Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3028▼ 62 respecto a la semana anterior
Críticas / altas1422▲ 60 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
102 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 9.8% | — | Apache Struts | 4/7/2016 | 17/6/2026 | Apache Struts 2 2.3.20 through 2.3.28.1 allows remote attackers to bypass intended access restrictions and conduct redirection attacks by leveraging a default method. | |
| Modificada | Alta (8.8) | 3.7% | — | Apache Struts | 4/7/2016 | 17/6/2026 | Apache Struts 2 2.3.20 through 2.3.28.1 mishandles token validation, which allows remote attackers to conduct cross-site request forgery (CSRF) attacks via unspecified vectors. | |
| Modificada | Alta (8.2) | 26% | — | Apache Struts | 4/7/2016 | 17/6/2026 | ActionServlet.java in Apache Struts 1 1.x through 1.3.10 does not properly restrict the Validator configuration, which allows remote attackers to conduct cross-site scripting (XSS) attacks or cause a denial of service via crafted input, a related issue to CVE-2015-0899. | |
| Modificada | Alta (8.1) | 13% | — | Oracle Banking PlatformOracle PortalApache Struts | 4/7/2016 | 17/6/2026 | ActionServlet.java in Apache Struts 1 1.x through 1.3.10 mishandles multithreaded access to an ActionForm instance, which allows remote attackers to execute arbitrary code or cause a denial of service (unexpected memory access) via a multipart request, a related issue to CVE-2015-0899. | |
| Modificada | Alta (7.5) | 21% | — | Apache Struts | 4/7/2016 | 17/6/2026 | The MultiPageValidator implementation in Apache Struts 1 1.1 through 1.3.10 allows remote attackers to bypass intended access restrictions via a modified page parameter. | |
| Modificada | Media (5.3) | 8.4% | — | Ognl Project OgnlApache Struts | 7/6/2016 | 17/6/2026 | Apache Struts 2.0.0 through 2.3.24.1 does not properly cache method references when used with OGNL before 3.0.12, which allows remote attackers to cause a denial of service (block access to a web site) via unspecified vectors. | |
| Modificada | Crítica (9.8) | 82% | — | Apache Struts | 7/6/2016 | 17/6/2026 | Apache Struts 2.3.19 to 2.3.20.2, 2.3.21 to 2.3.24.1, and 2.3.25 to 2.3.28, when Dynamic Method Invocation is enabled, allow remote attackers to execute arbitrary code via vectors related to an ! (exclamation mark) operator to the REST Plugin. | |
| Modificada | Crítica (9.8) | 19% | — | Apache Struts | 26/4/2016 | 17/6/2026 | XSLTResult in Apache Struts 2.x before 2.3.20.2, 2.3.24.x before 2.3.24.2, and 2.3.28.x before 2.3.28.1 allows remote attackers to execute arbitrary code via the stylesheet location parameter. | |
| Modificada | Alta (8.1) | 93% | — | Apache StrutsOracle Siebel E-billing | 26/4/2016 | 17/6/2026 | Apache Struts 2.3.19 to 2.3.20.2, 2.3.21 to 2.3.24.1, and 2.3.25 to 2.3.28, when Dynamic Method Invocation is enabled, allow remote attackers to execute arbitrary code via method: prefix, related to chained expressions. | |
| Modificada | Media (6.1) | 12% | — | Apache Struts | 12/4/2016 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the URLDecoder function in JRE before 1.8, as used in Apache Struts 2.x before 2.3.28, when using a single byte page encoding, allows remote attackers to inject arbitrary web script or HTML via multi-byte characters in a url-encoded parameter. | |
| Modificada | Media (6.1) | 7.8% | — | Apache Struts | 12/4/2016 | 17/6/2026 | Apache Struts 2.x before 2.3.25 does not sanitize text in the Locale object constructed by I18NInterceptor, which might allow remote attackers to conduct cross-site scripting (XSS) attacks via unspecified vectors involving language display. | |
| Modificada | Alta (8.8) | 8.9% | — | Apache Struts | 12/4/2016 | 17/6/2026 | Apache Struts 2.x before 2.3.28 allows remote attackers to execute arbitrary code via a "%{}" sequence in a tag attribute, aka forced double OGNL evaluation. | |
| Modificada | Alta (7.5) | 6.4% | — | Apache Struts | 16/7/2015 | 17/6/2026 | The default exclude patterns (excludeParams) in Apache Struts 2.3.20 allow remote attackers to "compromise internal state of an application" via unspecified vectors. | |
| Modificada | Media (6.8) | 3.5% | — | Apache Struts | 10/12/2014 | 17/6/2026 | Apache Struts 2.0.0 through 2.3.x before 2.3.20 uses predictable <s:token/> values, which allows remote attackers to bypass the CSRF protection mechanism. | |
| Modificada | Media (5.8) | 6.6% | — | Apache Struts | 8/5/2014 | 17/6/2026 | CookieInterceptor in Apache Struts 2.x before 2.3.20, when a wildcard cookiesName value is used, does not properly restrict access to the getClass method, which allows remote attackers to "manipulate" the ClassLoader and modify session state via a crafted request. NOTE: this vulnerability exists because of an… | |
| Modificada | Alta (7.5) | 99% | — | Apache Commons BeanutilsApache Struts | 30/4/2014 | 17/6/2026 | Apache Commons BeanUtils, as distributed in lib/commons-beanutils-1.8.0.jar in Apache Struts 1.x through 1.3.10 and in other products requiring commons-beanutils through 1.9.2, does not suppress the class property, which allows remote attackers to "manipulate" the ClassLoader and execute arbitrary code via the class… | |
| Modificada | Alta (7.5) | 78% | — | Apache Struts | 29/4/2014 | 17/6/2026 | CookieInterceptor in Apache Struts before 2.3.20, when a wildcard cookiesName value is used, does not properly restrict access to the getClass method, which allows remote attackers to "manipulate" the ClassLoader and execute arbitrary code via a crafted request. NOTE: this vulnerability exists because of an incomplete… | |
| Modificada | Alta (7.5) | 98% | — | Apache Struts | 29/4/2014 | 17/6/2026 | ParametersInterceptor in Apache Struts before 2.3.20 does not properly restrict access to the getClass method, which allows remote attackers to "manipulate" the ClassLoader and execute arbitrary code via a crafted request. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-0094. | |
| Modificada | Media (5) | 100% | — | Apache Struts | 11/3/2014 | 17/6/2026 | The ParametersInterceptor in Apache Struts before 2.3.16.2 allows remote attackers to "manipulate" the ClassLoader via the class parameter, which is passed to the getClass method. | |
| Modificada | Media (4.3) | 6.1% | — | Apache Struts | 2/11/2013 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Apache Struts 2.3.15.3 allow remote attackers to inject arbitrary web script or HTML via the namespace parameter to (1) actionNames.action and (2) showConfig.action in config-browser/. | |
| Modificada | Alta (10) | 8.4% | — | Apache StrutsOracle Flexcube Private BankingOracle Mysql Enterprise MonitorOracle Webcenter Sites | 30/9/2013 | 16/6/2026 | Apache Struts 2.0.0 through 2.3.15.1 enables Dynamic Method Invocation by default, which has unknown impact and attack vectors. | |
| Modificada | Media (5.8) | 6.5% | — | Apache Struts | 30/9/2013 | 16/6/2026 | Apache Struts 2.0.0 through 2.3.15.1 allows remote attackers to bypass access controls via a crafted action: prefix. | |
| Analizada | Crítica (9.8) | 100% | ⚠ Explotación activa | Apache ArchivaApache StrutsFujitsu Interstage Business Process Manager AnalyticsOracle Siebel Apps - E-billing | 20/7/2013 | 16/6/2026 | Apache Struts 2.0.0 through 2.3.15 allows remote attackers to execute arbitrary OGNL expressions via a parameter with a crafted (1) action:, (2) redirect:, or (3) redirectAction: prefix. | |
| Modificada | Media (5.8) | 95% | — | Apache Struts | 20/7/2013 | 16/6/2026 | Multiple open redirect vulnerabilities in Apache Struts 2.0.0 through 2.3.15 allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in a parameter using the (1) redirect: or (2) redirectAction: prefix. | |
| Modificada | Alta (9.3) | 14% | — | Apache Struts | 16/7/2013 | 16/6/2026 | Apache Struts 2 before 2.3.14.3 allows remote attackers to execute arbitrary OGNL code via a request with a crafted value that contains both "${}" and "%{}" sequences, which causes the OGNL code to be evaluated twice. |