Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
By Recent Activity
struts vulnerabilities and exploits
(subscribe to this query)
7.5
CVSSv2
CVE-2016-4438
The REST plugin in Apache Struts 2 2.3.19 through 2.3.28.1 allows remote attackers to execute arbitrary code via a crafted expression....
Apache Struts 2.3.20
Apache Struts 2.3.20.1
Apache Struts 2.3.20.3
Apache Struts 2.3.24
Apache Struts 2.3.24.1
Apache Struts 2.3.24.3
Apache Struts 2.3.28
2 Github repositories available
4.3
CVSSv2
CVE-2008-2025
Cross-site scripting (XSS) vulnerability in Apache Struts before 1.2.9-162.31.1 on SUSE Linux Enterprise (SLE) 11, before 1.2.9-108.2 on SUSE openSUSE 10.3, before 1.2.9-198.2 on SUSE openSUSE 11.0, and before 1.2.9-162.163.2 on SUSE openSUSE 11.1 allows remote attackers to...
Apache Struts 1.0.2
Apache Struts 1.1
Apache Struts 1.2.4
Apache Struts 1.2.7
Apache Struts 1.2.8
4.3
CVSSv2
CVE-2012-1006
Multiple cross-site scripting (XSS) vulnerabilities in Apache Struts 2.0.14 and 2.2.3 allow remote attackers to inject arbitrary web script or HTML via the (1) name or (2) lastName parameter to struts2-showcase/person/editPerson.action, or the (3) clientName parameter to...
Apache Struts 2.0.14
Apache Struts 2.2.3
1 EDB exploit available
7.8
CVSSv2
CVE-2006-1547
ActionForm in Apache Software Foundation (ASF) Struts before 1.2.9 with BeanUtils 1.7 allows remote attackers to cause a denial of service via a multipart/form-data encoded form with a parameter name that references the public getMultipartRequestHandler method, which provides...
Apache Struts 1.2.7
Apache Struts
1 Github repository available
9.3
CVSSv2
CVE-2012-0391
The ExceptionDelegator component in Apache Struts before 2.2.3.1 interprets parameter values as OGNL expressions during certain exception handling for mismatched data types of properties, which allows remote attackers to execute arbitrary Java code via a crafted parameter....
Apache Struts
2 EDB exploits available
1 Metasploit module available
9.3
CVSSv2
CVE-2013-2135
Apache Struts 2 before 2.3.14.3 allows remote attackers to execute arbitrary OGNL code via a request with a crafted value that contains both "${}" and "%{}" sequences, which causes the OGNL code to be evaluated twice....
Apache Struts
5
CVSSv2
CVE-2018-1327
The Apache Struts REST Plugin is using XStream library which is vulnerable and allow perform a DoS attack when using a malicious request with specially crafted XML payload. Upgrade to the Apache Struts version 2.5.16 and switch to an optional Jackson XML handler as described...
Apache Struts
4 Github repositories available
9
CVSSv2
CVE-2016-0785
Apache Struts 2.x before 2.3.28 allows remote attackers to execute arbitrary code via a "%{}" sequence in a tag attribute, aka forced double OGNL evaluation....
Apache Struts
7.5
CVSSv2
CVE-2014-0112
ParametersInterceptor in Apache Struts before 2.3.20 does not properly restrict access to the getClass method, which allows remote attackers to "manipulate" the ClassLoader and execute arbitrary code via a crafted request. NOTE: this vulnerability exists because of an...
Apache Struts
2 EDB exploits available
1 Metasploit module available
3 Github repositories available
1 Article available
5
CVSSv2
CVE-2014-0094
The ParametersInterceptor in Apache Struts before 2.3.16.2 allows remote attackers to "manipulate" the ClassLoader via the class parameter, which is passed to the getClass method....
Apache Struts
2 EDB exploits available
1 Metasploit module available
5 Github repositories available
1 Article available
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2021-24086
CVE-2021-25374
CVE-2021-25373
CVE-2021-26855
log injection
CVE-2021-20022
server-side request forgery
local
CVE-2021-25360
Vulnerability Notification Service
Get Started
« PREV
1
2
3
4
5
6
7
8
9
NEXT »