🚀 Invicti Acquires Kondukto to Deliver Proof-Based Application Security Posture Management
100% Signal 0% Noise
Platform
Platform Overview
ASPM
APIÂ Security
DAST
SAST
SCA
Container Security
AI-Powered AppSec
Cost Savings Calculator
Features
Solutions
Manage Vulnerabilities
Automate Security Workflows
Track AppSec KPIs
Manage Open Source Risk
Pricing
Why Invicti
About Us
Case Studies
Contact Us
Careers
Resources
Resource Library
Blog
Webinars
White Papers
Podcasts
Case Studies
Invicti Learn
Live Training
Partners
Documentation
Get a demo
Web Application Vulnerabilities Index
This page lists
144
vulnerabilities categorized as medium severity that can be detected by Invicti.
Select Category
Critical
High
Medium
Low
Best Practice
Information
Select Vulnerability
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
Vulnerability Name
Classification
Severity
Social Security Number Disclosure
Social Security Number Disclosure
Low
SonicWall SSL-VPN Server Identified
SonicWall SSL-VPN Server Identified
Information
Sortablejs Identified
Sortablejs Identified
Information
Source Code Disclosure (ASP.NET)
Source Code Disclosure (ASP.NET)
Medium
Source Code Disclosure (ColdFusion)
Source Code Disclosure (ColdFusion)
Medium
Source Code Disclosure (Generic)
Source Code Disclosure (Generic)
Medium
Source Code Disclosure (JSP)
Source Code Disclosure (JSP)
Medium
Source Code Disclosure (Java Servlet)
Source Code Disclosure (Java Servlet)
Medium
Source Code Disclosure (Java)
Source Code Disclosure (Java)
Medium
Source Code Disclosure (PHP)
Source Code Disclosure (PHP)
Medium
Source Code Disclosure (Perl)
Source Code Disclosure (Perl)
Medium
Source Code Disclosure (Python)
Source Code Disclosure (Python)
Medium
Source Code Disclosure (Ruby)
Source Code Disclosure (Ruby)
Medium
Source Code Disclosure (Tomcat)
Source Code Disclosure (Tomcat)
Medium
Spring Boot Actuator Endpoint Detected
Spring Boot Actuator Endpoint Detected
Medium
Spring Boot Misconfiguration: Actuator endpoint security disabled
Spring Boot Misconfiguration: Actuator endpoint security disabled
Medium
Spring Boot Misconfiguration: Admin MBean enabled
Spring Boot Misconfiguration: Admin MBean enabled
Medium
Spring Boot Misconfiguration: All Spring Boot Actuator endpoints are web exposed
Spring Boot Misconfiguration: All Spring Boot Actuator endpoints are web exposed
Medium
Spring Boot Misconfiguration: Datasource credentials stored in the properties file
Spring Boot Misconfiguration: Datasource credentials stored in the properties file
Medium
Spring Boot Misconfiguration: Developer tools enabled on production
Spring Boot Misconfiguration: Developer tools enabled on production
Medium
Spring Boot Misconfiguration: H2 console enabled
Spring Boot Misconfiguration: H2 console enabled
Medium
Spring Boot Misconfiguration: MongoDB credentials stored in the properties file
Spring Boot Misconfiguration: MongoDB credentials stored in the properties file
Medium
Spring Boot Misconfiguration: Overly long session timeout
Spring Boot Misconfiguration: Overly long session timeout
Medium
Spring Boot Misconfiguration: Spring Boot Actuator shutdown endpoint is web exposed
Spring Boot Misconfiguration: Spring Boot Actuator shutdown endpoint is web exposed
Medium
Spring Boot Misconfiguration: Unsafe value for session tracking
Spring Boot Misconfiguration: Unsafe value for session tracking
Medium
Spring Framework Identified
Spring Framework Identified
Information
Spring Misconfiguration: HTML Escaping disabled
Spring Misconfiguration: HTML Escaping disabled
Medium
Squarespace Identified
Squarespace Identified
Information
Squid Identified
Squid Identified
Information
Stack Trace Disclosure (ASP.NET)
Stack Trace Disclosure (ASP.NET)
Low
Stack Trace Disclosure (Apache MyFaces)
Stack Trace Disclosure (Apache MyFaces)
Low
Stack Trace Disclosure (Apache Shiro)
Stack Trace Disclosure (Apache Shiro)
Low
Stack Trace Disclosure (CakePHP Framework)
Stack Trace Disclosure (CakePHP Framework)
Low
Stack Trace Disclosure (CherryPy)
Stack Trace Disclosure (CherryPy)
Low
Stack Trace Disclosure (ColdFusion)
Stack Trace Disclosure (ColdFusion)
Medium
Stack Trace Disclosure (Django)
Stack Trace Disclosure (Django)
Medium
Stack Trace Disclosure (Grails)
Stack Trace Disclosure (Grails)
Low
Stack Trace Disclosure (GraphQL)
Stack Trace Disclosure (GraphQL)
Low
Stack Trace Disclosure (Java)
Stack Trace Disclosure (Java)
Medium
Stack Trace Disclosure (Laravel)
Stack Trace Disclosure (Laravel)
Medium
Stack Trace Disclosure (Node.js)
Stack Trace Disclosure (Node.js)
Low
Stack Trace Disclosure (PHP)
Stack Trace Disclosure (PHP)
Low
Stack Trace Disclosure (Python)
Stack Trace Disclosure (Python)
Medium
Stack Trace Disclosure (RoR)
Stack Trace Disclosure (RoR)
Medium
Stack Trace Disclosure (Ruby-Sinatra Framework)
Stack Trace Disclosure (Ruby-Sinatra Framework)
Medium
Static Nonce Identified in Content Security Policy (CSP)
Static Nonce Identified in Content Security Policy (CSP)
Information
Stored Cross-site Scripting
Stored Cross-site Scripting
High
Struts 2 Config Browser plugin enabled
Struts 2 Config Browser plugin enabled
Medium
Struts 2 Development Mode Enabled
Struts 2 Development Mode Enabled
Medium
Struts2 Development Mode Enabled
Struts2 Development Mode Enabled
Low
Sublime SFTP Config File Detected
Sublime SFTP Config File Detected
Medium
Subresource Integrity (SRI) Hash Invalid
Subresource Integrity (SRI) Hash Invalid
Low
Subresource Integrity (SRI) Not Implemented
Subresource Integrity (SRI) Not Implemented
Best Practice
Sugar CRM Identified
Sugar CRM Identified
Information
SwaggerUI Identified
SwaggerUI Identified
Information
SweetAlert2 Identified
SweetAlert2 Identified
Information
TCExam Detected
TCExam Detected
Information
TLS/SSL Certificate Key Size Too Small
TLS/SSL Certificate Key Size Too Small
Medium
TRACE/TRACK Method Detected
TRACE/TRACK Method Detected
Low
TS Web Access Identified
TS Web Access Identified
Information
Tableau Server Detected
Tableau Server Detected
Information
Taleo Web Server Identified
Taleo Web Server Identified
Information
Telerik Web UI Identified
Telerik Web UI Identified
Information
Test File Detected
Test File Detected
Information
Text4Shell Remote Code Execution - (CVE-2022-42889)
Text4Shell Remote Code Execution - (CVE-2022-42889)
Critical
ThreeJs Identified
ThreeJs Identified
Information
TinyMCE Identified
TinyMCE Identified
Information
Tomcat Identified
Tomcat Identified
Information
TorchServe Management API Publicly Exposed
TorchServe Management API Publicly Exposed
High
TorchServe Management API SSRF (CVE-2023-43654)
TorchServe Management API SSRF (CVE-2023-43654)
Critical
Tornado Web Server Identified
Tornado Web Server Identified
Information
Trac Software Project Management Tool Identified
Trac Software Project Management Tool Identified
Information
Trace.axd Detected
Trace.axd Detected
High
Tracy Debugging Identified
Tracy Debugging Identified
Information
1