Vulnerability index

Browse CVEs

40 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

HIGH 8.1 CVE-2017-12615 KEVEPSS 100% When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g. via setting the readonly initialisation parameter of the Default t… Tomcat after 7.0.79 Fix from $1,9502017-09-19 HIGH 8.1 CVE-2017-9805 KEVEPSS 99% The REST Plugin in Apache Struts 2.1.1 through 2.3.x before 2.3.34 and 2.5.x before 2.5.13 uses an XStreamHandler with an instance of XStream for des… Struts 2.3.34 / 2.5.13+ Fix from $1,9502017-09-15 CRITICAL 9.8 CVE-2017-9791 KEVEPSS 99% The Struts 1 plugin in Apache Struts 2.1.x and 2.3.x might allow remote code execution via a malicious field value passed in a raw message to the Act… Struts Patch available Fix from $2,3002017-07-10 CRITICAL 9.8 CVE-2016-8735 KEVEPSS 90% Remote code execution is possible with Apache Tomcat before 6.0.48, 7.x before 7.0.73, 8.x before 8.0.39, 8.5.x before 8.5.7, and 9.x before 9.0.0.M1… Tomcat 6.0.48 / 7.0.73+ Fix from $2,3002017-04-06 CRITICAL 9.8 CVE-2017-5638 KEVEPSS 100% The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception handling and error-message gene… Struts 2.3.32 / 2.5.10.1+ Fix from $2,3002017-03-11 CRITICAL 9.8 CVE-2016-4437 KEVEPSS 93% Apache Shiro before 1.2.5, when a cipher key has not been configured for the "remember me" feature, allows remote attackers to execute arbitrary code… Aurora 0.18.1 / 1.2.5+ Fix from $2,3002016-06-07 CRITICAL 9.8 CVE-2016-3088 KEVEPSS 99% The Fileserver web application in Apache ActiveMQ 5.x before 5.14.0 allows remote attackers to upload and execute arbitrary files via an HTTP PUT fol… Activemq 5.14.0+ Fix from $2,3002016-06-01 CRITICAL 9.8 CVE-2013-2251 KEVEPSS 100% Apache Struts 2.0.0 through 2.3.15 allows remote attackers to execute arbitrary OGNL expressions via a parameter with a crafted (1) action:, (2) redi… Archiva 1.3.8+ Fix from $2,3002013-07-20 CRITICAL 9.8 CVE-2012-0391 KEVEPSS 75% The ExceptionDelegator component in Apache Struts before 2.2.3.1 interprets parameter values as OGNL expressions during certain exception handling fo… Struts 2.2.3.1+ Fix from $2,3002012-01-08 HIGH 7.5 CVE-2006-1547 KEVEPSS 55% ActionForm in Apache Software Foundation (ASF) Struts before 1.2.9 with BeanUtils 1.7 allows remote attackers to cause a denial of service via a mult… Struts 1.2.9+ Fix from $1,9502006-03-30