Known vulnerabilities in Apache Struts - page 3
Vendor:
Apache Foundation
Software:
Apache Struts
Software CPE:
cpe:2.3:a:apache_foundation:struts:*:*:*:*:*:apache_tomcat:*:*
Website:
https://www.apache.org
Total vulnerabilities:
43
Public exploits:
18
Known exploited (KEV):
8
Highest CVSSv4 Score:
9.3
Breakdown by Severity Chart
6.11.0
7.3.0
6.10.0
7.2.1
6.9.0
1.3.9
1.3.8
1.3.7
1.3.6
1.3.5
1.3.4
1.3.3
1.3.2
1.3.1
1.3.0
1.2.8
1.2.6
1.2.5
1.2.4
1.2.3
1.2.2
1.2.1
1.2
1.1
1.0.2
1.0.1
1.0
6.8.0
7.1.1
7.0.3
7.0.0
6.7.0
6.6.1
6.6.0
1.2.9-162.163.2
1.2.9-198.2
1.2.9-108.2
1.2.9-162.31.1
1.2.9
1.2.7
6.4.0
2.5.33
6.3.0.2
6.1.2.2
2.5.32
6.3.0.1
6.3.0
2.5.31
6.2.0
2.5.30.1
6.1.2.1
6.1.2
6.1.1
6.0.3
6.0.0
2.5.30
2.5.29
2.5.28.3
2.5.28.2
2.5.28.1
2.5.28
2.5.27
2.5.26
2.5.25
2.5.22
2.5.20
2.3.33
1.3.10
2.5.18
2.3.36
2.5.17
2.3.35
2.5.16
2.5.14.1
2.5.14
2.3.34
2.5.13
2.5.12
2.1.1
2.2.0
2.2.2
2.3.5
2.3.6
2.3.9
2.3.10
2.3.11
2.3.13
2.3.16.2
2.3.16.3
2.3.17
2.3.19
2.3.21
2.3.22
2.3.23
2.3.24.2
2.3.25
2.3.26
2.3.27
2.3.29
2.3.31
2.3.32
2.3.2
2.5.10.1
2.5.10
2.5.9
2.5.8
2.5.7
2.5.6
2.5.5
2.5.4
2.5.3
2.5.2
2.5.1
2.5
2.3.16.1
2.3.16
2.3.15.3
2.3.15.2
2.3.15.1
2.3.15
2.3.14.3
2.3.14.2
2.3.14.1
2.3.14
2.3.12
2.3.8
2.3.7
2.3.4.1
2.3.4
2.3.3
2.3.1.2
2.3.1.1
2.3.1
2.2.3.1
2.2.3
2.2.1.1
2.2.1
2.1.8.1
2.1.8
2.1.7
2.1.6
2.1.5
2.1.4
2.1.3
2.1.2
2.1.0
2.0.14
2.0.13
2.0.12
2.0.11.2
2.0.11.1
2.0.11
2.0.10
2.0.9
2.0.8
2.0.7
2.0.6
2.0.5
2.0.4
2.0.3
2.0.2
2.0.1
2.0.0
2.3.30
2.3.28.1
2.3.28
2.3.24.3
2.3.24.1
2.3.24
2.3.20.3
2.3.20.2
2.3.20.1
2.3.20
Vulnerabilities (43)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU5233 - Resource exhaustion CVE-2014-0050 |
CWE-400 | Medium | 2.3.16.1 | 23.01.2017 |
SB2014020601 SB2015092620 SB2014041701 and 12 more |
||
| #VU49061 - Improper Control of Generation of Code ('Code Injection') CVE-2012-0392 |
CWE-94 | High | 2.3.1.1 | 08.01.2012 |
SB2012010805 SB20240417121 SB2024053144 |
||
| #VU49062 - Improper Control of Generation of Code ('Code Injection') CVE-2012-0391 |
CWE-94 | High | 2.2.3.1 | 08.01.2012 |
SB2012010806 SB20240417121 SB2024053144 |
Showing elements 41 - 60 out of 43