Plugins
Settings
Links
Tenable Cloud
Tenable Community & Support
Tenable University
Severity
VPR
CVSS v2
CVSS v3
CVSS v4
Theme
Light
Dark
Auto
Help
Plugins
Overview
Plugins Pipeline
Newest
Updated
Search
Nessus Families
WAS Families
NNM Families
LCE Families
Tenable OT Security Families
About Plugin Families
Release Notes
Audits
Overview
Newest
Updated
Search Audit Files
Search Items
References
Authorities
Documentation
Download All Audit Files
Indicators
Overview
Search
Indicators of Attack
Indicators of Exposure
CVEs
Overview
Newest
Updated
Search
Attack Path Techniques
Overview
Search
Links
Tenable Cloud
Tenable Community & Support
Tenable University
Settings
Severity
VPR
CVSS v2
CVSS v3
CVSS v4
Theme
Light
Dark
Auto
Detections
Plugins
Overview
Plugins Pipeline
Release Notes
Newest
Updated
Search
Nessus Families
WAS Families
NNM Families
LCE Families
Tenable OT Security Families
About Plugin Families
Audits
Overview
Newest
Updated
Search Audit Files
Search Items
References
Authorities
Documentation
Download All Audit Files
Indicators
Overview
Search
Indicators of Attack
Indicators of Exposure
Analytics
CVEs
Overview
Newest
Updated
Search
Attack Path Techniques
Overview
Search
Plugins
Web App Scanning Release Notes
202310170831
Web App Scanning Release Notes
was Plugin Feed 202310170831
Oct 17, 2023, 8:31 AM
Modified Detection
112290
Apache Tomcat 9.0.0.M1 < 9.0.10 Multiple Vulnerabilities
112295
Apache Tomcat 9.0.0.M1 < 9.0.0.M22 Multiple Vulnerabilities
112353
ASP.NET DEBUG Method Enabled
112354
lighttpd < 1.4.28 Insecure Temporary File Creation
112358
lighttpd < 1.4.35 Multiple Vulnerabilities
112476
Prototype < 1.6.0.2 Cross-Site Ajax Request
112501
Sitefinity < 10.0.6412.0 Multiple Vulnerabilities
112520
Magento Unsupported Version
112529
Missing 'X-Content-Type-Options' Header
112543
HTTPS Not Detected
112544
HTTP to HTTPS Redirect Not Enabled
112551
Missing Content Security Policy
112552
Deprecated Content Security Policy
112553
Missing 'Cache-Control' Header
112554
Permissive Content Security Policy Detected
112582
Microsoft SharePoint Server 2016 < 16.0.5056.1001 Multiple Vulnerabilities
112583
Microsoft SharePoint Server 2019 < 16.0.10366.12106 Multiple Vulnerabilities
112584
Microsoft SharePoint Server 2013 < 15.0.5275.1001 Multiple Vulnerabilities
112585
Microsoft SharePoint Server 2010 < 14.0.7260.5000 Multiple Vulnerabilities
112586
Microsoft SharePoint Server 2016 < 16.0.5044.1000 Multiple Vulnerabilities
112587
Microsoft SharePoint Server 2013 < 15.0.5267.1000 Multiple Vulnerabilities
112588
Microsoft SharePoint Server 2019 < 16.0.10364.20001 Multiple Vulnerabilities
112589
Microsoft SharePoint Server 2010 < 14.0.7256.5000 Multiple Vulnerabilities
112673
Resin < 4.0.40 Incorrect Unicode Transformations
112697
JSON Web Token Weak Secret
112703
JSON Web Token None Hashing Algorithm
112705
Oracle WebLogic 10.3.6.0.0 / 12.1.3.0.0 / 12.2.1.4.0 / 14.1.1.0.0 Authentication Bypass
112730
Microsoft SharePoint Server 2016 < 16.0.5095.1000 Multiple Vulnerabilities
112731
Microsoft SharePoint Server 2019 < 16.0.10369.20000 Multiple Vulnerabilities
112732
Microsoft SharePoint Server 2010 < 14.0.7263.5000 Multiple Vulnerabilities
112733
Microsoft SharePoint Server 2010 < 14.0.7262.5000 Multiple Vulnerabilities
112734
Microsoft SharePoint Server 2019 < 16.0.10368.20022 Multiple Vulnerabilities
112735
Microsoft SharePoint Server 2013 < 15.0.5293.1000 Multiple Vulnerabilities
112736
Microsoft SharePoint Server 2016 < 16.0.5083.1000 Multiple Vulnerabilities
112737
Microsoft SharePoint Server 2010 < 14.0.7261.5000 Multiple Vulnerabilities
112738
Microsoft SharePoint Server 2019 < 16.0.10367.20000 Multiple Vulnerabilities
112739
Microsoft SharePoint Server 2016 < 16.0.5071.1000 Multiple Vulnerabilities
112740
Microsoft SharePoint Server 2013 < 15.0.5285.1000 Multiple Vulnerabilities
112804
phpBB User Enumeration
112920
GraphQL Cross-Site Request Forgery
112926
Microsoft SharePoint Server 2019 < 16.0.10376.20001 Multiple Vulnerabilities
112927
Microsoft SharePoint Server 2016 < 16.0.5188.1000 Multiple Vulnerabilities
112928
Microsoft SharePoint Server 2013 < 15.0.5363.1000 Multiple Vulnerabilities
112940
Microsoft SharePoint Server 2019 < 16.0.10370.20001 Multiple Vulnerabilities
112941
Microsoft SharePoint Server 2016 < 16.0.5110.1000 Multiple Vulnerabilities
112942
Microsoft SharePoint Server 2010 < 14.0.7264.5000 Multiple Vulnerabilities
112943
Microsoft SharePoint Server 2013 < 15.0.5311.1000 Multiple Vulnerabilities
113029
Microsoft IIS Unsupported Version
113059
OPcache UI Detected
113075
Apache Log4j Remote Code Execution (Log4Shell)
113078
AngularJS Unsupported Version
113088
Microsoft SharePoint Server 2019 < 16.0.10377.20001 Multiple Vulnerabilities
113089
Microsoft SharePoint Server 2013 < 15.0.5371.1000 Multiple Vulnerabilities
113090
Microsoft SharePoint Server 2016 < 16.0.5200.1000 Multiple Vulnerabilities
113117
Magento Administration Panel Login Form Bruteforced
113136
Wordpress Administration Panel Login Form Bruteforced
113158
Package Dependencies Detected
113165
Apache mod_negotiation Alternative Filename Disclosure
113168
Docker Compose Configuration Detected
113211
HTTP Verb Tampering
113217
Spring Framework < 5.2.20 / 5.3.x < 5.3.18 Remote Code Execution (Spring4Shell)
113242
Java Psychic Signatures
113338
Web Cache Poisoning
113420
Nginx < 1.22.1 Multiple Vulnerabilities
113421
Nginx 1.23.x < 1.23.2 Multiple Vulnerabilities
113458
Yoast SEO Plugin for WordPress < 1.5.7 Multiple Vulnerabilities
113459
Yoast SEO Plugin for WordPress 1.6.x < 1.6.4 Multiple Vulnerabilities
113460
Yoast SEO Plugin for WordPress 1.7.x < 1.7.4 Multiple Vulnerabilities
113467
WP DBManager Plugin for WordPress < 2.7.2 Multiple Vulnerabilities
113472
WP EasyCart Plugin for WordPress < 3.0.9 Unrestricted File Upload
113473
WP Photo Album Plus Plugin for WordPress < 6.1.3 Multiple Cross-Site Scripting
113474
WP-Print Plugin for WordPress < 2.52 Cross-Site Request Forgery
113475
WP eCommerce Plugin for WordPress < 3.8.7.6 SQL Injection
113476
WP-PostViews Plugin for WordPress < 1.63 Cross-Site Request Forgery
113478
All In One WP Security & Firewall Plugin for WordPress < 3.8.8 SQL Injection
113479
All In One WP Security & Firewall Plugin for WordPress < 3.8.3 Multiple SQL Injection
113488
Advanced Dewplayer Plugin for WordPress < 1.3 Path Traversal
113489
WordPress Classifieds Plugin Plugin for WordPress < 3.0 SQL Injection
113490
WordPress Mobile Pack Plugin for WordPress < 2.0.2 Sensitive Information Disclosure
113491
WP Easy Post Types Plugin for WordPress < 1.4.4 Cross-Site Scripting
113492
Apptha WordPress Video Gallery Plugin for WordPress < 2.8.0 SQL Injection
113493
Cross-RSS Plugin for WordPress Arbitrary Files Read
113494
WP Ultimate Email Marketer Plugin for WordPress Multiple Vulnerabilities
113495
WP Cron Dashboard Plugin for WordPress < 1.1.6 Cross-Site Scripting
113496
WP RESTful Plugin for WordPress Multiple Cross-Site Scripting
113497
Social Invitations Plugin for WordPress < 1.4.4.3 Cross-Site Scripting
113498
WP e-Commerce Shop Styling Plugin for WordPress < 1.8 Code Injection
113499
WP Symposium Plugin for WordPress < 15.8 SQL Injection
113503
WordPress < 2.1 Cross-Site Request Forgery
113504
Slimstat Analytics Plugin for WordPress < 3.9.2 Cross-site Scripting
113520
Kibana 7.14.0 HTML Injection
113521
Kibana 7.10.2 < 7.14.1 Code Execution
113522
Kibana 7.9.0 < 7.14.1 Path Traversal
113545
Apache 2.4.x < 2.4.55 Multiple Vulnerabilities
113550
Zoho ManageEngine SAML SSO Remote Code Execution
113580
Web Cache Deception
113584
Joomla! 4.0.0 < 4.2.8 Broken Access Control
113715
Atlassian Jira < 3.13.1 Cross-Site Scripting
113816
Atlassian Jira < 6.0.4 Directory Traversal In Issue Collector
113817
Atlassian Jira < 6.0.5 Multiple Vulnerabilities
113818
Atlassian Jira < 3.7.1 Giffy Plugin Arbitrary File Read
113819
Atlassian Jira < 6.4.3.1 / 6.5.x < 6.5.0.2 / 7.x < 7.0.3 Software Tempo Plugin Xml Denial Of Service
113820
Atlassian Jira 6.5.x < 6.5.0.2 Software Tempo Plugin Xml Denial Of Service
113821
Atlassian Jira 7.x < 7.0.3 Software Tempo Plugin Xml Denial Of Service
113823
Atlassian Jira < 3.12.1 Xss In 500 Page
113838
WooCommerce Payments Plugin for WordPress 5.6.x < 5.6.2 Authentication Bypass
113853
Customer Reviews for WooCommerce Plugin for WordPress < 5.17.0 Cross-Site Scripting
113855
GiveWP Plugin for WordPress < 2.24.1 SQL Injection
113871
DotNetNuke User Enumeration
113900
Cross-Site Request Forgery Token Validation Bypass
113904
Sitecore Unauthenticated User Enumeration
113938
CA SiteMinder WebAgent Cross-Site Scripting
113959
GeoServer SQL Injection
113987
PHP 8.1.x < 8.1.22 Multiple Vulnerabilities
113988
PHP 8.0.x < 8.0.30 Multiple Vulnerabilities
114006
Web Cache Poisoning Denial of Service
114007
PHP 8.2.x < 8.2.9 Multiple Vulnerabilities
114012
Prometheus Sensitive Endpoint Detected
114026
WP EasyCart Plugin for WordPress < 2.0.6 Sensitive Information Disclosure
114027
WP Fastest Cache Plugin for WordPress < 1.1.3 Multiple Vulnerabilities
114031
WooCommerce Payments Plugin for WordPress 6.3.x < 6.3.2 Authentication Bypass
114032
WooCommerce Payments Plugin for WordPress 6.2.x < 6.2.2 Authentication Bypass
114033
WooCommerce Payments Plugin for WordPress 5.5.x < 5.5.2 Authentication Bypass
114034
WooCommerce Payments Plugin for WordPress 5.4.x < 5.4.1 Authentication Bypass
114035
WooCommerce Payments Plugin for WordPress 5.3.x < 5.3.1 Authentication Bypass
114036
WooCommerce Payments Plugin for WordPress 5.2.x < 5.2.2 Authentication Bypass
114037
WooCommerce Payments Plugin for WordPress 5.1.x < 5.1.3 Authentication Bypass
114038
WooCommerce Payments Plugin for WordPress 5.0.x < 5.0.4 Authentication Bypass
114039
WooCommerce Payments Plugin for WordPress 4.9.x < 4.9.1 Authentication Bypass
114040
WooCommerce Payments Plugin for WordPress 4.8.x < 4.8.2 Authentication Bypass
114041
Strapi Cognito Provider Authentication Bypass
114042
Adobe ColdFusion Remote Code Execution
114043
Adobe ColdFusion Improper Access Control
114047
Drupal 10.1.x < 10.1.4 Cache Poisoning
114048
Drupal 10.0.x < 10.0.11 Cache Poisoning
114049
Drupal 8.7.x < 9.5.11 Cache Poisoning
114055
Simple Membership Plugin For WordPress < 4.3.6 Reflected Cross-Site Scripting
114056
Atlassian Confluence 8.x < 8.3.3 Privilege Escalation
114057
Atlassian Confluence 8.4.x < 8.4.3 Privilege Escalation
114058
Atlassian Confluence 8.5.x < 8.5.2 Privilege Escalation
114060
Apache Tomcat 11.0.0-M1 < 11.0.0-M12 Multiple Vulnerabilities
114061
Apache Tomcat 10.1.0-M1 < 10.1.14 Multiple Vulnerabilities
114062
Apache Tomcat 9.0.70 < 9.0.81 Multiple Vulnerabilities
114063
Apache Tomcat 8.5.85 < 8.5.94 Multiple Vulnerabilities
114065
Pimcore Administration Panel Login Form Detected
115540
Cookie Without SameSite Flag Detected
98056
Missing HTTP Strict Transport Security Policy
98057
Insecure 'Access-Control-Allow-Origin' Header
98060
Missing 'X-Frame-Options' Header
98067
Insecure Cross-Domain Policy (allow-access-from)
98068
Insecure Cross-Domain Policy (allow-http-request-headers-from)
98084
Directory Listing
98095
Misconfiguration in LIMIT directive of .htaccess file
98097
Backdoor Detection
98098
Source Code Disclosure
98107
Cross-Site Scripting (XSS) in path
98112
Cross-Site Request Forgery
98129
Credit Card Number Disclosure
98146
Password Submitted Using GET Method
98200
Drupal Administration Panel Login Form Detected
98203
WordPress User Enumeration
98208
Joomla! User Enumeration
98209
Drupal User Enumeration
98212
WordPress Directory Listing
98213
Drupal Directory Listing
98214
Joomla! Directory Listing
98227
WordPress Unsupported Version
98228
Drupal Unsupported Version
98229
Joomla! Unsupported Version
98230
PHP Unsupported Version
98231
Apache Unsupported Version
98232
Apache Tomcat Unsupported Version
98237
MediaElement.js < 2.11.2 Cross-Site Scripting
98398
JK Status Manager Information Disclosure
98538
Environment Configuration File Detected
98607
Ultimate Member Plugin for WordPress < 2.0.46 Multiple Vulnerabilities
98618
HTTP Header Information Disclosure
98642
Magento Administration Panel Login Form Detected
98648
Missing 'Content-Type' Header
98671
CVS Entries Detected
98679
Webmin < 1.730 Read Mail Symlink Vulnerability
98703
Magento API Anonymous Access
98715
Permissive HTTP Strict Transport Security Policy Detected
98779
Source Code Passive Disclosure
98780
Java Object Deserialization
98806
PHP 5.6.x < 5.6.14 Multiple Vulnerabilities
98828
PHP 5.6.x < 5.6.5 Multiple Vulnerabilities
98831
PHP 5.6.x < 5.6.8 Multiple Vulnerabilities
98901
Apache 2.4.x < 2.4.3 Multiple Vulnerabilities
98936
Joomla! 2.5.x < 3.9.14 Multiple Vulnerabilities
98950
Nginx < 1.4.1 ngx_http_proxy_module.c Multiple Vulnerabilities
98951
Nginx < 1.2.9 ngx_http_proxy_module.c Multiple Vulnerabilities
98952
Nginx < 1.5.7 ngx_parse_http Security Bypass
98953
Nginx < 1.4.4 ngx_parse_http Security Bypass
98957
Nginx < 1.7.4 SMTP STARTTLS Command Injection
98958
Nginx < 1.6.1 SMTP STARTTLS Command Injection
98959
Nginx < 1.7.5 SSL Session Reuse
98960
Nginx < 1.6.2 SSL Session Reuse
98986
Magento Directory Listing
98995
Kentico CMS 8.2.x < 8.2.41 Open Redirect
98996
Kentico CMS < 9.0.51 Cross-Site Scripting
New
114059
Pimcore Admin Login Cross-Site Scripting
114064
MediaWiki Status Module Information Disclosure