112526 | Missing 'X-XSS-Protection' Header (deprecated) | Web App Scanning | HTTP Security Header | 1/17/2025 | info |
98071 | Common Files Detection | Web App Scanning | Web Servers | 1/9/2025 | info |
98115 | SQL Injection | Web App Scanning | Injection | 1/7/2025 | high |
114549 | Apache Struts < 6.4.0 Unrestricted File Upload (S2-067) | Web App Scanning | Component Vulnerability | 1/7/2025 | critical |
113059 | OPcache UI Detected | Web App Scanning | Web Applications | 1/7/2025 | medium |
98110 | DOM-based Cross-Site Scripting (XSS) in attribute context | Web App Scanning | Cross Site Scripting | 12/23/2024 | medium |
98107 | Cross-Site Scripting (XSS) in path | Web App Scanning | Cross Site Scripting | 12/23/2024 | medium |
112763 | Apache Struts 2.1.6 < 2.3.34 / 2.5 < 2.5.13 Remote Code Execution (S2-052) | Web App Scanning | Component Vulnerability | 12/19/2024 | high |
112762 | Apache Struts 2 < 2.3.33 Remote Code Execution (S2-048) | Web App Scanning | Component Vulnerability | 12/19/2024 | critical |
112760 | Apache Struts 2 Demo Application Detected | Web App Scanning | Component Vulnerability | 12/19/2024 | low |
112742 | Apache Struts 2 < 2.3.29 DevMode Remote Code Execution | Web App Scanning | Component Vulnerability | 12/19/2024 | critical |
112741 | Apache Struts 2.x < 2.3.15.1 Remote Code Execution (S2-016) | Web App Scanning | Component Vulnerability | 12/19/2024 | critical |
112727 | Apache Struts 2.0.4 < 2.3.35 / 2.5.x < 2.5.17 Remote Code Execution (S2-057) | Web App Scanning | Component Vulnerability | 12/19/2024 | high |
112726 | Apache Struts 2.3.5 < 2.3.32 / 2.5.x < 2.5.10.1 Remote Code Execution (S2-045 / S2-046) | Web App Scanning | Component Vulnerability | 12/19/2024 | critical |
112719 | Client-Side Prototype Pollution | Web App Scanning | Web Applications | 12/19/2024 | high |
112290 | Apache Tomcat 9.0.0.M1 < 9.0.10 Multiple Vulnerabilities | Web App Scanning | Component Vulnerability | 12/19/2024 | critical |
114469 | CyberPanel < 2.3.8 Remote Command Execution | Web App Scanning | Component Vulnerability | 12/10/2024 | critical |
98623 | Host Header Injection | Web App Scanning | Injection | 12/3/2024 | medium |
98077 | Private IP Address Disclosure | Web App Scanning | Data Exposure | 12/3/2024 | info |
114223 | HTTP Request Smuggling | Web App Scanning | Web Applications | 12/3/2024 | high |
98068 | Insecure Cross-Domain Policy (allow-http-request-headers-from) | Web App Scanning | Web Applications | 11/26/2024 | low |
98067 | Insecure Cross-Domain Policy (allow-access-from) | Web App Scanning | Web Applications | 11/26/2024 | low |
114503 | Virtual Hosts Detected | Web App Scanning | Web Applications | 11/26/2024 | info |
114497 | Symfony < 5.4.46 / 6.x < 6.4.14 / 7.x < 7.1.7 Improper Input Handling | Web App Scanning | Component Vulnerability | 11/20/2024 | high |
114143 | Node-config Configuration File Detected | Web App Scanning | Data Exposure | 11/20/2024 | medium |
113219 | Insecure Redirect Chain | Web App Scanning | SSL/TLS | 11/14/2024 | medium |
112920 | GraphQL Cross-Site Request Forgery | Web App Scanning | Cross Site Request Forgery | 11/14/2024 | medium |
112353 | ASP.NET DEBUG Method Enabled | Web App Scanning | Component Vulnerability | 11/14/2024 | medium |
114466 | Path Relative Stylesheet Import | Web App Scanning | Injection | 11/8/2024 | info |
113897 | HTML Comments Detected | Web App Scanning | Data Exposure | 11/8/2024 | info |
114468 | SonarQube Public Projects Detected | Web App Scanning | Data Exposure | 11/5/2024 | info |
114040 | WooCommerce Payments Plugin for WordPress 4.8.x < 4.8.2 Authentication Bypass | Web App Scanning | Component Vulnerability | 10/21/2024 | critical |
114039 | WooCommerce Payments Plugin for WordPress 4.9.x < 4.9.1 Authentication Bypass | Web App Scanning | Component Vulnerability | 10/21/2024 | critical |
114038 | WooCommerce Payments Plugin for WordPress 5.0.x < 5.0.4 Authentication Bypass | Web App Scanning | Component Vulnerability | 10/21/2024 | critical |
114037 | WooCommerce Payments Plugin for WordPress 5.1.x < 5.1.3 Authentication Bypass | Web App Scanning | Component Vulnerability | 10/21/2024 | critical |
114036 | WooCommerce Payments Plugin for WordPress 5.2.x < 5.2.2 Authentication Bypass | Web App Scanning | Component Vulnerability | 10/21/2024 | critical |
114035 | WooCommerce Payments Plugin for WordPress 5.3.x < 5.3.1 Authentication Bypass | Web App Scanning | Component Vulnerability | 10/21/2024 | critical |
114034 | WooCommerce Payments Plugin for WordPress 5.4.x < 5.4.1 Authentication Bypass | Web App Scanning | Component Vulnerability | 10/21/2024 | critical |
114033 | WooCommerce Payments Plugin for WordPress 5.5.x < 5.5.2 Authentication Bypass | Web App Scanning | Component Vulnerability | 10/21/2024 | critical |
114032 | WooCommerce Payments Plugin for WordPress 6.2.x < 6.2.2 Authentication Bypass | Web App Scanning | Component Vulnerability | 10/21/2024 | critical |
114031 | WooCommerce Payments Plugin for WordPress 6.3.x < 6.3.2 Authentication Bypass | Web App Scanning | Component Vulnerability | 10/21/2024 | critical |
113838 | WooCommerce Payments Plugin for WordPress 5.6.x < 5.6.2 Authentication Bypass | Web App Scanning | Component Vulnerability | 10/21/2024 | critical |
113217 | Spring Framework < 5.2.20 / 5.3.x < 5.3.18 Remote Code Execution (Spring4Shell) | Web App Scanning | Component Vulnerability | 10/21/2024 | critical |
114247 | Authentication Check Pattern Found in Unauthenticated Browser | Web App Scanning | Authentication & Session | 10/15/2024 | info |
114439 | Express.js Cookie-Session Weak Secret Key | Web App Scanning | Web Applications | 10/3/2024 | high |
113393 | Performance Telemetry | Web App Scanning | General | 10/3/2024 | info |
112550 | Full Path Disclosure | Web App Scanning | Data Exposure | 10/3/2024 | info |
114283 | Unrestricted File Upload | Web App Scanning | Web Applications | 9/26/2024 | high |
114433 | Ivanti EPM RecordGoodApp SQL Injection | Web App Scanning | Component Vulnerability | 9/24/2024 | high |
112686 | JSON Web Token Detected | Web App Scanning | Web Applications | 9/24/2024 | info |