| CVE-2016-3081 |
high |
8.1 |
9.1 |
|
|
|
10y ago |
Apache Struts RCE Vulnerability |
| CVE-2013-2115 |
high |
8.1 |
9.1 |
|
|
|
13y ago |
Code injection in Apache Struts |
| CVE-2016-4461 |
high |
8.8 |
8.8 |
|
|
|
9y ago |
Apache Struts forced double OGNL evaluation |
| CVE-2016-0785 |
high |
8.8 |
8.8 |
|
|
|
10y ago |
Apache Struts RCE Vulnerability |
| CVE-2014-0113 |
high |
— |
8.5 |
|
|
|
12y ago |
ClassLoader manipulation in Apache Struts |
| CVE-2014-0112 |
high |
— |
8.5 |
|
|
|
12y ago |
ClassLoader manipulation in Apache Struts |
| CVE-2012-0392 |
medium |
— |
7.8 |
|
|
|
15y ago |
Apache Struts's CookieInterceptor component does not use the parameter-name whitelist |
| CVE-2017-9804 |
high |
7.5 |
7.5 |
|
|
|
9y ago |
Apache Struts allows entering a custom URL in a form field if built-in URLValidator is used |
| CVE-2015-5209 |
high |
7.5 |
7.5 |
|
|
|
9y ago |
Special top object can be used to access Struts' internals |
| CVE-2017-9787 |
high |
7.5 |
7.5 |
|
|
|
9y ago |
Spring AOP functionality (Struts) vulnerable to DoS attack |
| CVE-2015-1831 |
high |
— |
7.5 |
|
|
|
11y ago |
Incomplete exclude pattern in Apache Struts |
| CVE-2012-0393 |
medium |
— |
7.4 |
|
|
|
15y ago |
Apache Struts's ParameterInterceptor component does not prevent access to public constructors |
| CVE-2014-7809 |
medium |
— |
6.8 |
|
|
|
12y ago |
Cross-Site Request Forgery in Apache Struts |
| CVE-2013-2248 |
medium |
— |
6.8 |
|
|
|
13y ago |
Open redirect in Apache Struts |
| CVE-2012-4386 |
medium |
— |
6.8 |
|
|
|
14y ago |
Cross-Site Request Forgery in Apache Struts |
| CVE-2015-5169 |
medium |
6.1 |
6.1 |
|
|
|
9y ago |
Cross-site Scripting in Apache Struts |
| CVE-2016-4003 |
medium |
6.1 |
6.1 |
|
|
|
10y ago |
Cross-site Scripting in Apache Struts |
| CVE-2016-2162 |
medium |
6.1 |
6.1 |
|
|
|
10y ago |
Apache Struts XSS Vulnerability |
| CVE-2014-0094 |
medium |
— |
6.0 |
|
|
|
12y ago |
ClassLoader manipulation in Apache Struts |
| CVE-2010-1870 |
medium |
— |
6.0 |
|
|
|
16y ago |
Server side object manipulation in Apache Struts |
| CVE-2016-8738 |
medium |
5.9 |
5.9 |
|
|
|
9y ago |
Apache Struts vulnerable to possible DoS attack when using URLValidator |
| CVE-2017-7672 |
medium |
5.9 |
5.9 |
|
|
|
9y ago |
Apache Struts Improper Input Validation vulnerability |
| CVE-2014-0116 |
medium |
— |
5.8 |
|
|
|
12y ago |
ClassLoader manipulation in Apache Struts |
| CVE-2013-4310 |
medium |
— |
5.8 |
|
|
|
13y ago |
Apache Struts2 Broken Access Control Vulnerability |
| CVE-2016-4465 |
medium |
5.3 |
5.3 |
|
|
|
10y ago |
Apache Struts vulnerable to possible DoS attack when using URLValidator |
| CVE-2016-3093 |
medium |
5.3 |
5.3 |
|
|
|
10y ago |
Denial of service in Apache Struts |
| CVE-2013-6348 |
medium |
— |
4.3 |
|
|
|
13y ago |
Apache Struts is vulnerable to Cross-site Scripting |