NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
20086  CVE-2016-4430  Apache Struts 2 2.3.20 through 2.3.28.1 mishandles token validation, which allows remote attackers to conduct cross-site request forgery (CSRF) attacks via unspecified vectors.    6.8  Medium  2017-01-19  2016-10-06  View
42906  CVE-2012-0838  Apache Struts 2 before 2.2.3.1 evaluates a string as an OGNL expression during the handling of a conversion error, which allows remote attackers to modify run-time data values, and consequently execute arbitrary code, via invalid input to a field.    10  High  2017-01-19  2013-07-26  View
38091  CVE-2013-1966  Apache Struts 2 before 2.3.14.1 allows remote attackers to execute arbitrary OGNL code via a crafted request that is not properly handled when using the includeParams attribute in the (1) URL or (2) A tag.    9.3  High  2017-01-18  2013-07-11  View
38215  CVE-2013-2115  Apache Struts 2 before 2.3.14.2 allows remote attackers to execute arbitrary OGNL code via a crafted request that is not properly handled when using the includeParams attribute in the (1) URL or (2) A tag. NOTE: this issue is due to an incomplete fix for CVE-2013-1966.    9.3  High  2017-01-18  2013-07-11  View
38233  CVE-2013-2134  Apache Struts 2 before 2.3.14.3 allows remote attackers to execute arbitrary OGNL code via a request with a crafted action name that is not properly handled during wildcard matching, a different vulnerability than CVE-2013-2135.    9.3  High  2017-01-18  2017-01-06  View

Page 1285 of 17672, showing 5 records out of 88360 total, starting on record 6421, ending on 6425

Actions