Plugins
Settings
Links
Tenable Cloud
Tenable Community & Support
Tenable University
Severity
VPR
CVSS v2
CVSS v3
CVSS v4
Theme
Light
Dark
Auto
Help
Plugins
Overview
Plugins Pipeline
Newest
Updated
Search
Nessus Families
WAS Families
NNM Families
LCE Families
Tenable OT Security Families
About Plugin Families
Release Notes
Audits
Overview
Newest
Updated
Search Audit Files
Search Items
References
Authorities
Documentation
Download All Audit Files
Indicators
Overview
Search
Indicators of Attack
Indicators of Exposure
CVEs
Overview
Newest
Updated
Search
Attack Path Techniques
Overview
Search
Links
Tenable Cloud
Tenable Community & Support
Tenable University
Settings
Severity
VPR
CVSS v2
CVSS v3
CVSS v4
Theme
Light
Dark
Auto
Detections
Plugins
Overview
Plugins Pipeline
Release Notes
Newest
Updated
Search
Nessus Families
WAS Families
NNM Families
LCE Families
Tenable OT Security Families
About Plugin Families
Audits
Overview
Newest
Updated
Search Audit Files
Search Items
References
Authorities
Documentation
Download All Audit Files
Indicators
Overview
Search
Indicators of Attack
Indicators of Exposure
Analytics
CVEs
Overview
Newest
Updated
Search
Attack Path Techniques
Overview
Search
Plugins
Web App Scanning Release Notes
202409030646
Web App Scanning Release Notes
was Plugin Feed 202409030646
Sep 3, 2024, 6:46 AM
Modified Detection
112290
Apache Tomcat 9.0.0.M1 < 9.0.10 Multiple Vulnerabilities
112353
ASP.NET DEBUG Method Enabled
112526
Missing 'X-XSS-Protection' Header (deprecated)
112544
HTTP to HTTPS Redirect Not Enabled
112550
Full Path Disclosure
112686
JSON Web Token Detected
112719
Client-Side Prototype Pollution
112726
Apache Struts 2.3.5 < 2.3.32 / 2.5.x < 2.5.10.1 Remote Code Execution (S2-045 / S2-046)
112727
Apache Struts 2.0.4 < 2.3.35 / 2.5.x < 2.5.17 Remote Code Execution (S2-057)
112741
Apache Struts 2.x < 2.3.15.1 Remote Code Execution (S2-016)
112742
Apache Struts 2 < 2.3.29 DevMode Remote Code Execution
112760
Apache Struts 2 Demo Application Detected
112762
Apache Struts 2 < 2.3.33 Remote Code Execution (S2-048)
112763
Apache Struts 2.1.6 < 2.3.34 / 2.5 < 2.5.13 Remote Code Execution (S2-052)
112907
GraphQL Interface Detected
112920
GraphQL Cross-Site Request Forgery
113059
OPcache UI Detected
113158
Package Dependencies Detected
113162
MySQLjs SQL Injection Authentication Bypass
113217
Spring Framework < 5.2.20 / 5.3.x < 5.3.18 Remote Code Execution (Spring4Shell)
113219
Insecure Redirect Chain
113310
Blind XPath Injection (differential analysis)
113337
NoSQL Injection Authentication Bypass
113393
Performance Telemetry
113420
Nginx < 1.22.1 Multiple Vulnerabilities
113421
Nginx 1.23.x < 1.23.2 Multiple Vulnerabilities
113838
WooCommerce Payments Plugin for WordPress 5.6.x < 5.6.2 Authentication Bypass
113897
HTML Comments Detected
113943
Disclosed Hong Kong Identity Number
114006
Web Cache Poisoning Denial of Service
114029
Well-Known URIs Detected
114031
WooCommerce Payments Plugin for WordPress 6.3.x < 6.3.2 Authentication Bypass
114032
WooCommerce Payments Plugin for WordPress 6.2.x < 6.2.2 Authentication Bypass
114033
WooCommerce Payments Plugin for WordPress 5.5.x < 5.5.2 Authentication Bypass
114034
WooCommerce Payments Plugin for WordPress 5.4.x < 5.4.1 Authentication Bypass
114035
WooCommerce Payments Plugin for WordPress 5.3.x < 5.3.1 Authentication Bypass
114036
WooCommerce Payments Plugin for WordPress 5.2.x < 5.2.2 Authentication Bypass
114037
WooCommerce Payments Plugin for WordPress 5.1.x < 5.1.3 Authentication Bypass
114038
WooCommerce Payments Plugin for WordPress 5.0.x < 5.0.4 Authentication Bypass
114039
WooCommerce Payments Plugin for WordPress 4.9.x < 4.9.1 Authentication Bypass
114040
WooCommerce Payments Plugin for WordPress 4.8.x < 4.8.2 Authentication Bypass
114129
Secret Data Disclosure
114143
Node-config Configuration File Detected
114146
Subdomain Takeover
114220
Atlassian Confluence < 7.19.18 Cross-Site Scripting
114221
Atlassian Confluence 8.7.x < 8.7.2 Cross-Site Scripting
114222
Atlassian Confluence 7.20.x < 8.5.5 Cross-Site Scripting
114223
HTTP Request Smuggling
114238
Atlassian Confluence < 7.19.20 Path Traversal
114239
Atlassian Confluence 7.20.x < 8.5.7 Path Traversal
114240
Atlassian Confluence 8.6.x < 8.8.1 Path Traversal
114247
Authentication Check Pattern Found in Unauthenticated Browser
114258
LayerSlider Plugin for WordPress 7.9.11 < 7.10.1 SQL Injection
114283
Unrestricted File Upload
114373
Joomla! 5.x < 5.1.2 Multiple Vulnerabilities
114374
Joomla! 4.x < 4.4.6 Multiple Vulnerabilities
114375
Joomla! 3.x < 3.10.16 Multiple Vulnerabilities
114377
Atlassian Confluence < 7.19.22 Cross-Site Scripting
114378
Atlassian Confluence 7.20.x < 8.5.9 Cross-Site Scripting
114379
Atlassian Confluence 8.6.x < 8.9.1 Cross-Site Scripting
114386
External Broken Resources Detected
114400
Apache OFBiz < 18.12.11 Server-Side Request Forgery
98067
Insecure Cross-Domain Policy (allow-access-from)
98068
Insecure Cross-Domain Policy (allow-http-request-headers-from)
98070
Common Administration Interfaces Detection
98071
Common Files Detection
98077
Private IP Address Disclosure
98084
Directory Listing
98100
Path Traversal
98107
Cross-Site Scripting (XSS) in path
98109
DOM-based Cross-Site Scripting (XSS)
98110
DOM-based Cross-Site Scripting (XSS) in attribute context
98114
XPath Injection
98115
SQL Injection
98117
Blind SQL Injection (differential analysis)
98119
Blind NoSQL Injection (differential analysis)
98146
Password Submitted Using GET Method
98228
Drupal Unsupported Version
98538
Environment Configuration File Detected
98611
Error Message
98623
Host Header Injection
98950
Nginx < 1.4.1 ngx_http_proxy_module.c Multiple Vulnerabilities
98951
Nginx < 1.2.9 ngx_http_proxy_module.c Multiple Vulnerabilities
New
114395
WebSocket Detected
114396
Apache OFBiz < 18.12.15 Remote Code Execution
114397
AI Engine Plugin for WordPress < 2.4.8 Server-Side Request Forgery
114398
Edge Side Includes Injection
114399
Apache OFBiz < 18.12.13 Path Traversal
114401
Nginx+ Dashboard Unrestricted Access
114402
Nginx HTTP API Module Unrestricted Access
114403
Laravel Pulse Unrestricted Access
114404
Laravel Horizon Unrestricted Access
114405
Laravel Telescope Unrestricted Access
114406
LiteSpeed Cache Plugin for WordPress < 6.4 Privilege Escalation
114407
Gradio Detected
114408
Gradio Unauthenticated Access
114409
Gradio 4.3 < 4.13 Local File Read
114410
FCKEditor Unsupported Version
114411
Ivanti Virtual Traffic Manager Authentication Bypass