An open API service providing security vulnerability metadata for many open source software ecosystems.

Browse Security Advisories

Critical
11 months ago

Apache Struts file upload logic is flawed GSA_kwCzR0hTQS00M21xLTZ4bWctMjl2bc4ABCSU

maven org.apache.struts:struts2-core
Critical
almost 2 years ago

Apache Struts vulnerable to path traversal GSA_kwCzR0hTQS0yajM5LXFjam0tNDI4d84AA3mt

maven org.apache.struts:struts2-core
High
over 2 years ago

Apache Struts vulnerable to memory exhaustion GSA_kwCzR0hTQS00ZzQyLWdxcmctNDYzM84AAz2O

maven struts:struts, org.apache.struts:struts-core
Moderate
over 2 years ago

Apache Struts vulnerable to memory exhaustion GSA_kwCzR0hTQS04ZjZ4LXY2ODUtZzJ4Y84AAz2D

maven org.apache.struts:struts2-core
Moderate
over 3 years ago

Apache Struts is vulnerable to Cross-site Scripting GSA_kwCzR0hTQS1qZ2NyLTljMnEtcnZwOM4AAgP6

maven org.apache.struts:struts2-core
Moderate
over 3 years ago

Apache Struts directory traversal vulnerability GSA_kwCzR0hTQS13djdnLXhodnctOGhjcM4AAgPc

maven org.apache.struts:struts2-core
Moderate
over 3 years ago

Apache Struts Multiple XSS Vulnerabilities GSA_kwCzR0hTQS01cGdqLXI3YzYtN2M3d84AAf9i

maven org.apache.struts:struts2-parent
Moderate
over 3 years ago

Apache Struts2 Broken Access Control Vulnerability GSA_kwCzR0hTQS1xNXE4LWpnaGYtM3BtM84AAekz

maven org.apache.struts:struts2-core
Moderate
over 3 years ago

Apache Struts XSS Vulnerability GSA_kwCzR0hTQS0yajRxLTlmZmYtMjM2as4AAdCC

maven org.apache.struts:struts2-core
High
over 3 years ago

Code injection in Apache Struts GSA_kwCzR0hTQS1qN2g2LXhyN2ctbTJjNc4AAcrC

maven org.apache.struts:struts2-rest-plugin, org.apache.struts:struts2-core
Moderate
over 3 years ago

Open redirect in Apache Struts GSA_kwCzR0hTQS1ycGo5LXI4OTctd2M2cc4AAcSx

maven org.apache.struts:struts2-core
High
over 3 years ago

Apache Struts Access Control Redirect GSA_kwCzR0hTQS12cTc5LW1ncHgtMnd4NM4AAa4S

maven org.apache.struts:struts-parent
Critical
over 3 years ago

Apache Struts improper action name cleanup GSA_kwCzR0hTQS14bTkyLXYybXEtODQycc4AAa4Q

maven org.apache.struts:struts2-core
High
over 3 years ago

Apache Struts Open Redirect GSA_kwCzR0hTQS13bTh3LXFwMmYtNzI4cc4AAa4R

maven org.apache.struts.xwork:xwork-core
Moderate
over 3 years ago

Denial of service in Apache Struts GSA_kwCzR0hTQS1ocmdjLTU0bXYtNThnds4AAaDb

maven org.apache.struts.xwork:xwork-core
High
over 3 years ago

Incomplete exclude pattern in Apache Struts GSA_kwCzR0hTQS1xMmNnLXhmOXAtaDQ1N84AAYyu

maven org.apache.struts.xwork:xwork-core, org.apache.struts:struts2-core
High
over 3 years ago

Apache Struts CSRF Vulnerability GSA_kwCzR0hTQS0zOHF3LWo3ODctdjhjMs4AAYUX

maven org.apache.struts.xwork:xwork-core
Moderate
over 3 years ago

XWork in Apache Struts Reveals Sensitive Information GSA_kwCzR0hTQS05Y2NtLWczNjItMnIzNc4AAWMP

maven org.apache.struts.xwork:xwork-core
Moderate
over 3 years ago

Cross-Site Request Forgery in Apache Struts GSA_kwCzR0hTQS1oNHY5LWpmMnItOWg2bc4AAWFk

maven org.apache.struts:struts2-core
High
over 3 years ago

Arbitrary code execution in Apache Struts 2 GSA_kwCzR0hTQS1ncXFtLTU2NGYtdnZ4cc4AAUxj

maven org.apache.struts.xwork:xwork-core, org.apache.struts:struts2-core
Moderate
over 3 years ago

Cross-site Scripting in Apache Struts GSA_kwCzR0hTQS1tM3g2LTl2NmgtNGcyOM4AAUxh

maven org.apache.struts:struts2-core
High
over 3 years ago

Arbitrary code execution in Apache Struts 2 GSA_kwCzR0hTQS1wdzhyLXgycW0tM2g1bc4AAUxe

maven org.apache.struts.xwork:xwork-core, org.apache.struts:struts2-core
Moderate
over 3 years ago

ClassLoader manipulation in Apache Struts GSA_kwCzR0hTQS12cndjLXFqbXctNXJqbc4AATRA

maven org.apache.struts:struts2-core
High
over 3 years ago

Arbitrary code execution in Apache Struts GSA_kwCzR0hTQS03Mzd3LW1oNTgtY3hqcM4AATQ_

maven org.apache.struts.xwork:xwork-core, org.apache.struts:struts2-core
High
over 3 years ago

ClassLoader manipulation in Apache Struts GSA_kwCzR0hTQS1obWhxLTM4MnEtbXA1Ns4AATQ0

maven org.apache.struts:struts2-core
Critical
over 3 years ago

Path Traversal in Apache Struts GSA_kwCzR0hTQS00NGh2LWpqeDctcWZqZ84AATQy

maven org.apache.struts:struts2-convention-plugin
Critical
over 3 years ago

Arbitrary code execution in Apache Struts 2 GSA_kwCzR0hTQS00cHJqLXZ3OWotdjZwcs4AATRG

maven org.apache.struts:struts2-rest-plugin, org.apache.struts:struts2-core
High
over 3 years ago

Apache Struts RCE Vulnerability GSA_kwCzR0hTQS04NzZwLTR3Z2MtNzVyeM4AATMB

maven org.apache.struts:struts2-core
Critical
over 3 years ago

Code execution in Apache Struts 1 plugin GSA_kwCzR0hTQS0yOXJtLTY3NTItZ3Z3ds4AAQdV

maven org.apache.struts:struts2-struts1-plugin
High
over 3 years ago

Code injection in Apache Struts GSA_kwCzR0hTQS03Z2htLXJwYzctcDdnNc34jQ

maven org.apache.struts.xwork:xwork-core, org.apache.struts:struts2-core
Critical
over 3 years ago

Code injection in Apache Struts GSA_kwCzR0hTQS00N3FwLTh2OWctMzlocM32gA

maven org.apache.struts:struts2-core
Critical
over 3 years ago

Apache Struts Remote Java Code Execution GSA_kwCzR0hTQS00d3JyLTloNXItbTkyd83e2w

maven org.apache.struts.xwork:xwork-core, org.apache.struts:struts2-core
Moderate
over 3 years ago

Apache Struts's CookieInterceptor component does not use the parameter-name whitelist GSA_kwCzR0hTQS0ycHBwLXhqMzQtdnZmN83e3A

maven org.apache.struts.xwork:xwork-core, org.apache.struts:struts2-core

Filter by Severity

Filter by Ecosystem

Filter by Package

tensorflow 433 moodle/moodle 425 tensorflow-cpu 410 tensorflow-gpu 394 magento/community-edition 325 Microsoft.ChakraCore 247 org.jenkins-ci.main:jenkins-core 242 typo3/cms 166 com.liferay.portal:release.portal.bom 151 org.apache.tomcat:tomcat 136 github.com/mattermost/mattermost/server/v8 136 com.liferay.portal:release.dxp.bom 124 pimcore/pimcore 120 dolibarr/dolibarr 117 typo3/cms-core 107 phpmyadmin/phpmyadmin 107 microweber/microweber 103 drupal/core 99 silverstripe/framework 90 apache-airflow 89 Django 89 librenms/librenms 86 magento/project-community-edition 84 thorsten/phpmyfaq 74 drupal/drupal 71 github.com/mattermost/mattermost-server 69 com.fasterxml.jackson.core:jackson-databind 69 github.com/usememos/memos 68 concrete5/concrete5 67 salt 65 ansible 64 shopware/platform 62 apache-superset 61 actionpack 58 symfony/symfony 58 github.com/grafana/grafana 56 org.apache.struts:struts2-core 55 Plone 54 craftcms/cms 53 mlflow 53 shopware/core 51 org.keycloak:keycloak-core 50 github.com/rancher/rancher 50 github.com/hashicorp/vault 48 nova 48 mautic/core 47 baserproject/basercms 47 django 46 nokogiri 45 mantisbt/mantisbt 45 org.keycloak:keycloak-services 45 vyper 44 gradio 44 org.xwiki.platform:xwiki-platform-oldcore 43 org.elasticsearch:elasticsearch 43 matrix-synapse 43 nilsteampassnet/teampass 42 rdiffweb 42 plone 41 showdoc/showdoc 41 org.apache.tomcat.embed:tomcat-embed-core 41 froxlor/froxlor 40 k8s.io/kubernetes 40 intelliants/subrion 40 picklescan 39 directus 39 snipe/snipe-it 38 net.mingsoft:ms-mcms 38 github.com/mattermost/mattermost-server/v6 38 com.thoughtworks.xstream:xstream 37 com.jfinal:jfinal 36 github.com/argoproj/argo-cd/v2 36 rack 35 io.undertow:undertow-core 35 moin 35 github.com/answerdev/answer 34 parse-server 33 org.jenkins-ci.plugins:script-security 33 zendframework/zendframework1 32 gogs.io/gogs 32 shopware/shopware 31 opencv-python 31 github.com/hashicorp/nomad 31 github.com/cilium/cilium 31 keystone 31 flowise 31 github.com/hashicorp/consul 31 opencv-contrib-python 30 getgrav/grav 30 github.com/argoproj/argo-cd 30 github.com/docker/docker 29 contao/core-bundle 29 next 29 org.apache.solr:solr-core 28 electron 28 Pillow 28 mediawiki/core 28 pillow 28 DotNetNuke.Core 28 vllm 28 org.opencms:opencms-core 27 org.springframework.security:spring-security-core 27 centreon/centreon 27 prestashop/prestashop 27 org.apache.tomcat:tomcat-catalina 26 open-webui 25 github.com/traefik/traefik/v2 25 rubygems-update 25 org.eclipse.jetty:jetty-server 25 openssl-src 25 pocketmine/pocketmine-mp 25 getkirby/cms 24 pyload-ng 24 surrealdb 24 magento/core 24 org.keycloak:keycloak-parent 24 simplesamlphp/simplesamlphp 23 grumpydictator/firefly-iii 23 puppet 23 laravel/framework 23 remdex/livehelperchat 23 zendframework/zendframework 22 org.apache.openmeetings:openmeetings-parent 22 phpoffice/phpspreadsheet 22 activerecord 22 tribalsystems/zenario 22 deno 22 ckb 22 @openzeppelin/contracts-upgradeable 21 org.bouncycastle:bcprov-jdk15on 21 wasmtime 21 Microsoft.AspNetCore.App.Runtime.win-x64 21 github.com/ethereum/go-ethereum 21 glance 21 github.com/goharbor/harbor 21 @openzeppelin/contracts 21 org.apache.nifi:nifi 21 aim 20 org.xwiki.platform:xwiki-platform-web-templates 20 Microsoft.AspNetCore.App.Runtime.win-x86 20 typo3/cms-backend 20 code.gitea.io/gitea 20 ethyca-fides 20 org.cloudfoundry.identity:cloudfoundry-identity-server 20 cockpit-hq/cockpit 20 funadmin/funadmin 20 topthink/framework 19 neutron 19 Microsoft.AspNetCore.App.Runtime.win-arm 19 contao/contao 19 transformers 19 helm.sh/helm/v3 19 langchain 19 github.com/zitadel/zitadel 19 com.liferay.portal:com.liferay.portal.impl 18 com.vaadin:vaadin-bom 18 mercurial 18 cobbler 18 mindsdb 18 golang.org/x/net 18 forkcms/forkcms 18 org.springframework:spring-core 18 Microsoft.AspNetCore.App.Runtime.osx-x64 18 genix/cms 18 Microsoft.AspNetCore.App.Runtime.linux-musl-x64 18 Microsoft.AspNetCore.App.Runtime.linux-arm64 18 org.apache.jspwiki:jspwiki-main 18 openmage/magento-lts 18 Microsoft.AspNetCore.App.Runtime.linux-x64 18 Microsoft.AspNetCore.App.Runtime.win-arm64 18 cakephp/cakephp 17 github.com/traefik/traefik/v3 17 Microsoft.AspNetCore.App.Runtime.linux-musl-arm64 17 org.apache.geode:geode-core 17 Microsoft.AspNetCore.App.Runtime.linux-arm 17 cryptography 17 org.apache.inlong:manager-pojo 17 ezsystems/ezpublish-kernel 17 github.com/openfga/openfga 17 calibreweb 17 OctoPrint 17 francoisjacquet/rosariosis 17 yetiforce/yetiforce-crm 17 notebook 17 opencart/opencart 17 org.apache.ranger:ranger 16 lollms 16 vite 16 org.apache.tomcat:tomcat-coyote 16 rusqlite 16 phpbb/phpbb 16 PaddlePaddle 16 sequelize 16 ghost 16 org.apache.activemq:activemq-client 16 org.apache.dubbo:dubbo 16 paddlepaddle 16 tinymce 16 aiohttp 15 ckeditor4 15

Filter by Repository

https://github.com/tensorflow/tensorflow 433 https://github.com/moodle/moodle 250 https://github.com/xwiki/xwiki-platform 222 https://github.com/chakra-core/ChakraCore 214 https://github.com/jenkinsci/jenkins 178 https://github.com/liferay/liferay-portal 169 https://github.com/django/django 119 https://github.com/apache/tomcat 118 https://github.com/pimcore/pimcore 116 https://github.com/apache/airflow 105 https://github.com/TYPO3/typo3 94 https://github.com/microweber/microweber 90 https://github.com/keycloak/keycloak 90 https://github.com/librenms/librenms 77 https://github.com/rails/rails 70 https://github.com/FasterXML/jackson-databind 70 https://github.com/thorsten/phpmyfaq 69 https://github.com/silverstripe/silverstripe-framework 68 https://github.com/usememos/memos 68 https://github.com/kubernetes/kubernetes 66 https://github.com/symfony/symfony 64 https://github.com/Dolibarr/dolibarr 60 https://github.com/ansible/ansible 59 https://github.com/mattermost/mattermost 59 https://github.com/python-pillow/Pillow 52 https://github.com/spring-projects/spring-framework 51 https://github.com/argoproj/argo-cd 50 https://github.com/grafana/grafana 47 https://github.com/apache/struts 47 https://github.com/rancher/rancher 46 https://github.com/mautic/mautic 46 https://github.com/phpmyadmin/phpmyadmin 45 https://github.com/vyperlang/vyper 44 https://github.com/concretecms/concretecms 44 https://github.com/shopware/platform 43 https://github.com/mantisbt/mantisbt 42 https://github.com/ikus060/rdiffweb 42 https://github.com/saltstack/salt 42 https://github.com/craftcms/cms 41 https://github.com/directus/directus 41 https://github.com/shopware/shopware 40 https://github.com/gradio-app/gradio 39 https://github.com/mmaitre314/picklescan 39 https://github.com/star7th/showdoc 39 https://github.com/openstack/nova 38 https://github.com/magento/magento2 38 https://github.com/dotnet/runtime 38 https://github.com/x-stream/xstream 37 https://github.com/plone/Products.CMFPlone 37 https://github.com/octobercms/october 36 https://github.com/sparklemotion/nokogiri 35 https://github.com/umbraco/Umbraco-CMS 35 https://github.com/mlflow/mlflow 35 https://github.com/answerdev/answer 34 https://github.com/apache/activemq 34 https://github.com/parse-community/parse-server 33 https://github.com/go-gitea/gitea 32 https://github.com/matrix-org/synapse 32 https://github.com/opencv/opencv 32 https://github.com/cilium/cilium 31 https://github.com/apache/inlong 31 https://github.com/PaddlePaddle/Paddle 31 https://github.com/snipe/snipe-it 30 https://github.com/contao/contao 30 https://github.com/rack/rack 29 https://github.com/strapi/strapi 29 https://github.com/FlowiseAI/Flowise 28 https://github.com/gogs/gogs 28 https://github.com/openstack/keystone 28 https://github.com/electron/electron 28 https://github.com/CVEProject/cvelist 28 https://github.com/netty/netty 27 https://github.com/baserproject/basercms 26 https://github.com/froxlor/froxlor 26 https://github.com/github/advisory-database 26 https://github.com/geoserver/geoserver 26 https://github.com/apache/nifi 26 https://github.com/bcgit/bc-java 25 https://github.com/zitadel/zitadel 25 https://github.com/vercel/next.js 25 https://github.com/langchain-ai/langchain 25 https://github.com/surrealdb/surrealdb 25 https://github.com/vllm-project/vllm 25 https://github.com/traefik/traefik 25 https://github.com/denoland/deno 25 https://github.com/pmmp/PocketMine-MP 25 https://github.com/apache/cxf 24 https://github.com/pyload/pyload 24 https://github.com/getgrav/grav 24 https://github.com/hashicorp/consul 24 https://github.com/run-llama/llama_index 24 https://github.com/PrestaShop/PrestaShop 23 https://github.com/TYPO3/TYPO3.CMS 23 https://github.com/eclipse/jetty.project 23 https://github.com/livehelperchat/livehelperchat 23 https://github.com/bytecodealliance/wasmtime 23 https://github.com/moby/moby 23 https://github.com/nilsteampassnet/TeamPass 23 https://github.com/dnnsoftware/Dnn.Platform 23 https://github.com/firefly-iii/firefly-iii 23 https://github.com/nervosnetwork/ckb 22 https://github.com/jenkinsci/script-security-plugin 22 https://github.com/PHPOffice/PhpSpreadsheet 22 https://github.com/helm/helm 22 https://github.com/getkirby/kirby 22 https://github.com/laravel/framework 21 https://github.com/undertow-io/undertow 21 https://github.com/hashicorp/vault 21 https://github.com/goharbor/harbor 21 https://github.com/OpenZeppelin/openzeppelin-contracts 21 https://github.com/OpenNMS/opennms 20 https://github.com/jeecgboot/jeecg-boot 20 https://github.com/simplesamlphp/simplesamlphp 20 https://github.com/ethyca/fides 20 https://github.com/opencast/opencast 20 https://github.com/funadmin/funadmin 20 https://github.com/cloudfoundry/uaa 19 https://github.com/TYPO3-CMS/core 19 https://github.com/alkacon/opencms-core 19 https://github.com/backstage/backstage 19 https://github.com/huggingface/transformers 19 https://github.com/nilsteampassnet/teampass 19 https://github.com/intelliants/subrion 19 https://github.com/apache/camel 18 https://github.com/OpenMage/magento-lts 18 https://github.com/vaadin/platform 18 https://github.com/rubygems/rubygems 18 https://github.com/apache/kylin 17 https://github.com/ethereum/go-ethereum 17 https://github.com/openfga/openfga 17 https://github.com/liufee/cms 17 https://github.com/containerd/containerd 17 https://github.com/vantage6/vantage6 17 https://github.com/mindsdb/mindsdb 17 https://github.com/sequelize/sequelize 16 https://github.com/etcd-io/etcd 16 https://github.com/rusqlite/rusqlite 16 https://github.com/forkcms/forkcms 16 https://github.com/vitejs/vite 16 https://github.com/pyca/cryptography 16 https://github.com/tinymce/tinymce 16 https://github.com/quarkusio/quarkus 16 https://github.com/dotnet/aspnetcore 16 https://github.com/hashicorp/nomad 16 https://github.com/yetiforcecompany/yetiforcecrm 16 https://github.com/thorsten/phpMyFAQ 15 https://github.com/cobbler/cobbler 15 https://github.com/xuxueli/xxl-job 15 https://github.com/aio-libs/aiohttp 15 https://github.com/MobSF/Mobile-Security-Framework-MobSF 15 https://github.com/PHPMailer/PHPMailer 15 https://github.com/centreon/centreon 15 https://github.com/drupal/core 15 https://github.com/zendframework/zendframework 15 https://github.com/puppetlabs/puppet 15 https://github.com/dompdf/dompdf 15 https://github.com/decidim/decidim 15 https://github.com/containers/podman 15 https://github.com/spring-projects/spring-security 15 https://github.com/OPCFoundation/UA-.NETStandard 15 https://github.com/ckeditor/ckeditor4 15 https://github.com/nodejs/undici 15 https://github.com/pgadmin-org/pgadmin4 14 https://github.com/janeczku/calibre-web 14 https://github.com/golang/go 14 https://github.com/apache/zeppelin 14 https://github.com/ming-soft/MCMS 14 https://github.com/twisted/twisted 14 https://github.com/urllib3/urllib3 14 https://github.com/apache/superset 14 https://github.com/publify/publify 14 https://github.com/dpgaspar/Flask-AppBuilder 14 https://github.com/rails/rails-html-sanitizer 14 https://github.com/cockpit-hq/cockpit 14 https://github.com/pimcore/admin-ui-classic-bundle 14 https://github.com/cosmos/cosmos-sdk 14 https://github.com/TryGhost/Ghost 14 https://github.com/ImageMagick/ImageMagick 14 https://github.com/Graylog2/graylog2-server 14 https://github.com/modoboa/modoboa 13 https://github.com/apache/dolphinscheduler 13 https://github.com/openbao/openbao 13 https://github.com/dromara/hutool 13 https://github.com/zenml-io/zenml 13 https://github.com/1Panel-dev/1Panel 13 https://github.com/OpenRefine/OpenRefine 13 https://github.com/swagger-api/swagger-ui 13 https://github.com/h2oai/h2o-3 13 https://github.com/opencontainers/runc 13 https://github.com/laurent22/joplin 13 https://github.com/wagtail/wagtail 12 https://github.com/openstack/glance 12 https://github.com/smarty-php/smarty 12 https://github.com/nautobot/nautobot 12 https://github.com/YesWiki/yeswiki 12 https://github.com/OctoPrint/OctoPrint 12 https://github.com/igniterealtime/Openfire 12 https://github.com/yiisoft/yii2 12 https://github.com/n8n-io/n8n 12