296,746
Total vulnerabilities in the database
The default exclude patterns (excludeParams) in Apache Struts 2.3.20 allow remote attackers to "compromise internal state of an application" via unspecified vectors.
| Software | From | Fixed in | 
|---|---|---|
| apache / struts | 2.3.20 | 2.3.20.x | 
|  org.apache.struts / struts2-core | - | 2.3.20.1 |