Plugins
Settings
Links
Tenable Cloud
Tenable Community & Support
Tenable University
Severity
VPR
CVSS v2
CVSS v3
CVSS v4
Theme
Light
Dark
Auto
Help
Plugins
Overview
Plugins Pipeline
Newest
Updated
Search
Nessus Families
WAS Families
NNM Families
LCE Families
Tenable OT Security Families
About Plugin Families
Release Notes
Audits
Overview
Newest
Updated
Search Audit Files
Search Items
References
Authorities
Documentation
Download All Audit Files
Indicators
Overview
Search
Indicators of Attack
Indicators of Exposure
CVEs
Overview
Newest
Updated
Search
Attack Path Techniques
Overview
Search
Links
Tenable Cloud
Tenable Community & Support
Tenable University
Settings
Severity
VPR
CVSS v2
CVSS v3
CVSS v4
Theme
Light
Dark
Auto
Detections
Plugins
Overview
Plugins Pipeline
Release Notes
Newest
Updated
Search
Nessus Families
WAS Families
NNM Families
LCE Families
Tenable OT Security Families
About Plugin Families
Audits
Overview
Newest
Updated
Search Audit Files
Search Items
References
Authorities
Documentation
Download All Audit Files
Indicators
Overview
Search
Indicators of Attack
Indicators of Exposure
Analytics
CVEs
Overview
Newest
Updated
Search
Attack Path Techniques
Overview
Search
Plugins
Web App Scanning Release Notes
202312180856
Web App Scanning Release Notes
was Plugin Feed 202312180856
Dec 18, 2023, 8:56 AM
Modified Detection
112290
Apache Tomcat 9.0.0.M1 < 9.0.10 Multiple Vulnerabilities
112295
Apache Tomcat 9.0.0.M1 < 9.0.0.M22 Multiple Vulnerabilities
112353
ASP.NET DEBUG Method Enabled
112354
lighttpd < 1.4.28 Insecure Temporary File Creation
112358
lighttpd < 1.4.35 Multiple Vulnerabilities
112501
Sitefinity < 10.0.6412.0 Multiple Vulnerabilities
112520
Magento Unsupported Version
112526
Missing 'X-XSS-Protection' Header
112527
Disabled 'X-XSS-Protection' Header
112529
Missing 'X-Content-Type-Options' Header
112535
HTTP Strict Transport Security Policy Detected
112543
HTTPS Not Detected
112544
HTTP to HTTPS Redirect Not Enabled
112550
Full Path Disclosure
112551
Missing Content Security Policy
112552
Deprecated Content Security Policy
112553
Missing 'Cache-Control' Header
112554
Permissive Content Security Policy Detected
112555
Report Only Content Security Policy Detected
112569
OpenAPI Import Success
112570
OpenAPI Import Failed
112582
Microsoft SharePoint Server 2016 < 16.0.5056.1001 Multiple Vulnerabilities
112583
Microsoft SharePoint Server 2019 < 16.0.10366.12106 Multiple Vulnerabilities
112584
Microsoft SharePoint Server 2013 < 15.0.5275.1001 Multiple Vulnerabilities
112585
Microsoft SharePoint Server 2010 < 14.0.7260.5000 Multiple Vulnerabilities
112586
Microsoft SharePoint Server 2016 < 16.0.5044.1000 Multiple Vulnerabilities
112587
Microsoft SharePoint Server 2013 < 15.0.5267.1000 Multiple Vulnerabilities
112588
Microsoft SharePoint Server 2019 < 16.0.10364.20001 Multiple Vulnerabilities
112589
Microsoft SharePoint Server 2010 < 14.0.7256.5000 Multiple Vulnerabilities
112614
Server-Side Template Injection
112615
OpenAPI File Detected
112673
Resin < 4.0.40 Incorrect Unicode Transformations
112686
JSON Web Token Detected
112697
JSON Web Token Weak Secret
112703
JSON Web Token None Hashing Algorithm
112705
Oracle WebLogic 10.3.6.0.0 / 12.1.3.0.0 / 12.2.1.4.0 / 14.1.1.0.0 Authentication Bypass
112730
Microsoft SharePoint Server 2016 < 16.0.5095.1000 Multiple Vulnerabilities
112731
Microsoft SharePoint Server 2019 < 16.0.10369.20000 Multiple Vulnerabilities
112732
Microsoft SharePoint Server 2010 < 14.0.7263.5000 Multiple Vulnerabilities
112733
Microsoft SharePoint Server 2010 < 14.0.7262.5000 Multiple Vulnerabilities
112734
Microsoft SharePoint Server 2019 < 16.0.10368.20022 Multiple Vulnerabilities
112735
Microsoft SharePoint Server 2013 < 15.0.5293.1000 Multiple Vulnerabilities
112736
Microsoft SharePoint Server 2016 < 16.0.5083.1000 Multiple Vulnerabilities
112737
Microsoft SharePoint Server 2010 < 14.0.7261.5000 Multiple Vulnerabilities
112738
Microsoft SharePoint Server 2019 < 16.0.10367.20000 Multiple Vulnerabilities
112739
Microsoft SharePoint Server 2016 < 16.0.5071.1000 Multiple Vulnerabilities
112740
Microsoft SharePoint Server 2013 < 15.0.5285.1000 Multiple Vulnerabilities
112907
GraphQL Interface Detected
112920
GraphQL Cross-Site Request Forgery
112926
Microsoft SharePoint Server 2019 < 16.0.10376.20001 Multiple Vulnerabilities
112927
Microsoft SharePoint Server 2016 < 16.0.5188.1000 Multiple Vulnerabilities
112928
Microsoft SharePoint Server 2013 < 15.0.5363.1000 Multiple Vulnerabilities
112940
Microsoft SharePoint Server 2019 < 16.0.10370.20001 Multiple Vulnerabilities
112941
Microsoft SharePoint Server 2016 < 16.0.5110.1000 Multiple Vulnerabilities
112942
Microsoft SharePoint Server 2010 < 14.0.7264.5000 Multiple Vulnerabilities
112943
Microsoft SharePoint Server 2013 < 15.0.5311.1000 Multiple Vulnerabilities
113010
API Key Authentication Succeeded
113011
API Key Authentication Failed
113012
Bearer Token Authentication Succeeded
113013
Bearer Token Authentication Failed
113027
Out-of-Date JQuery Detected
113028
Out-of-Date Lodash Detected
113029
Microsoft IIS Unsupported Version
113030
Out-of-Date Bootstrap Detected
113031
Out-of-Date JQuery UI Detected
113032
Out-of-Date Modernizr Detected
113033
Out-of-Date Underscore.js Detected
113034
Out-of-Date MediaElement.Js Detected
113035
Out-of-Date Moment JS Framework Detected
113036
Out-of-Date Knockout JS Detected
113037
Out-of-Date Backbone JS Framework Detected
113075
Apache Log4j Remote Code Execution (Log4Shell)
113078
AngularJS Unsupported Version
113088
Microsoft SharePoint Server 2019 < 16.0.10377.20001 Multiple Vulnerabilities
113089
Microsoft SharePoint Server 2013 < 15.0.5371.1000 Multiple Vulnerabilities
113090
Microsoft SharePoint Server 2016 < 16.0.5200.1000 Multiple Vulnerabilities
113117
Magento Administration Panel Login Form Bruteforced
113136
Wordpress Administration Panel Login Form Bruteforced
113158
Package Dependencies Detected
113162
MySQLjs SQL Injection Authentication Bypass
113165
Apache mod_negotiation Alternative Filename Disclosure
113168
Docker Compose Configuration Detected
113211
HTTP Verb Tampering
113212
Content Injection
113217
Spring Framework < 5.2.20 / 5.3.x < 5.3.18 Remote Code Execution (Spring4Shell)
113237
PHP Object Deserialization
113242
Java Psychic Signatures
113310
Blind XPath Injection (differential analysis)
113333
Duplicate HTTP Headers Detected
113337
NoSQL Injection Authentication Bypass
113338
Web Cache Poisoning
113393
Performance Telemetry
113420
Nginx < 1.22.1 Multiple Vulnerabilities
113421
Nginx 1.23.x < 1.23.2 Multiple Vulnerabilities
113452
WordPress Plugins Detected
113458
Yoast SEO Plugin for WordPress < 1.5.7 Multiple Vulnerabilities
113459
Yoast SEO Plugin for WordPress 1.6.x < 1.6.4 Multiple Vulnerabilities
113460
Yoast SEO Plugin for WordPress 1.7.x < 1.7.4 Multiple Vulnerabilities
113467
WP DBManager Plugin for WordPress < 2.7.2 Multiple Vulnerabilities
113472
WP EasyCart Plugin for WordPress < 3.0.9 Unrestricted File Upload
113473
WP Photo Album Plus Plugin for WordPress < 6.1.3 Multiple Cross-Site Scripting
113474
WP-Print Plugin for WordPress < 2.52 Cross-Site Request Forgery
113475
WP eCommerce Plugin for WordPress < 3.8.7.6 SQL Injection
113476
WP-PostViews Plugin for WordPress < 1.63 Cross-Site Request Forgery
113478
All In One WP Security & Firewall Plugin for WordPress < 3.8.8 SQL Injection
113479
All In One WP Security & Firewall Plugin for WordPress < 3.8.3 Multiple SQL Injection
113488
Advanced Dewplayer Plugin for WordPress < 1.3 Path Traversal
113489
WordPress Classifieds Plugin Plugin for WordPress < 3.0 SQL Injection
113490
WordPress Mobile Pack Plugin for WordPress < 2.0.2 Sensitive Information Disclosure
113491
WP Easy Post Types Plugin for WordPress < 1.4.4 Cross-Site Scripting
113492
Apptha WordPress Video Gallery Plugin for WordPress < 2.8.0 SQL Injection
113493
Cross-RSS Plugin for WordPress Arbitrary Files Read
113494
WP Ultimate Email Marketer Plugin for WordPress Multiple Vulnerabilities
113495
WP Cron Dashboard Plugin for WordPress < 1.1.6 Cross-Site Scripting
113496
WP RESTful Plugin for WordPress Multiple Cross-Site Scripting
113497
Social Invitations Plugin for WordPress < 1.4.4.3 Cross-Site Scripting
113498
WP e-Commerce Shop Styling Plugin for WordPress < 1.8 Code Injection
113499
WP Symposium Plugin for WordPress < 15.8 SQL Injection
113503
WordPress < 2.1 Cross-Site Request Forgery
113504
Slimstat Analytics Plugin for WordPress < 3.9.2 Cross-site Scripting
113545
Apache 2.4.x < 2.4.55 Multiple Vulnerabilities
113580
Web Cache Deception
113584
Joomla! 4.0.0 < 4.2.8 Broken Access Control
113715
Atlassian Jira < 3.13.1 Cross-Site Scripting
113816
Atlassian Jira < 6.0.4 Directory Traversal In Issue Collector
113817
Atlassian Jira < 6.0.5 Multiple Vulnerabilities
113818
Atlassian Jira < 3.7.1 Giffy Plugin Arbitrary File Read
113819
Atlassian Jira < 6.4.3.1 / 6.5.x < 6.5.0.2 / 7.x < 7.0.3 Software Tempo Plugin Xml Denial Of Service
113820
Atlassian Jira 6.5.x < 6.5.0.2 Software Tempo Plugin Xml Denial Of Service
113821
Atlassian Jira 7.x < 7.0.3 Software Tempo Plugin Xml Denial Of Service
113823
Atlassian Jira < 3.12.1 Xss In 500 Page
113838
WooCommerce Payments Plugin for WordPress 5.6.x < 5.6.2 Authentication Bypass
113853
Customer Reviews for WooCommerce Plugin for WordPress < 5.17.0 Cross-Site Scripting
113855
GiveWP Plugin for WordPress < 2.24.1 SQL Injection
113871
DotNetNuke User Enumeration
113897
HTML Comments Detected
113900
Cross-Site Request Forgery Token Validation Bypass
113904
Sitecore Unauthenticated User Enumeration
113938
CA SiteMinder WebAgent Cross-Site Scripting
113959
GeoServer SQL Injection
113973
Web Services Description Language (WSDL) File Detected
114006
Web Cache Poisoning Denial of Service
114026
WP EasyCart Plugin for WordPress < 2.0.6 Sensitive Information Disclosure
114027
WP Fastest Cache Plugin for WordPress < 1.1.3 Multiple Vulnerabilities
114031
WooCommerce Payments Plugin for WordPress 6.3.x < 6.3.2 Authentication Bypass
114032
WooCommerce Payments Plugin for WordPress 6.2.x < 6.2.2 Authentication Bypass
114033
WooCommerce Payments Plugin for WordPress 5.5.x < 5.5.2 Authentication Bypass
114034
WooCommerce Payments Plugin for WordPress 5.4.x < 5.4.1 Authentication Bypass
114035
WooCommerce Payments Plugin for WordPress 5.3.x < 5.3.1 Authentication Bypass
114036
WooCommerce Payments Plugin for WordPress 5.2.x < 5.2.2 Authentication Bypass
114037
WooCommerce Payments Plugin for WordPress 5.1.x < 5.1.3 Authentication Bypass
114038
WooCommerce Payments Plugin for WordPress 5.0.x < 5.0.4 Authentication Bypass
114039
WooCommerce Payments Plugin for WordPress 4.9.x < 4.9.1 Authentication Bypass
114040
WooCommerce Payments Plugin for WordPress 4.8.x < 4.8.2 Authentication Bypass
114041
Strapi Cognito Provider Authentication Bypass
114042
Adobe ColdFusion Remote Code Execution
114043
Adobe ColdFusion Improper Access Control
114089
Pimcore User Enumeration
114099
Microsoft SharePoint Server 2019 build < 16.0.10399.20005 Elevation of Privilege
114108
Strapi < 4.8.0 Private Fields Sensitive Information Disclosure
114117
OwnCloud graphapi 0.2.x < 0.2.1 / 0.3.x < 0.3.1 Sensitive Informations Disclosure
114122
Appwrite Server-Side Request Forgery
114123
Atlassian Confluence 4.x < 7.19.17 Template Injection
114124
Atlassian Confluence 8.x < 8.4.5 Template Injection
114125
Atlassian Confluence 8.5.x < 8.5.4 Template Injection
114126
Atlassian Confluence 8.6.x < 8.6.2 Template Injection
114127
Atlassian Confluence 8.7.x < 8.7.1 Template Injection
114129
Secret Data Disclosure
114134
HTML/CSS Injection
114141
Backup Migration Plugin for WordPress < 1.3.8 Remote Code Execution
115540
Cookie Without SameSite Flag Detected
98008
Web Application Firewall Detected
98034
Login Form Authentication Failed
98035
Login Form Authentication Succeeded
98047
Allowed HTTP Methods
98056
Missing HTTP Strict Transport Security Policy
98057
Insecure 'Access-Control-Allow-Origin' Header
98060
Missing 'X-Frame-Options' Header
98062
Cookie Set For Parent Domain
98063
Cookie Without HttpOnly Flag Detected
98064
Cookie Without Secure Flag Detected
98067
Insecure Cross-Domain Policy (allow-access-from)
98068
Insecure Cross-Domain Policy (allow-http-request-headers-from)
98071
Common Files Detection
98072
Common Directories Detection
98084
Directory Listing
98095
Misconfiguration in LIMIT directive of .htaccess file
98097
Backdoor Detection
98107
Cross-Site Scripting (XSS) in path
98112
Cross-Site Request Forgery
98114
XPath Injection
98115
SQL Injection
98117
Blind SQL Injection (differential analysis)
98119
Blind NoSQL Injection (differential analysis)
98123
Operating System Command Injection
98136
Target Information
98139
Cookie Authentication Succeeded
98140
Cookie Authentication Failed
98141
Selenium Authentication Succeeded
98142
Selenium Authentication Failed
98143
Selenium Crawl Succeeded
98145
Selenium Crawl Failed
98146
Password Submitted Using GET Method
98200
Drupal Administration Panel Login Form Detected
98227
WordPress Unsupported Version
98228
Drupal Unsupported Version
98229
Joomla! Unsupported Version
98230
PHP Unsupported Version
98231
Apache Unsupported Version
98232
Apache Tomcat Unsupported Version
98237
MediaElement.js < 2.11.2 Cross-Site Scripting
98398
JK Status Manager Information Disclosure
98526
Missing Permissions Policy
98527
Missing Referrer Policy
98538
Environment Configuration File Detected
98607
Ultimate Member Plugin for WordPress < 2.0.46 Multiple Vulnerabilities
98618
HTTP Header Information Disclosure
98642
Magento Administration Panel Login Form Detected
98648
Missing 'Content-Type' Header
98679
Webmin < 1.730 Read Mail Symlink Vulnerability
98703
Magento API Anonymous Access
98715
Permissive HTTP Strict Transport Security Policy Detected
98779
Source Code Passive Disclosure
98950
Nginx < 1.4.1 ngx_http_proxy_module.c Multiple Vulnerabilities
98951
Nginx < 1.2.9 ngx_http_proxy_module.c Multiple Vulnerabilities
98952
Nginx < 1.5.7 ngx_parse_http Security Bypass
98953
Nginx < 1.4.4 ngx_parse_http Security Bypass
98957
Nginx < 1.7.4 SMTP STARTTLS Command Injection
98958
Nginx < 1.6.1 SMTP STARTTLS Command Injection
98959
Nginx < 1.7.5 SSL Session Reuse
98960
Nginx < 1.6.2 SSL Session Reuse
98995
Kentico CMS 8.2.x < 8.2.41 Open Redirect
98996
Kentico CMS < 9.0.51 Cross-Site Scripting
New
114115
HTTP NTLM Information Disclosure
114128
External Backend API Detected
114130
WordPress 6.4.x < 6.4.2 Remote Code Execution
114131
SAP NetWeaver DI Server-Side Request Forgery
114132
JavaScript Source Map Detected
114133
SAP ICF Open-Redirect
114135
Input Reflected
114136
Bearer Token Authentication Detected
114137
NTLM Authentication Detected
114138
Digest Authentication Detected
114139
Joomla! 5.x < 5.0.1 Information Disclosure
114140
Joomla! 1.6.x < 4.4.1 Information Disclosure