was Plugin Feed 202312180856

Dec 18, 2023, 8:56 AM
Modified Detection
  • 112290Apache Tomcat 9.0.0.M1 < 9.0.10 Multiple Vulnerabilities
  • 112295Apache Tomcat 9.0.0.M1 < 9.0.0.M22 Multiple Vulnerabilities
  • 112353ASP.NET DEBUG Method Enabled
  • 112354lighttpd < 1.4.28 Insecure Temporary File Creation
  • 112358lighttpd < 1.4.35 Multiple Vulnerabilities
  • 112501Sitefinity < 10.0.6412.0 Multiple Vulnerabilities
  • 112520Magento Unsupported Version
  • 112526Missing 'X-XSS-Protection' Header
  • 112527Disabled 'X-XSS-Protection' Header
  • 112529Missing 'X-Content-Type-Options' Header
  • 112535HTTP Strict Transport Security Policy Detected
  • 112543HTTPS Not Detected
  • 112544HTTP to HTTPS Redirect Not Enabled
  • 112550Full Path Disclosure
  • 112551Missing Content Security Policy
  • 112552Deprecated Content Security Policy
  • 112553Missing 'Cache-Control' Header
  • 112554Permissive Content Security Policy Detected
  • 112555Report Only Content Security Policy Detected
  • 112569OpenAPI Import Success
  • 112570OpenAPI Import Failed
  • 112582Microsoft SharePoint Server 2016 < 16.0.5056.1001 Multiple Vulnerabilities
  • 112583Microsoft SharePoint Server 2019 < 16.0.10366.12106 Multiple Vulnerabilities
  • 112584Microsoft SharePoint Server 2013 < 15.0.5275.1001 Multiple Vulnerabilities
  • 112585Microsoft SharePoint Server 2010 < 14.0.7260.5000 Multiple Vulnerabilities
  • 112586Microsoft SharePoint Server 2016 < 16.0.5044.1000 Multiple Vulnerabilities
  • 112587Microsoft SharePoint Server 2013 < 15.0.5267.1000 Multiple Vulnerabilities
  • 112588Microsoft SharePoint Server 2019 < 16.0.10364.20001 Multiple Vulnerabilities
  • 112589Microsoft SharePoint Server 2010 < 14.0.7256.5000 Multiple Vulnerabilities
  • 112614Server-Side Template Injection
  • 112615OpenAPI File Detected
  • 112673Resin < 4.0.40 Incorrect Unicode Transformations
  • 112686JSON Web Token Detected
  • 112697JSON Web Token Weak Secret
  • 112703JSON Web Token None Hashing Algorithm
  • 112705Oracle WebLogic 10.3.6.0.0 / 12.1.3.0.0 / 12.2.1.4.0 / 14.1.1.0.0 Authentication Bypass
  • 112730Microsoft SharePoint Server 2016 < 16.0.5095.1000 Multiple Vulnerabilities
  • 112731Microsoft SharePoint Server 2019 < 16.0.10369.20000 Multiple Vulnerabilities
  • 112732Microsoft SharePoint Server 2010 < 14.0.7263.5000 Multiple Vulnerabilities
  • 112733Microsoft SharePoint Server 2010 < 14.0.7262.5000 Multiple Vulnerabilities
  • 112734Microsoft SharePoint Server 2019 < 16.0.10368.20022 Multiple Vulnerabilities
  • 112735Microsoft SharePoint Server 2013 < 15.0.5293.1000 Multiple Vulnerabilities
  • 112736Microsoft SharePoint Server 2016 < 16.0.5083.1000 Multiple Vulnerabilities
  • 112737Microsoft SharePoint Server 2010 < 14.0.7261.5000 Multiple Vulnerabilities
  • 112738Microsoft SharePoint Server 2019 < 16.0.10367.20000 Multiple Vulnerabilities
  • 112739Microsoft SharePoint Server 2016 < 16.0.5071.1000 Multiple Vulnerabilities
  • 112740Microsoft SharePoint Server 2013 < 15.0.5285.1000 Multiple Vulnerabilities
  • 112907GraphQL Interface Detected
  • 112920GraphQL Cross-Site Request Forgery
  • 112926Microsoft SharePoint Server 2019 < 16.0.10376.20001 Multiple Vulnerabilities
  • 112927Microsoft SharePoint Server 2016 < 16.0.5188.1000 Multiple Vulnerabilities
  • 112928Microsoft SharePoint Server 2013 < 15.0.5363.1000 Multiple Vulnerabilities
  • 112940Microsoft SharePoint Server 2019 < 16.0.10370.20001 Multiple Vulnerabilities
  • 112941Microsoft SharePoint Server 2016 < 16.0.5110.1000 Multiple Vulnerabilities
  • 112942Microsoft SharePoint Server 2010 < 14.0.7264.5000 Multiple Vulnerabilities
  • 112943Microsoft SharePoint Server 2013 < 15.0.5311.1000 Multiple Vulnerabilities
  • 113010API Key Authentication Succeeded
  • 113011API Key Authentication Failed
  • 113012Bearer Token Authentication Succeeded
  • 113013Bearer Token Authentication Failed
  • 113027Out-of-Date JQuery Detected
  • 113028Out-of-Date Lodash Detected
  • 113029Microsoft IIS Unsupported Version
  • 113030Out-of-Date Bootstrap Detected
  • 113031Out-of-Date JQuery UI Detected
  • 113032Out-of-Date Modernizr Detected
  • 113033Out-of-Date Underscore.js Detected
  • 113034Out-of-Date MediaElement.Js Detected
  • 113035Out-of-Date Moment JS Framework Detected
  • 113036Out-of-Date Knockout JS Detected
  • 113037Out-of-Date Backbone JS Framework Detected
  • 113075Apache Log4j Remote Code Execution (Log4Shell)
  • 113078AngularJS Unsupported Version
  • 113088Microsoft SharePoint Server 2019 < 16.0.10377.20001 Multiple Vulnerabilities
  • 113089Microsoft SharePoint Server 2013 < 15.0.5371.1000 Multiple Vulnerabilities
  • 113090Microsoft SharePoint Server 2016 < 16.0.5200.1000 Multiple Vulnerabilities
  • 113117Magento Administration Panel Login Form Bruteforced
  • 113136Wordpress Administration Panel Login Form Bruteforced
  • 113158Package Dependencies Detected
  • 113162MySQLjs SQL Injection Authentication Bypass
  • 113165Apache mod_negotiation Alternative Filename Disclosure
  • 113168Docker Compose Configuration Detected
  • 113211HTTP Verb Tampering
  • 113212Content Injection
  • 113217Spring Framework < 5.2.20 / 5.3.x < 5.3.18 Remote Code Execution (Spring4Shell)
  • 113237PHP Object Deserialization
  • 113242Java Psychic Signatures
  • 113310Blind XPath Injection (differential analysis)
  • 113333Duplicate HTTP Headers Detected
  • 113337NoSQL Injection Authentication Bypass
  • 113338Web Cache Poisoning
  • 113393Performance Telemetry
  • 113420Nginx < 1.22.1 Multiple Vulnerabilities
  • 113421Nginx 1.23.x < 1.23.2 Multiple Vulnerabilities
  • 113452WordPress Plugins Detected
  • 113458Yoast SEO Plugin for WordPress < 1.5.7 Multiple Vulnerabilities
  • 113459Yoast SEO Plugin for WordPress 1.6.x < 1.6.4 Multiple Vulnerabilities
  • 113460Yoast SEO Plugin for WordPress 1.7.x < 1.7.4 Multiple Vulnerabilities
  • 113467WP DBManager Plugin for WordPress < 2.7.2 Multiple Vulnerabilities
  • 113472WP EasyCart Plugin for WordPress < 3.0.9 Unrestricted File Upload
  • 113473WP Photo Album Plus Plugin for WordPress < 6.1.3 Multiple Cross-Site Scripting
  • 113474WP-Print Plugin for WordPress < 2.52 Cross-Site Request Forgery
  • 113475WP eCommerce Plugin for WordPress < 3.8.7.6 SQL Injection
  • 113476WP-PostViews Plugin for WordPress < 1.63 Cross-Site Request Forgery
  • 113478All In One WP Security & Firewall Plugin for WordPress < 3.8.8 SQL Injection
  • 113479All In One WP Security & Firewall Plugin for WordPress < 3.8.3 Multiple SQL Injection
  • 113488Advanced Dewplayer Plugin for WordPress < 1.3 Path Traversal
  • 113489WordPress Classifieds Plugin Plugin for WordPress < 3.0 SQL Injection
  • 113490WordPress Mobile Pack Plugin for WordPress < 2.0.2 Sensitive Information Disclosure
  • 113491WP Easy Post Types Plugin for WordPress < 1.4.4 Cross-Site Scripting
  • 113492Apptha WordPress Video Gallery Plugin for WordPress < 2.8.0 SQL Injection
  • 113493Cross-RSS Plugin for WordPress Arbitrary Files Read
  • 113494WP Ultimate Email Marketer Plugin for WordPress Multiple Vulnerabilities
  • 113495WP Cron Dashboard Plugin for WordPress < 1.1.6 Cross-Site Scripting
  • 113496WP RESTful Plugin for WordPress Multiple Cross-Site Scripting
  • 113497Social Invitations Plugin for WordPress < 1.4.4.3 Cross-Site Scripting
  • 113498WP e-Commerce Shop Styling Plugin for WordPress < 1.8 Code Injection
  • 113499WP Symposium Plugin for WordPress < 15.8 SQL Injection
  • 113503WordPress < 2.1 Cross-Site Request Forgery
  • 113504Slimstat Analytics Plugin for WordPress < 3.9.2 Cross-site Scripting
  • 113545Apache 2.4.x < 2.4.55 Multiple Vulnerabilities
  • 113580Web Cache Deception
  • 113584Joomla! 4.0.0 < 4.2.8 Broken Access Control
  • 113715Atlassian Jira < 3.13.1 Cross-Site Scripting
  • 113816Atlassian Jira < 6.0.4 Directory Traversal In Issue Collector
  • 113817Atlassian Jira < 6.0.5 Multiple Vulnerabilities
  • 113818Atlassian Jira < 3.7.1 Giffy Plugin Arbitrary File Read
  • 113819Atlassian Jira < 6.4.3.1 / 6.5.x < 6.5.0.2 / 7.x < 7.0.3 Software Tempo Plugin Xml Denial Of Service
  • 113820Atlassian Jira 6.5.x < 6.5.0.2 Software Tempo Plugin Xml Denial Of Service
  • 113821Atlassian Jira 7.x < 7.0.3 Software Tempo Plugin Xml Denial Of Service
  • 113823Atlassian Jira < 3.12.1 Xss In 500 Page
  • 113838WooCommerce Payments Plugin for WordPress 5.6.x < 5.6.2 Authentication Bypass
  • 113853Customer Reviews for WooCommerce Plugin for WordPress < 5.17.0 Cross-Site Scripting
  • 113855GiveWP Plugin for WordPress < 2.24.1 SQL Injection
  • 113871DotNetNuke User Enumeration
  • 113897HTML Comments Detected
  • 113900Cross-Site Request Forgery Token Validation Bypass
  • 113904Sitecore Unauthenticated User Enumeration
  • 113938CA SiteMinder WebAgent Cross-Site Scripting
  • 113959GeoServer SQL Injection
  • 113973Web Services Description Language (WSDL) File Detected
  • 114006Web Cache Poisoning Denial of Service
  • 114026WP EasyCart Plugin for WordPress < 2.0.6 Sensitive Information Disclosure
  • 114027WP Fastest Cache Plugin for WordPress < 1.1.3 Multiple Vulnerabilities
  • 114031WooCommerce Payments Plugin for WordPress 6.3.x < 6.3.2 Authentication Bypass
  • 114032WooCommerce Payments Plugin for WordPress 6.2.x < 6.2.2 Authentication Bypass
  • 114033WooCommerce Payments Plugin for WordPress 5.5.x < 5.5.2 Authentication Bypass
  • 114034WooCommerce Payments Plugin for WordPress 5.4.x < 5.4.1 Authentication Bypass
  • 114035WooCommerce Payments Plugin for WordPress 5.3.x < 5.3.1 Authentication Bypass
  • 114036WooCommerce Payments Plugin for WordPress 5.2.x < 5.2.2 Authentication Bypass
  • 114037WooCommerce Payments Plugin for WordPress 5.1.x < 5.1.3 Authentication Bypass
  • 114038WooCommerce Payments Plugin for WordPress 5.0.x < 5.0.4 Authentication Bypass
  • 114039WooCommerce Payments Plugin for WordPress 4.9.x < 4.9.1 Authentication Bypass
  • 114040WooCommerce Payments Plugin for WordPress 4.8.x < 4.8.2 Authentication Bypass
  • 114041Strapi Cognito Provider Authentication Bypass
  • 114042Adobe ColdFusion Remote Code Execution
  • 114043Adobe ColdFusion Improper Access Control
  • 114089Pimcore User Enumeration
  • 114099Microsoft SharePoint Server 2019 build < 16.0.10399.20005 Elevation of Privilege
  • 114108Strapi < 4.8.0 Private Fields Sensitive Information Disclosure
  • 114117OwnCloud graphapi 0.2.x < 0.2.1 / 0.3.x < 0.3.1 Sensitive Informations Disclosure
  • 114122Appwrite Server-Side Request Forgery
  • 114123Atlassian Confluence 4.x < 7.19.17 Template Injection
  • 114124Atlassian Confluence 8.x < 8.4.5 Template Injection
  • 114125Atlassian Confluence 8.5.x < 8.5.4 Template Injection
  • 114126Atlassian Confluence 8.6.x < 8.6.2 Template Injection
  • 114127Atlassian Confluence 8.7.x < 8.7.1 Template Injection
  • 114129Secret Data Disclosure
  • 114134HTML/CSS Injection
  • 114141Backup Migration Plugin for WordPress < 1.3.8 Remote Code Execution
  • 115540Cookie Without SameSite Flag Detected
  • 98008Web Application Firewall Detected
  • 98034Login Form Authentication Failed
  • 98035Login Form Authentication Succeeded
  • 98047Allowed HTTP Methods
  • 98056Missing HTTP Strict Transport Security Policy
  • 98057Insecure 'Access-Control-Allow-Origin' Header
  • 98060Missing 'X-Frame-Options' Header
  • 98062Cookie Set For Parent Domain
  • 98063Cookie Without HttpOnly Flag Detected
  • 98064Cookie Without Secure Flag Detected
  • 98067Insecure Cross-Domain Policy (allow-access-from)
  • 98068Insecure Cross-Domain Policy (allow-http-request-headers-from)
  • 98071Common Files Detection
  • 98072Common Directories Detection
  • 98084Directory Listing
  • 98095Misconfiguration in LIMIT directive of .htaccess file
  • 98097Backdoor Detection
  • 98107Cross-Site Scripting (XSS) in path
  • 98112Cross-Site Request Forgery
  • 98114XPath Injection
  • 98115SQL Injection
  • 98117Blind SQL Injection (differential analysis)
  • 98119Blind NoSQL Injection (differential analysis)
  • 98123Operating System Command Injection
  • 98136Target Information
  • 98139Cookie Authentication Succeeded
  • 98140Cookie Authentication Failed
  • 98141Selenium Authentication Succeeded
  • 98142Selenium Authentication Failed
  • 98143Selenium Crawl Succeeded
  • 98145Selenium Crawl Failed
  • 98146Password Submitted Using GET Method
  • 98200Drupal Administration Panel Login Form Detected
  • 98227WordPress Unsupported Version
  • 98228Drupal Unsupported Version
  • 98229Joomla! Unsupported Version
  • 98230PHP Unsupported Version
  • 98231Apache Unsupported Version
  • 98232Apache Tomcat Unsupported Version
  • 98237MediaElement.js < 2.11.2 Cross-Site Scripting
  • 98398JK Status Manager Information Disclosure
  • 98526Missing Permissions Policy
  • 98527Missing Referrer Policy
  • 98538Environment Configuration File Detected
  • 98607Ultimate Member Plugin for WordPress < 2.0.46 Multiple Vulnerabilities
  • 98618HTTP Header Information Disclosure
  • 98642Magento Administration Panel Login Form Detected
  • 98648Missing 'Content-Type' Header
  • 98679Webmin < 1.730 Read Mail Symlink Vulnerability
  • 98703Magento API Anonymous Access
  • 98715Permissive HTTP Strict Transport Security Policy Detected
  • 98779Source Code Passive Disclosure
  • 98950Nginx < 1.4.1 ngx_http_proxy_module.c Multiple Vulnerabilities
  • 98951Nginx < 1.2.9 ngx_http_proxy_module.c Multiple Vulnerabilities
  • 98952Nginx < 1.5.7 ngx_parse_http Security Bypass
  • 98953Nginx < 1.4.4 ngx_parse_http Security Bypass
  • 98957Nginx < 1.7.4 SMTP STARTTLS Command Injection
  • 98958Nginx < 1.6.1 SMTP STARTTLS Command Injection
  • 98959Nginx < 1.7.5 SSL Session Reuse
  • 98960Nginx < 1.6.2 SSL Session Reuse
  • 98995Kentico CMS 8.2.x < 8.2.41 Open Redirect
  • 98996Kentico CMS < 9.0.51 Cross-Site Scripting
New
  • 114115HTTP NTLM Information Disclosure
  • 114128External Backend API Detected
  • 114130WordPress 6.4.x < 6.4.2 Remote Code Execution
  • 114131SAP NetWeaver DI Server-Side Request Forgery
  • 114132JavaScript Source Map Detected
  • 114133SAP ICF Open-Redirect
  • 114135Input Reflected
  • 114136Bearer Token Authentication Detected
  • 114137NTLM Authentication Detected
  • 114138Digest Authentication Detected
  • 114139Joomla! 5.x < 5.0.1 Information Disclosure
  • 114140Joomla! 1.6.x < 4.4.1 Information Disclosure