GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,285
Erlang
31
GitHub Actions
21
Go
2,057
Maven
5,000+
npm
3,742
NuGet
668
pip
3,422
Pub
12
RubyGems
892
Rust
875
Swift
36
Unreviewed advisories
All unreviewed
5,000+
349 advisories
Filter by severity
Apache Tomcat Directory Traversal
Moderate
CVE-2007-0450
was published
for
org.apache.tomcat:tomcat
(Maven)
May 1, 2022
Apache Struts REST Plugin can potentially allow a DoS attack
High
CVE-2018-1327
was published
for
org.apache.struts:struts2-rest-plugin
(Maven)
Oct 16, 2018
Apache Struts allows entering a custom URL in a form field if built-in URLValidator is used
High
CVE-2017-9804
was published
for
org.apache.struts:struts2-core
(Maven)
Oct 16, 2018
Spring AOP functionality (Struts) vulnerable to DoS attack
High
CVE-2017-9787
was published
for
org.apache.struts:struts2-core
(Maven)
Oct 16, 2018
Apache Struts 2.0.1 uses an unintentional expression in a Freemarker tag instead of string literal
Critical
CVE-2017-12611
was published
for
org.apache.struts:struts2-core
(Maven)
Oct 16, 2018
Apache Struts vulnerable to possible DoS attack when using URLValidator
Moderate
CVE-2016-8738
was published
for
org.apache.struts:struts2-core
(Maven)
May 14, 2022
Path Traversal in Apache Struts
Critical
CVE-2016-6795
was published
for
org.apache.struts:struts2-convention-plugin
(Maven)
May 14, 2022
Apache Struts vulnerable to possible DoS attack when using URLValidator
Moderate
CVE-2016-4465
was published
for
org.apache.struts:struts2-core
(Maven)
May 17, 2022
Apache Struts improper action name cleanup
Critical
CVE-2016-4436
was published
for
org.apache.struts:struts2-core
(Maven)
May 17, 2022
Apache Struts Open Redirect
High
CVE-2016-4433
was published
for
org.apache.struts.xwork:xwork-core
(Maven)
May 17, 2022
Apache Struts vulnerable to arbitrary remote code execution due to improper input validation
Critical
CVE-2016-3087
was published
for
org.apache.struts:struts2-core
(Maven)
May 14, 2022
Arbitrary code execution in Apache Struts 2
Critical
CVE-2016-4438
was published
for
org.apache.struts:struts2-core
(Maven)
May 14, 2022
Apache Struts CSRF Vulnerability
High
CVE-2016-4430
was published
for
org.apache.struts.xwork:xwork-core
(Maven)
May 17, 2022
Cross-site Scripting in Apache Struts
Moderate
CVE-2016-4003
was published
for
org.apache.struts:struts2-core
(Maven)
May 14, 2022
Apache Struts XSS Vulnerability
Moderate
CVE-2016-2162
was published
for
org.apache.struts:struts2-core
(Maven)
May 17, 2022
Apache Struts RCE Vulnerability
High
CVE-2016-0785
was published
for
org.apache.struts:struts2-core
(Maven)
May 14, 2022
Incomplete exclude pattern in Apache Struts
High
CVE-2015-1831
was published
for
org.apache.struts.xwork:xwork-core
(Maven)
May 17, 2022
Cross-Site Request Forgery in Apache Struts
Moderate
CVE-2014-7809
was published
for
org.apache.struts:struts2-core
(Maven)
May 14, 2022
ClassLoader manipulation in Apache Struts
High
CVE-2014-0116
was published
for
org.apache.struts:struts2-core
(Maven)
May 14, 2022
ClassLoader manipulation in Apache Struts
Moderate
CVE-2014-0094
was published
for
org.apache.struts.xwork:xwork-core
(Maven)
May 14, 2022
Code injection in Apache Struts
High
CVE-2013-4316
was published
for
org.apache.struts:struts2-core
(Maven)
May 17, 2022
Apache Struts2 Broken Access Control Vulnerability
Moderate
CVE-2013-4310
was published
for
org.apache.struts:struts2-core
(Maven)
May 17, 2022
Code injection in Apache Struts
High
CVE-2013-2251
was published
for
org.apache.struts:struts2-core
(Maven)
May 13, 2022
Open redirect in Apache Struts
Moderate
CVE-2013-2248
was published
for
org.apache.struts:struts2-core
(Maven)
May 17, 2022
Arbitrary code execution in Apache Struts 2
High
CVE-2013-2135
was published
for
org.apache.struts.xwork:xwork-core
(Maven)
May 14, 2022
ProTip!
Advisories are also available from the
GraphQL API