Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3017▼ 66 respecto a la semana anterior
Críticas / altas1412▲ 56 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)381▼ 129 respecto a la semana anterior
–

102 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)97%—Apache StrutsOracle Communications Policy ManagementOracle Financial Services Data Integration HUBOracle Financial Services Market Risk Measurement AND Management+114/9/202017/6/2026
Apache Struts 2.0.0 to 2.5.20 forced double OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote code execution.
ModificadaMedia (6.1)5.8%—Apache Struts27/2/202017/6/2026
Apache Struts before 2.3.20 has a cross-site scripting (XSS) vulnerability.
ModificadaAlta (8.8)29%—Apache Struts5/12/201916/6/2026
A local code execution issue exists in Apache Struts2 when processing malformed XSLT files, which could let a malicious user upload and execute arbitrary files.
ModificadaCrítica (9.8)89%—Apache StrutsRedhat Jboss Enterprise WEB Server1/11/201916/6/2026
Apache Struts before 2.3.1.2 allows remote attackers to bypass security protections in the ParameterInterceptor class and execute arbitrary commands.
AnalizadaAlta (8.1)100%⚠ Explotación activaApache StrutsNetapp Active IQ Unified ManagerNetapp Oncommand InsightNetapp Oncommand Workflow Automation+422/8/201817/6/2026
Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullNamespace is true (either by user or a plugin like Convention Plugin) and then: results are used with no namespace and in same time, its upper package have no or wildcard namespace and similar to…
ModificadaAlta (7.5)8.6%—Apache Struts27/3/201817/6/2026
The Apache Struts REST Plugin is using XStream library which is vulnerable and allow perform a DoS attack when using a malicious request with specially crafted XML payload. Upgrade to the Apache Struts version 2.5.16 and switch to an optional Jackson XML handler as described here…
ModificadaMedia (6.2)4.9%—Apache StrutsNetapp Oncommand BalanceOracle Agile PLM FrameworkOracle Enterprise Manager FOR Virtualization+81/12/201717/6/2026
In Apache Struts 2.5 to 2.5.14, the REST Plugin is using an outdated JSON-lib library which is vulnerable and allow perform a DoS attack using malicious request with specially crafted JSON payload.
ModificadaAlta (8.8)5.7%—Apache Struts30/10/201717/6/2026
The TextParseUtil.translateVariables method in Apache Struts 2.x before 2.3.20 allows remote attackers to execute arbitrary code via a crafted OGNL expression with ANTLR tooling.
ModificadaAlta (8.8)8.1%—Apache StrutsNetapp Oncommand Balance16/10/201717/6/2026
Apache Struts 2.x before 2.3.29 allows remote attackers to execute arbitrary code via a "%{}" sequence in a tag attribute, aka forced double OGNL evaluation. NOTE: this vulnerability exists because of an incomplete fix for CVE-2016-0785.
ModificadaMedia (6.1)7.5%—Apache Struts25/9/201717/6/2026
Cross-site scripting (XSS) vulnerability in Apache Struts before 2.3.20.
ModificadaAlta (7.5)8.2%—Apache Struts20/9/201717/6/2026
In Apache Struts 2.3.7 through 2.3.33 and 2.5 through 2.5.12, if an application allows entering a URL in a form field and built-in URLValidator is used, it is possible to prepare a special URL which will be used to overload server process when performing validation of the URL. NOTE: this vulnerability exists because…
ModificadaAlta (7.5)8.8%—Apache Struts20/9/201717/6/2026
The REST Plugin in Apache Struts 2.1.x, 2.3.7 through 2.3.33 and 2.5 through 2.5.12 is using an outdated XStream library which is vulnerable and allow perform a DoS attack using malicious request with specially crafted XML payload.
ModificadaCrítica (9.8)87%—Apache Struts20/9/201717/6/2026
In Apache Struts 2.0.0 through 2.3.33 and 2.5 through 2.5.10.1, using an unintentional expression in a Freemarker tag instead of string literals can lead to a RCE attack.
ModificadaMedia (5.9)3.3%—Apache Struts20/9/201717/6/2026
In Apache Struts 2.5 through 2.5.5, if an application allows entering a URL in a form field and the built-in URLValidator is used, it is possible to prepare a special URL which will be used to overload server process when performing validation of the URL.
ModificadaCrítica (9.8)8.2%—Apache Struts20/9/201717/6/2026
In the Convention plugin in Apache Struts 2.3.x before 2.3.31, and 2.5.x before 2.5.5, it is possible to prepare a special URL which will be used for path traversal and execution of arbitrary code on server side.
AnalizadaAlta (8.1)99%⚠ Explotación activaApache StrutsCisco Digital Media ManagerCisco Hosted Collaboration SolutionCisco Media Experience Engine+315/9/201717/6/2026
The REST Plugin in Apache Struts 2.1.1 through 2.3.x before 2.3.34 and 2.5.x before 2.5.13 uses an XStreamHandler with an instance of XStream for deserialization without any type filtering, which can lead to Remote Code Execution when deserializing XML payloads.
ModificadaAlta (7.5)9.1%—Apache Struts29/8/201717/6/2026
Apache Struts 2.x before 2.3.24.1 allows remote attackers to manipulate Struts internals, alter user sessions, or affect container settings via vectors involving a top object.
ModificadaAlta (7.5)11%—Apache Struts13/7/201717/6/2026
When using a Spring AOP functionality to secure Struts actions it is possible to perform a DoS attack. Solution is to upgrade to Apache Struts version 2.5.12 or 2.3.33.
ModificadaMedia (5.9)9.8%—Apache Struts13/7/201717/6/2026
If an application allows enter an URL in a form field and built-in URLValidator is used, it is possible to prepare a special URL which will be used to overload server process when performing validation of the URL. Solution is to upgrade to Apache Struts version 2.5.12.
AnalizadaCrítica (9.8)99%⚠ Explotación activaApache Struts10/7/201717/6/2026
The Struts 1 plugin in Apache Struts 2.1.x and 2.3.x might allow remote code execution via a malicious field value passed in a raw message to the ActionMessage.
AnalizadaCrítica (9.8)100%⚠ Explotación activaApache StrutsIBM Storwize V3500 FirmwareIBM Storwize V5000 FirmwareIBM Storwize V7000 Firmware+511/3/201717/6/2026
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception handling and error-message generation during file-upload attempts, which allows remote attackers to execute arbitrary commands via a crafted Content-Type, Content-Disposition, or Content-Length HTTP…
ModificadaCrítica (9.8)6.6%—Apache Struts3/10/201617/6/2026
Apache Struts 2 before 2.3.29 and 2.5.x before 2.5.1 allow attackers to have unspecified impact via vectors related to improper action name clean up.
ModificadaMedia (5.3)10%—Apache Struts4/7/201617/6/2026
The URLValidator class in Apache Struts 2 2.3.20 through 2.3.28.1 and 2.5.x before 2.5.1 allows remote attackers to cause a denial of service via a null value for a URL field.
ModificadaCrítica (9.8)17%—Apache Struts4/7/201617/6/2026
The REST plugin in Apache Struts 2 2.3.19 through 2.3.28.1 allows remote attackers to execute arbitrary code via a crafted expression.
ModificadaAlta (7.5)9.8%—Apache Struts4/7/201617/6/2026
Apache Struts 2 2.3.20 through 2.3.28.1 allows remote attackers to bypass intended access restrictions and conduct redirection attacks via a crafted request.