Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3017▼ 66 respecto a la semana anterior
Críticas / altas1412▲ 56 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)381▼ 129 respecto a la semana anterior
102 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 97% | — | Apache StrutsOracle Communications Policy ManagementOracle Financial Services Data Integration HUBOracle Financial Services Market Risk Measurement AND Management+1 | 14/9/2020 | 17/6/2026 | Apache Struts 2.0.0 to 2.5.20 forced double OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote code execution. | |
| Modificada | Media (6.1) | 5.8% | — | Apache Struts | 27/2/2020 | 17/6/2026 | Apache Struts before 2.3.20 has a cross-site scripting (XSS) vulnerability. | |
| Modificada | Alta (8.8) | 29% | — | Apache Struts | 5/12/2019 | 16/6/2026 | A local code execution issue exists in Apache Struts2 when processing malformed XSLT files, which could let a malicious user upload and execute arbitrary files. | |
| Modificada | Crítica (9.8) | 89% | — | Apache StrutsRedhat Jboss Enterprise WEB Server | 1/11/2019 | 16/6/2026 | Apache Struts before 2.3.1.2 allows remote attackers to bypass security protections in the ParameterInterceptor class and execute arbitrary commands. | |
| Analizada | Alta (8.1) | 100% | ⚠ Explotación activa | Apache StrutsNetapp Active IQ Unified ManagerNetapp Oncommand InsightNetapp Oncommand Workflow Automation+4 | 22/8/2018 | 17/6/2026 | Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullNamespace is true (either by user or a plugin like Convention Plugin) and then: results are used with no namespace and in same time, its upper package have no or wildcard namespace and similar to… | |
| Modificada | Alta (7.5) | 8.6% | — | Apache Struts | 27/3/2018 | 17/6/2026 | The Apache Struts REST Plugin is using XStream library which is vulnerable and allow perform a DoS attack when using a malicious request with specially crafted XML payload. Upgrade to the Apache Struts version 2.5.16 and switch to an optional Jackson XML handler as described here… | |
| Modificada | Media (6.2) | 4.9% | — | Apache StrutsNetapp Oncommand BalanceOracle Agile PLM FrameworkOracle Enterprise Manager FOR Virtualization+8 | 1/12/2017 | 17/6/2026 | In Apache Struts 2.5 to 2.5.14, the REST Plugin is using an outdated JSON-lib library which is vulnerable and allow perform a DoS attack using malicious request with specially crafted JSON payload. | |
| Modificada | Alta (8.8) | 5.7% | — | Apache Struts | 30/10/2017 | 17/6/2026 | The TextParseUtil.translateVariables method in Apache Struts 2.x before 2.3.20 allows remote attackers to execute arbitrary code via a crafted OGNL expression with ANTLR tooling. | |
| Modificada | Alta (8.8) | 8.1% | — | Apache StrutsNetapp Oncommand Balance | 16/10/2017 | 17/6/2026 | Apache Struts 2.x before 2.3.29 allows remote attackers to execute arbitrary code via a "%{}" sequence in a tag attribute, aka forced double OGNL evaluation. NOTE: this vulnerability exists because of an incomplete fix for CVE-2016-0785. | |
| Modificada | Media (6.1) | 7.5% | — | Apache Struts | 25/9/2017 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in Apache Struts before 2.3.20. | |
| Modificada | Alta (7.5) | 8.2% | — | Apache Struts | 20/9/2017 | 17/6/2026 | In Apache Struts 2.3.7 through 2.3.33 and 2.5 through 2.5.12, if an application allows entering a URL in a form field and built-in URLValidator is used, it is possible to prepare a special URL which will be used to overload server process when performing validation of the URL. NOTE: this vulnerability exists because… | |
| Modificada | Alta (7.5) | 8.8% | — | Apache Struts | 20/9/2017 | 17/6/2026 | The REST Plugin in Apache Struts 2.1.x, 2.3.7 through 2.3.33 and 2.5 through 2.5.12 is using an outdated XStream library which is vulnerable and allow perform a DoS attack using malicious request with specially crafted XML payload. | |
| Modificada | Crítica (9.8) | 87% | — | Apache Struts | 20/9/2017 | 17/6/2026 | In Apache Struts 2.0.0 through 2.3.33 and 2.5 through 2.5.10.1, using an unintentional expression in a Freemarker tag instead of string literals can lead to a RCE attack. | |
| Modificada | Media (5.9) | 3.3% | — | Apache Struts | 20/9/2017 | 17/6/2026 | In Apache Struts 2.5 through 2.5.5, if an application allows entering a URL in a form field and the built-in URLValidator is used, it is possible to prepare a special URL which will be used to overload server process when performing validation of the URL. | |
| Modificada | Crítica (9.8) | 8.2% | — | Apache Struts | 20/9/2017 | 17/6/2026 | In the Convention plugin in Apache Struts 2.3.x before 2.3.31, and 2.5.x before 2.5.5, it is possible to prepare a special URL which will be used for path traversal and execution of arbitrary code on server side. | |
| Analizada | Alta (8.1) | 99% | ⚠ Explotación activa | Apache StrutsCisco Digital Media ManagerCisco Hosted Collaboration SolutionCisco Media Experience Engine+3 | 15/9/2017 | 17/6/2026 | The REST Plugin in Apache Struts 2.1.1 through 2.3.x before 2.3.34 and 2.5.x before 2.5.13 uses an XStreamHandler with an instance of XStream for deserialization without any type filtering, which can lead to Remote Code Execution when deserializing XML payloads. | |
| Modificada | Alta (7.5) | 9.1% | — | Apache Struts | 29/8/2017 | 17/6/2026 | Apache Struts 2.x before 2.3.24.1 allows remote attackers to manipulate Struts internals, alter user sessions, or affect container settings via vectors involving a top object. | |
| Modificada | Alta (7.5) | 11% | — | Apache Struts | 13/7/2017 | 17/6/2026 | When using a Spring AOP functionality to secure Struts actions it is possible to perform a DoS attack. Solution is to upgrade to Apache Struts version 2.5.12 or 2.3.33. | |
| Modificada | Media (5.9) | 9.8% | — | Apache Struts | 13/7/2017 | 17/6/2026 | If an application allows enter an URL in a form field and built-in URLValidator is used, it is possible to prepare a special URL which will be used to overload server process when performing validation of the URL. Solution is to upgrade to Apache Struts version 2.5.12. | |
| Analizada | Crítica (9.8) | 99% | ⚠ Explotación activa | Apache Struts | 10/7/2017 | 17/6/2026 | The Struts 1 plugin in Apache Struts 2.1.x and 2.3.x might allow remote code execution via a malicious field value passed in a raw message to the ActionMessage. | |
| Analizada | Crítica (9.8) | 100% | ⚠ Explotación activa | Apache StrutsIBM Storwize V3500 FirmwareIBM Storwize V5000 FirmwareIBM Storwize V7000 Firmware+5 | 11/3/2017 | 17/6/2026 | The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception handling and error-message generation during file-upload attempts, which allows remote attackers to execute arbitrary commands via a crafted Content-Type, Content-Disposition, or Content-Length HTTP… | |
| Modificada | Crítica (9.8) | 6.6% | — | Apache Struts | 3/10/2016 | 17/6/2026 | Apache Struts 2 before 2.3.29 and 2.5.x before 2.5.1 allow attackers to have unspecified impact via vectors related to improper action name clean up. | |
| Modificada | Media (5.3) | 10% | — | Apache Struts | 4/7/2016 | 17/6/2026 | The URLValidator class in Apache Struts 2 2.3.20 through 2.3.28.1 and 2.5.x before 2.5.1 allows remote attackers to cause a denial of service via a null value for a URL field. | |
| Modificada | Crítica (9.8) | 17% | — | Apache Struts | 4/7/2016 | 17/6/2026 | The REST plugin in Apache Struts 2 2.3.19 through 2.3.28.1 allows remote attackers to execute arbitrary code via a crafted expression. | |
| Modificada | Alta (7.5) | 9.8% | — | Apache Struts | 4/7/2016 | 17/6/2026 | Apache Struts 2 2.3.20 through 2.3.28.1 allows remote attackers to bypass intended access restrictions and conduct redirection attacks via a crafted request. |