Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3037▲ 502 respecto a la semana anterior
Críticas / altas1448▲ 249 respecto a la semana anterior
Nueva explotación activa (KEV)8▼ 2 respecto a la semana anterior
Sin puntuar (sin CVSS)365▲ 158 respecto a la semana anterior
–

98 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (7.5)0.70%—Apache Struts15/8/202618/8/2026
Allocation of resources without limits or throttling vulnerability in Apache Struts. When no fixed locale is configured, the locale used for localized-text lookups is taken from the incoming request, allowing an unauthenticated remote client to cause the framework's internal localized-text caches to grow without bound…
AnalizadaAlta (7.5)0.73%—Apache Struts15/8/202618/8/2026
Uncontrolled resource consumption vulnerability in Apache Struts. An application that exposes an endpoint collecting Content Security Policy violation reports reads the submitted report into memory without bounding how much it will accept, so a single request can exhaust the heap and deny service to other users. Such…
AnalizadaMedia (4.3)0.38%—Apache Struts15/8/202618/8/2026
Exposure of data element to wrong session vulnerability in the JSON plugin of Apache Struts. Per-response serialization state could be shared across concurrent requests, allowing response content associated with one request to become observable in another. Only the SMD / JSON-RPC handling of the JSON interceptor is…
AnalizadaMedia (4.3)0.38%—Apache Struts15/8/202618/8/2026
Exposure of data element to wrong session vulnerability in the JSON plugin of Apache Struts. Per-request parsing state could be shared across concurrent requests, allowing data associated with one request to become observable in another, and configured parsing limits not to be enforced as intended. Populating actions…
AnalizadaAlta (7.5)0.70%—Apache Struts14/8/202618/8/2026
Uncontrolled resource consumption vulnerability in the JSON plugin of Apache Struts. When an application is configured to populate actions from a JSON request body, the plugin reads that body into memory without bounding how much it will accept, so a single request can exhaust the heap and deny service to other users.…
AplazadaCrítica (9.8)0.66%—Apache Struts2AIOwasp FactionAI26/5/202620/7/2026
FACTION is a PenTesting Report Generation and Collaboration Framework. Prior to 1.8.3, AccessControlInterceptor, the authentication gate for all Struts2 actions, unconditionally calls invocation.invoke() without checking for a valid session. Four action methods in BoilerPlateConfig perform no local session check…
ModificadaAlta (8.1)46%—Apache Struts11/1/202615/7/2026
Missing XML Validation vulnerability in Apache Struts, Apache Struts. This issue affects Apache Struts: from 2.0.0 before 2.2.1; Apache Struts: from 2.2.1 through 6.1.0. Users are recommended to upgrade to version 6.1.1, which fixes the issue.
AnalizadaAlta (8.2)0.59%—Apache Struts10/12/202517/6/2026
Denial of Service vulnerability in Apache Struts, file leak in multipart request processing causes disk exhaustion. This issue affects Apache Struts: from 2.0.0 through 6.7.4, from 7.0.0 through 7.0.3. Users are recommended to upgrade to version 6.8.0 or 7.1.1, which fixes the issue. It's related to…
AnalizadaAlta (7.5)1.5%—Apache Struts1/12/202517/6/2026
Denial of Service vulnerability in Apache Struts, file leak in multipart request processing causes disk exhaustion. This issue affects Apache Struts: from 2.0.0 through 6.7.0, from 7.0.0 through 7.0.3. Users are recommended to upgrade to version 6.8.0 or 7.1.1, which fixes the issue.
AplazadaCrítica (9.8)0.80%—ZTE ZxcdnAIApache StrutsAI14/10/202517/6/2026
ZTE's ZXCDN product is affected by a Struts remote code execution (RCE) vulnerability. An unauthenticated attacker can remotely execute commands with non-root privileges.
ModificadaMedia (6.5)0.59%—Apache Struts Extras30/7/202517/6/2026
** UNSUPPORTED WHEN ASSIGNED ** Improper Output Neutralization for Logs vulnerability in Apache Struts. This issue affects Apache Struts Extras: before 2. When using LookupDispatchAction, in some cases, Struts may print untrusted input to the logs without any filtering. Specially-crafted input may lead to log output…
AnalizadaCrítica (9.5)70%—Apache Struts11/12/202417/6/2026
File upload logic in Apache Struts is flawed. An attacker can manipulate file upload params to enable paths traversal and under some circumstances this can lead to uploading a malicious file which can be used to perform Remote Code Execution. This issue affects Apache Struts: from 2.0.0 before 6.4.0. Users are…
ModificadaCrítica (9.8)81%—Apache Struts7/12/202317/6/2026
An attacker can manipulate file upload params to enable paths traversal and under some circumstances this can lead to uploading a malicious file which can be used to perform Remote Code Execution. Users are recommended to upgrade to versions Struts 2.5.33 or Struts 6.3.0.2 or greater to fix this issue.
ModificadaAlta (7.5)7.3%—Apache Struts5/12/202317/6/2026
When a Multipart request is performed but some of the fields exceed the maxStringLength limit, the upload files will remain in struts.multipart.saveDir even if the request has been denied. Users are recommended to upgrade to versions Struts 2.5.32 or 6.1.2.2 or Struts 6.3.0.1 or greater, which fixe this issue.
ModificadaAlta (7.5)5.5%—Apache Struts14/6/202317/6/2026
Allocation of Resources Without Limits or Throttling vulnerability in Apache Software Foundation Apache Struts.This issue affects Apache Struts: through 2.5.30, through 6.1.2. Upgrade to Struts 2.5.31 or 6.1.2.1 or greater
ModificadaMedia (6.5)5.4%—Apache Struts14/6/202317/6/2026
Allocation of Resources Without Limits or Throttling vulnerability in Apache Software Foundation Apache Struts.This issue affects Apache Struts: through 2.5.30, through 6.1.2. Upgrade to Struts 2.5.31 or 6.1.2.1 or greater.
ModificadaCrítica (9.8)85%—Apache Struts12/4/202217/6/2026
The fix issued for CVE-2020-17530 was incomplete. So from Apache Struts 2.0.0 to 2.5.29, still some of the tag’s attributes could perform a double evaluation if a developer applied forced OGNL evaluation by using the %{...} syntax. Using forced OGNL evaluation on untrusted user input can lead to a Remote Code…
AnalizadaMedia (6.8)82%—Apache StrutsXstreamDebian LinuxFedoraproject Fedora16/12/202017/6/2026
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.15, is vulnerable to an Arbitrary File Deletion on the local host when unmarshalling. The vulnerability may allow a remote attacker to delete arbitrary know files on the host as log as the executing process has…
AnalizadaAlta (7.7)82%—Apache StrutsXstreamDebian LinuxFedoraproject Fedora16/12/202017/6/2026
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.15, a Server-Side Forgery Request vulnerability can be activated when unmarshalling. The vulnerability may allow a remote attacker to request data from internal resources that are not publicly available only by…
AnalizadaCrítica (9.8)96%⚠ Explotación activaApache StrutsOracle Business IntelligenceOracle Communications Diameter Intelligence HUBOracle Communications Policy Management+411/12/202017/6/2026
Forced OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote code execution. Affected software : Apache Struts 2.0.0 - Struts 2.5.25.
ModificadaAlta (7.5)68%—Apache StrutsOracle Communications Policy ManagementOracle Financial Services Data Integration HUBOracle Financial Services Market Risk Measurement AND Management+114/9/202017/6/2026
An access permission override in Apache Struts 2.0.0 to 2.5.20 may cause a Denial of Service when performing a file upload.
ModificadaCrítica (9.8)97%—Apache StrutsOracle Communications Policy ManagementOracle Financial Services Data Integration HUBOracle Financial Services Market Risk Measurement AND Management+114/9/202017/6/2026
Apache Struts 2.0.0 to 2.5.20 forced double OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote code execution.
ModificadaMedia (6.1)5.8%—Apache Struts27/2/202017/6/2026
Apache Struts before 2.3.20 has a cross-site scripting (XSS) vulnerability.
ModificadaAlta (8.8)29%—Apache Struts5/12/201916/6/2026
A local code execution issue exists in Apache Struts2 when processing malformed XSLT files, which could let a malicious user upload and execute arbitrary files.
ModificadaCrítica (9.8)89%—Apache StrutsRedhat Jboss Enterprise WEB Server1/11/201916/6/2026
Apache Struts before 2.3.1.2 allows remote attackers to bypass security protections in the ParameterInterceptor class and execute arbitrary commands.