🚀 Invicti Acquires Kondukto to Deliver Proof-Based Application Security Posture Management
100% Signal 0% Noise
Platform
Platform Overview
ASPM
APIÂ Security
DAST
SAST
SCA
Container Security
AI-Powered AppSec
Cost Savings Calculator
Features
Solutions
Manage Vulnerabilities
Automate Security Workflows
Track AppSec KPIs
Manage Open Source Risk
Pricing
Why Invicti
About Us
Case Studies
Contact Us
Careers
Resources
Resource Library
Blog
Webinars
White Papers
Podcasts
Case Studies
Invicti Learn
Live Training
Partners
Documentation
Get a demo
Web Application Vulnerabilities Index
This page lists
144
vulnerabilities categorized as medium severity that can be detected by Invicti.
Select Category
Critical
High
Medium
Low
Best Practice
Information
Select Vulnerability
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
Vulnerability Name
Classification
Severity
Mustachejs Identified
Mustachejs Identified
Information
MyBB Detected
MyBB Detected
Information
NTLM Authorization Required
NTLM Authorization Required
Information
Next.js React Framework Identified
Next.js React Framework Identified
Information
Nexus Repository OSS Identified
Nexus Repository OSS Identified
Information
Nginx Web Server Identified
Nginx Web Server Identified
Information
No SAML Response Signature Check
No SAML Response Signature Check
High
No Script Block Detected with the Hash Value Declared in Content Security Policy (CSP)
No Script Block Detected with the Hash Value Declared in Content Security Policy (CSP)
Information
Node.js Web Application does not handle uncaughtException
Node.js Web Application does not handle uncaughtException
Medium
Node.js Web Application does not handle unhandledRejection
Node.js Web Application does not handle unhandledRejection
Medium
Nonce Usage Detected in Content Security Policy (CSP) Directive
Nonce Usage Detected in Content Security Policy (CSP) Directive
Information
NuSOAP Identified
NuSOAP Identified
Information
OPTIONS Method Enabled
OPTIONS Method Enabled
Information
Omeka Detected
Omeka Detected
Information
Open Policy Crossdomain.xml Detected
Open Policy Crossdomain.xml Detected
Medium
Open Redirection
Open Redirection
Medium
Open Redirection (DOM based)
Open Redirection (DOM based)
Medium
Open Redirection in POST method
Open Redirection in POST method
Low
Open Silverlight Client Access Policy
Open Silverlight Client Access Policy
Medium
OpenCart Detected
OpenCart Detected
Information
OpenResty Web Platform Identified
OpenResty Web Platform Identified
Information
OpenSSL Heartbleed
OpenSSL Heartbleed
Critical
OpenSSL Identified
OpenSSL Identified
Information
OpenSearch.xml Detected
OpenSearch.xml Detected
Information
OpenVPN Access Server Identified
OpenVPN Access Server Identified
Information
Oracle Application Server Identified
Oracle Application Server Identified
Information
Oracle EBS - Unauthenticated Remote Code Execution
Oracle EBS - Unauthenticated Remote Code Execution
Critical
Oracle HTTP Server Identified
Oracle HTTP Server Identified
Information
Oracle WebLogic Authentication Bypass (CVE-2020-14883)
Oracle WebLogic Authentication Bypass (CVE-2020-14883)
High
Oracle WebLogic Remote Code Execution (CVE-2020-14882)
Oracle WebLogic Remote Code Execution (CVE-2020-14882)
Critical
Out of Band Code Evaluation (ASP)
Out of Band Code Evaluation (ASP)
Critical
Out of Band Code Evaluation (Apache Struts 2)
Out of Band Code Evaluation (Apache Struts 2)
Critical
Out of Band Code Evaluation (Apache Struts 2) S2-053
Out of Band Code Evaluation (Apache Struts 2) S2-053
Critical
Out of Band Code Evaluation (Log4j)
Out of Band Code Evaluation (Log4j)
Critical
Out of Band Code Evaluation (Node.js)
Out of Band Code Evaluation (Node.js)
Critical
Out of Band Code Evaluation (PHP)
Out of Band Code Evaluation (PHP)
Critical
Out of Band Code Evaluation (Perl)
Out of Band Code Evaluation (Perl)
Critical
Out of Band Code Evaluation (Python)
Out of Band Code Evaluation (Python)
Critical
Out of Band Code Evaluation (RoR - JSON)
Out of Band Code Evaluation (RoR - JSON)
Critical
Out of Band Code Evaluation (RoR)
Out of Band Code Evaluation (RoR)
Critical
Out of Band Code Evaluation (Ruby)
Out of Band Code Evaluation (Ruby)
Critical
Out of Band Code Execution via SSTI
Out of Band Code Execution via SSTI
Critical
Out of Band Code Execution via SSTI (Java FreeMarker)
Out of Band Code Execution via SSTI (Java FreeMarker)
Critical
Out of Band Code Execution via SSTI (Java Velocity)
Out of Band Code Execution via SSTI (Java Velocity)
Critical
Out of Band Code Execution via SSTI (Node.js Dot)
Out of Band Code Execution via SSTI (Node.js Dot)
Critical
Out of Band Code Execution via SSTI (Node.js EJS)
Out of Band Code Execution via SSTI (Node.js EJS)
Critical
Out of Band Code Execution via SSTI (Node.js Marko)
Out of Band Code Execution via SSTI (Node.js Marko)
Critical
Out of Band Code Execution via SSTI (Node.js Nunjucks)
Out of Band Code Execution via SSTI (Node.js Nunjucks)
Critical
Out of Band Code Execution via SSTI (Node.js Pug (Jade))
Out of Band Code Execution via SSTI (Node.js Pug (Jade))
Critical
Out of Band Code Execution via SSTI (PHP Smarty)
Out of Band Code Execution via SSTI (PHP Smarty)
Critical
Out of Band Code Execution via SSTI (PHP Twig)
Out of Band Code Execution via SSTI (PHP Twig)
Critical
Out of Band Code Execution via SSTI (Python Jinja)
Out of Band Code Execution via SSTI (Python Jinja)
Critical
Out of Band Code Execution via SSTI (Python Mako)
Out of Band Code Execution via SSTI (Python Mako)
Critical
Out of Band Code Execution via SSTI (Python Tornado)
Out of Band Code Execution via SSTI (Python Tornado)
Critical
Out of Band Command Injection
Out of Band Command Injection
Critical
Out of Band Remote File Inclusion
Out of Band Remote File Inclusion
Critical
Out of Band SAML Consumer Service XML Entity Injection
Out of Band SAML Consumer Service XML Entity Injection
High
Out of Band SAML Consumer Service XSLT Injection
Out of Band SAML Consumer Service XSLT Injection
High
Out of Band SQL Injection
Out of Band SQL Injection
Critical
Out of Band XML External Entity Injection
Out of Band XML External Entity Injection
High
Out-of-Date (Bootstrap Select)
Out-of-Date (Bootstrap Select)
Information
Out-of-Date (Bootstrap Table)
Out-of-Date (Bootstrap Table)
Information
Out-of-Date (Bootstrap Typeahead)
Out-of-Date (Bootstrap Typeahead)
Information
Out-of-Date (JQuery placeholder.js)
Out-of-Date (JQuery placeholder.js)
Information
Out-of-Date Version (Lua)
Out-of-Date Version (Lua)
Information
Out-of-date (ASP.NET MVC)
Out-of-date (ASP.NET MVC)
Information
Out-of-date (FrontPage)
Out-of-date (FrontPage)
Information
Out-of-date (Mongrel)
Out-of-date (Mongrel)
Information
Out-of-date (Oracle Application Server)
Out-of-date (Oracle Application Server)
Information
Out-of-date (Phusion Passenger)
Out-of-date (Phusion Passenger)
Information
Out-of-date (SharePoint)
Out-of-date (SharePoint)
Information
Out-of-date (Taleo Web Server)
Out-of-date (Taleo Web Server)
Information
Out-of-date (Varnish)
Out-of-date (Varnish)
Information
Out-of-date Component ({applicationName})
Out-of-date Component ({applicationName})
Low
1