was Plugin Feed 202402020754

Feb 2, 2024, 7:54 AM
Modified Detection
  • 112290Apache Tomcat 9.0.0.M1 < 9.0.10 Multiple Vulnerabilities
  • 112295Apache Tomcat 9.0.0.M1 < 9.0.0.M22 Multiple Vulnerabilities
  • 112353ASP.NET DEBUG Method Enabled
  • 112526Missing 'X-XSS-Protection' Header
  • 112527Disabled 'X-XSS-Protection' Header
  • 112529Missing 'X-Content-Type-Options' Header
  • 112535HTTP Strict Transport Security Policy Detected
  • 112543HTTPS Not Detected
  • 112544HTTP to HTTPS Redirect Not Enabled
  • 112550Full Path Disclosure
  • 112551Missing Content Security Policy
  • 112552Deprecated Content Security Policy
  • 112553Missing 'Cache-Control' Header
  • 112554Permissive Content Security Policy Detected
  • 112555Report Only Content Security Policy Detected
  • 112569OpenAPI Import Success
  • 112570OpenAPI Import Failed
  • 112614Server-Side Template Injection
  • 112686JSON Web Token Detected
  • 112697JSON Web Token Weak Secret
  • 112705Oracle WebLogic 10.3.6.0.0 / 12.1.3.0.0 / 12.2.1.4.0 / 14.1.1.0.0 Authentication Bypass
  • 112907GraphQL Interface Detected
  • 112920GraphQL Cross-Site Request Forgery
  • 113010API Key Authentication Succeeded
  • 113011API Key Authentication Failed
  • 113012Bearer Token Authentication Succeeded
  • 113013Bearer Token Authentication Failed
  • 113030Out-of-Date Bootstrap Detected
  • 113031Out-of-Date JQuery UI Detected
  • 113032Out-of-Date Modernizr Detected
  • 113033Out-of-Date Underscore.js Detected
  • 113034Out-of-Date MediaElement.Js Detected
  • 113037Out-of-Date Backbone JS Framework Detected
  • 113075Apache Log4j Remote Code Execution (Log4Shell)
  • 113078AngularJS Unsupported Version
  • 113117Magento Administration Panel Login Form Bruteforced
  • 113136Wordpress Administration Panel Login Form Bruteforced
  • 113158Package Dependencies Detected
  • 113162MySQLjs SQL Injection Authentication Bypass
  • 113165Apache mod_negotiation Alternative Filename Disclosure
  • 113168Docker Compose Configuration Detected
  • 113211HTTP Verb Tampering
  • 113217Spring Framework < 5.2.20 / 5.3.x < 5.3.18 Remote Code Execution (Spring4Shell)
  • 113237PHP Object Deserialization
  • 113310Blind XPath Injection (differential analysis)
  • 113333Duplicate HTTP Headers Detected
  • 113337NoSQL Injection Authentication Bypass
  • 113338Web Cache Poisoning
  • 113393Performance Telemetry
  • 113420Nginx < 1.22.1 Multiple Vulnerabilities
  • 113421Nginx 1.23.x < 1.23.2 Multiple Vulnerabilities
  • 113452WordPress Plugins Detected
  • 113580Web Cache Deception
  • 113838WooCommerce Payments Plugin for WordPress 5.6.x < 5.6.2 Authentication Bypass
  • 113897HTML Comments Detected
  • 113900Cross-Site Request Forgery Token Validation Bypass
  • 113959GeoServer SQL Injection
  • 113973Web Services Description Language (WSDL) File Detected
  • 114006Web Cache Poisoning Denial of Service
  • 114027WP Fastest Cache Plugin for WordPress < 1.1.3 Multiple Vulnerabilities
  • 114031WooCommerce Payments Plugin for WordPress 6.3.x < 6.3.2 Authentication Bypass
  • 114032WooCommerce Payments Plugin for WordPress 6.2.x < 6.2.2 Authentication Bypass
  • 114033WooCommerce Payments Plugin for WordPress 5.5.x < 5.5.2 Authentication Bypass
  • 114034WooCommerce Payments Plugin for WordPress 5.4.x < 5.4.1 Authentication Bypass
  • 114035WooCommerce Payments Plugin for WordPress 5.3.x < 5.3.1 Authentication Bypass
  • 114036WooCommerce Payments Plugin for WordPress 5.2.x < 5.2.2 Authentication Bypass
  • 114037WooCommerce Payments Plugin for WordPress 5.1.x < 5.1.3 Authentication Bypass
  • 114038WooCommerce Payments Plugin for WordPress 5.0.x < 5.0.4 Authentication Bypass
  • 114039WooCommerce Payments Plugin for WordPress 4.9.x < 4.9.1 Authentication Bypass
  • 114040WooCommerce Payments Plugin for WordPress 4.8.x < 4.8.2 Authentication Bypass
  • 114041Strapi Cognito Provider Authentication Bypass
  • 114042Adobe ColdFusion Remote Code Execution
  • 114043Adobe ColdFusion Improper Access Control
  • 114108Strapi < 4.8.0 Private Fields Sensitive Information Disclosure
  • 114122Appwrite Server-Side Request Forgery
  • 114129Secret Data Disclosure
  • 114134HTML/CSS Injection
  • 114143Node-config Configuration File Detected
  • 114145Apache OFBiz Authentication Bypass
  • 114164Stripe Payment Plugin for WooCommerce Plugin for WordPress < 3.8.0 SQL Injection
  • 114166SOAP API Detected
  • 98008Web Application Firewall Detected
  • 98034Login Form Authentication Failed
  • 98035Login Form Authentication Succeeded
  • 98047Allowed HTTP Methods
  • 98056Missing HTTP Strict Transport Security Policy
  • 98057Insecure 'Access-Control-Allow-Origin' Header
  • 98060Missing 'X-Frame-Options' Header
  • 98067Insecure Cross-Domain Policy (allow-access-from)
  • 98068Insecure Cross-Domain Policy (allow-http-request-headers-from)
  • 98084Directory Listing
  • 98095Misconfiguration in LIMIT directive of .htaccess file
  • 98097Backdoor Detection
  • 98107Cross-Site Scripting (XSS) in path
  • 98112Cross-Site Request Forgery
  • 98114XPath Injection
  • 98115SQL Injection
  • 98117Blind SQL Injection (differential analysis)
  • 98119Blind NoSQL Injection (differential analysis)
  • 98123Operating System Command Injection
  • 98136Target Information
  • 98139Cookie Authentication Succeeded
  • 98140Cookie Authentication Failed
  • 98141Selenium Authentication Succeeded
  • 98142Selenium Authentication Failed
  • 98143Selenium Crawl Succeeded
  • 98145Selenium Crawl Failed
  • 98146Password Submitted Using GET Method
  • 98200Drupal Administration Panel Login Form Detected
  • 98228Drupal Unsupported Version
  • 98526Missing Permissions Policy
  • 98527Missing Referrer Policy
  • 98538Environment Configuration File Detected
  • 98607Ultimate Member Plugin for WordPress < 2.0.46 Multiple Vulnerabilities
  • 98618HTTP Header Information Disclosure
  • 98642Magento Administration Panel Login Form Detected
  • 98648Missing 'Content-Type' Header
  • 98715Permissive HTTP Strict Transport Security Policy Detected
  • 98950Nginx < 1.4.1 ngx_http_proxy_module.c Multiple Vulnerabilities
  • 98951Nginx < 1.2.9 ngx_http_proxy_module.c Multiple Vulnerabilities
New
  • 114162XSLT Injection
  • 114163Fortra GoAnywhere MFT 6.x > 6.0.1 / 7.x < 7.4.1 Authentication Bypass
  • 114165Ivanti Connect Secure 9.x / 22.x Authentication Bypass
  • 114167gRPC Detected
  • 114168Jenkins < 2.442 / < LTS 2.426.3 Arbitrary File Read
  • 114169Google Extensible Service Proxy 2.20.0 < 2.43.0 Authentication Bypass
  • 114170WordPress 4.1.x < 4.1.40 Multiple Vulnerabilities
  • 114171WordPress 4.2.x < 4.2.37 Multiple Vulnerabilities
  • 114172WordPress 4.3.x < 4.3.33 Multiple Vulnerabilities
  • 114173WordPress 4.4.x < 4.4.32 Multiple Vulnerabilities
  • 114174WordPress 4.5.x < 4.5.31 Multiple Vulnerabilities
  • 114175WordPress 4.6.x < 4.6.28 Multiple Vulnerabilities
  • 114176WordPress 4.7.x < 4.7.28 Multiple Vulnerabilities
  • 114177WordPress 4.8.x < 4.8.24 Multiple Vulnerabilities
  • 114178WordPress 4.9.x < 4.9.25 Multiple Vulnerabilities
  • 114179WordPress 5.0.x < 5.0.21 Multiple Vulnerabilities
  • 114180WordPress 5.1.x < 5.1.18 Multiple Vulnerabilities
  • 114181WordPress 5.2.x < 5.2.20 Multiple Vulnerabilities
  • 114182WordPress 5.3.x < 5.3.17 Multiple Vulnerabilities
  • 114183WordPress 5.4.x < 5.4.15 Multiple Vulnerabilities
  • 114184WordPress 5.5.x < 5.5.14 Multiple Vulnerabilities
  • 114185WordPress 5.6.x < 5.6.13 Multiple Vulnerabilities
  • 114186WordPress 5.7.x < 5.7.11 Multiple Vulnerabilities
  • 114187WordPress 5.8.x < 5.8.9 Multiple Vulnerabilities
  • 114188WordPress 5.9.x < 5.9.9 Multiple Vulnerabilities
  • 114189WordPress 6.0.x < 6.0.7 Multiple Vulnerabilities
  • 114190WordPress 6.1.x < 6.1.5 Multiple Vulnerabilities
  • 114191WordPress 6.2.x < 6.2.4 Multiple Vulnerabilities
  • 114192WordPress 6.3.x < 6.3.3 Multiple Vulnerabilities
  • 114193WordPress 6.4.x < 6.4.3 Multiple Vulnerabilities
  • 114194Express.js Authentication Bypass
  • 114195Web Server Configuration File Detected