 2.3.15.2
Apache Struts 2.3.15.3
Apache Struts 2.3.16
Apache Struts 2.3.16.1
Apache Struts 2.3.16.2
Apache Struts 2.3.16.3
Apache Struts 2.3.20
Apache Struts 2.3.20.1
Apache Struts 2.3.20.3
Apache Struts 2.3.24
Apache Struts 2.3.24.1
Apache Struts 2.3.24.3
Apache Struts 2.3.28
Apache Struts 2.3.28.1
Apache Struts 2.3.29
Apache Struts 2.3.30
Apache Struts 2.3.31
Apache Struts 2.3.32
2 EDB exploits available
1 Metasploit module available
22 Github repositories available
3 Articles available
6.8
CVSSv2
CVE-2012-4386
The token check mechanism in Apache Struts 2.0.0 through 2.3.4 does not properly validate the token name configuration parameter, which allows remote attackers to perform cross-site request forgery (CSRF) attacks by setting the token name configuration parameter to a session...
Apache Struts 2.0.0
Apache Struts 2.0.1
Apache Struts 2.0.2
Apache Struts 2.0.3
Apache Struts 2.0.4
Apache Struts 2.0.5
Apache Struts 2.0.6
Apache Struts 2.0.7
Apache Struts 2.0.8
Apache Struts 2.0.9
Apache Struts 2.0.10
Apache Struts 2.0.11
Apache Struts 2.0.11.1
Apache Struts 2.0.11.2
Apache Struts 2.0.12
Apache Struts 2.0.13
Apache Struts 2.0.14
Apache Struts 2.1.0
Apache Struts 2.1.1
Apache Struts 2.1.2
Apache Struts 2.1.3
Apache Struts 2.1.4
Apache Struts 2.1.5
Apache Struts 2.1.6
Apache Struts 2.1.8
Apache Struts 2.1.8.1
Apache Struts 2.2.1
Apache Struts 2.2.1.1
Apache Struts 2.2.3
Apache Struts 2.2.3.1
Apache Struts 2.3.1
Apache Struts 2.3.1.1
Apache Struts 2.3.1.2
Apache Struts 2.3.3
Apache Struts 2.3.4
5.8
CVSSv2
CVE-2013-4310
Apache Struts 2.0.0 through 2.3.15.1 allows remote attackers to bypass access controls via a crafted action: prefix....
Apache Struts 2.0.0
Apache Struts 2.0.1
Apache Struts 2.0.2
Apache Struts 2.0.3
Apache Struts 2.0.4
Apache Struts 2.0.5
Apache Struts 2.0.6
Apache Struts 2.0.7
Apache Struts 2.0.8
Apache Struts 2.0.9
Apache Struts 2.0.10
Apache Struts 2.0.11
Apache Struts 2.0.11.1
Apache Struts 2.0.11.2
Apache Struts 2.0.12
Apache Struts 2.0.13
Apache Struts 2.0.14
Apache Struts 2.1.0
Apache Struts 2.1.1
Apache Struts 2.1.2
Apache Struts 2.1.3
Apache Struts 2.1.4
Apache Struts 2.1.5
Apache Struts 2.1.6
Apache Struts 2.1.8
Apache Struts 2.1.8.1
Apache Struts 2.2.1
Apache Struts 2.2.1.1
Apache Struts 2.2.3
Apache Struts 2.2.3.1
Apache Struts 2.3.1
Apache Struts 2.3.1.1
Apache Struts 2.3.1.2
Apache Struts 2.3.3
Apache Struts 2.3.4
Apache Struts 2.3.4.1
Apache Struts 2.3.7
Apache Struts 2.3.8
Apache Struts 2.3.12
Apache Struts 2.3.14
Apache Struts 2.3.14.1
Apache Struts 2.3.14.2
Apache Struts 2.3.14.3
Apache Struts 2.3.15
Apache Struts 2.3.15.1
1 Article available
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2020-3691
insecure direct object reference
CVE-2021-1140
CVE-2021-2109
information disclosure
CVE-2021-1303
CVE-2021-1304
IDOR
CVE-2020-14882
« PREV
1
2
3
4
5
6
7
NEXT »