Known vulnerabilities in Apache Struts

Software: Apache Struts
Software CPE: cpe:2.3:a:apache_foundation:struts:*:*:*:*:*:apache_tomcat:*:*
Total vulnerabilities: 43
Public exploits: 18
Known exploited (KEV): 8
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting Apache Struts Apache Struts is affected by 43 known vulnerabilities: 2 critical, 17 high, 18 medium, 6 low Critical High Medium Low

Vulnerabilities (43)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU144841 - Resource exhaustion
CVE-2026-73633
CWE-400 Medium
No
No
6.11.0, 7.3.0 24.08.2026 SB20260824147
#VU144840 - Allocation of Resources Without Limits or Throttling
CVE-2026-73635
CWE-770 Medium
No
No
6.11.0, 7.3.0 24.08.2026 SB20260824147
#VU144839 - Resource exhaustion
CVE-2026-73634
CWE-400 Medium
No
No
6.11.0, 7.3.0 24.08.2026 SB20260824147
#VU144837 - Exposure of Data Element to Wrong Session
CVE-2026-73632
CWE-488 Low
No
No
7.3.0 24.08.2026 SB20260824147
#VU144836 - Exposure of Data Element to Wrong Session
CVE-2026-73631
CWE-488 Medium
No
No
7.3.0 24.08.2026 SB20260824147
#VU121148 - Improper Restriction of XML External Entity Reference ('XXE')
CVE-2025-68493
CWE-611 Medium
Available
No
6.1.1 12.01.2026 SB2026011214
SB2026021948
SB20260428178
#VU119841 - Resource exhaustion
CVE-2025-66675
CWE-400 Medium
No
No
6.8.0, 7.1.1 11.12.2025 SB2025120157
SB2026021868
SB2026021948
#VU118877 - Resource exhaustion
CVE-2025-64775
CWE-400 Medium
No
No
6.8.0, 7.1.1 01.12.2025 SB2025120157
SB2026012180
SB2026021948
and 4 more
#VU101653 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2024-53677
CWE-22 High
Available
No
6.4.0 11.12.2024 SB2024121136
SB2025012198
SB2025041017
and 2 more
#VU83960 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2023-50164
CWE-22 High
Available
Exploited
2.5.33, 6.3.0.2 07.12.2023 SB2023120703
SB2023121830
SB2024011029
and 7 more
#VU80762 - Resource exhaustion
CVE-2023-41835
CWE-400 Medium
No
No
2.5.32, 6.1.2.2, 6.3.0.1 13.09.2023 SB2023091364
SB2023110308
SB2023113020
and 7 more
#VU77228 - Resource exhaustion
CVE-2023-34149
CWE-400 Medium
No
No
2.5.30.1, 6.1.2.1 13.06.2023 SB2023061351
SB2023070502
SB2023071316
and 7 more
#VU77227 - Resource exhaustion
CVE-2023-34396
CWE-400 Medium
No
No
2.5.30.1, 6.1.2.1 13.06.2023 SB2023061351
SB2023070502
SB2023071316
and 12 more
#VU62084 - Improper Control of Generation of Code ('Code Injection')
CVE-2021-31805
CWE-94 High
Available
No
2.5.30 12.04.2022 SB2022041218
SB2022061004
SB2022062415
and 10 more
#VU59098 - Improper Control of Generation of Code ('Code Injection')
CVE-2021-44832
CWE-94 Medium
No
No
2.5.28.3 28.12.2021 SB2021122816
SB2021123002
SB2022010601
and 197 more
#VU59051 - Loop with Unreachable Exit Condition ('Infinite Loop')
CVE-2021-45105
CWE-835 Medium
Available
No
2.5.28.2 18.12.2021 SB2021121802
SB2021121903
SB2021122011
and 169 more
#VU58976 - Improper Control of Generation of Code ('Code Injection')
CVE-2021-45046
CWE-94 High
Available
Exploited
2.5.28.1 15.12.2021 SB2021121504
SB2021121511
SB2021121512
and 178 more
#VU48815 - Improper Control of Generation of Code ('Code Injection')
CVE-2020-17530
CWE-94 High
Available
Exploited
2.5.26 08.12.2020 SB2020120801
SB2020122202
SB2021042111
and 9 more
#VU45703 - Improper Control of Generation of Code ('Code Injection')
CVE-2019-0230
CWE-94 High
Available
No
2.5.22 14.08.2020 SB2020081408
SB2021012211
SB2021012212
and 4 more
#VU45702 - Improper Access Control
CVE-2019-0233
CWE-284 Medium
No
No
2.5.22 14.08.2020 SB2020081408
SB2022072502
SB2023071310
and 2 more


Showing elements 1 - 20 out of 43