🚀 Invicti Acquires Kondukto to Deliver Proof-Based Application Security Posture Management
100% Signal 0% Noise
Platform
Platform Overview
ASPM
APIÂ Security
DAST
SAST
SCA
Container Security
AI-Powered AppSec
Features
Pricing
Why Invicti
About Us
Case Studies
Contact Us
Resources
Resource Library
Blog
Webinars
White Papers
Podcasts
Case Studies
Invicti Learn
Live Training
Partners
Documentation
Get a demo
Web Application Vulnerabilities Index
This page lists
144
vulnerabilities categorized as medium severity that can be detected by Invicti.
Select Category
Critical
High
Medium
Low
Best Practice
Information
Select Vulnerability
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
Vulnerability Name
Classification
Severity
ActiveMQ - Remote Code Execution (CVE-2023-46604)
ActiveMQ - Remote Code Execution (CVE-2023-46604)
Critical
Bash Command Injection Vulnerability (Shellshock Bug)
Bash Command Injection Vulnerability (Shellshock Bug)
Critical
Blind Command Injection
Blind Command Injection
Critical
Blind SQL Injection
Blind SQL Injection
Critical
Boolean Based SQL Injection
Boolean Based SQL Injection
Critical
CVE-2024-6297 WordPress Plugin Backdoor
CVE-2024-6297 WordPress Plugin Backdoor
Critical
Code Evaluation (ASP)
Code Evaluation (ASP)
Critical
Code Evaluation (Apache Struts S02-53)
Code Evaluation (Apache Struts S02-53)
Critical
Code Evaluation (Apache Struts)
Code Evaluation (Apache Struts)
Critical
Code Evaluation (Apache Struts) S2-016
Code Evaluation (Apache Struts) S2-016
Critical
Code Evaluation (Apache Struts) S2-045
Code Evaluation (Apache Struts) S2-045
Critical
Code Evaluation (Apache Struts) S2-046
Code Evaluation (Apache Struts) S2-046
Critical
Code Evaluation (Node.js)
Code Evaluation (Node.js)
Critical
Code Evaluation (PHP)
Code Evaluation (PHP)
Critical
Code Evaluation (PHP) - IAST
Code Evaluation (PHP) - IAST
Critical
Code Evaluation (Perl)
Code Evaluation (Perl)
Critical
Code Evaluation (Python)
Code Evaluation (Python)
Critical
Code Evaluation (RoR - JSON)
Code Evaluation (RoR - JSON)
Critical
Code Evaluation (RoR)
Code Evaluation (RoR)
Critical
Code Evaluation (Ruby)
Code Evaluation (Ruby)
Critical
Code Evaluation via Local File Inclusion (PHP)
Code Evaluation via Local File Inclusion (PHP)
Critical
Code Execution via File Upload
Code Execution via File Upload
Critical
Code Execution via Local File Inclusion
Code Execution via Local File Inclusion
Critical
Code Execution via SSTI
Code Execution via SSTI
Critical
Code Execution via SSTI (ASP.NET Razor)
Code Execution via SSTI (ASP.NET Razor)
Critical
Code Execution via SSTI (Java FreeMarker)
Code Execution via SSTI (Java FreeMarker)
Critical
Code Execution via SSTI (Java Pebble)
Code Execution via SSTI (Java Pebble)
Critical
Code Execution via SSTI (Java Velocity)
Code Execution via SSTI (Java Velocity)
Critical
Code Execution via SSTI (JinJava)
Code Execution via SSTI (JinJava)
Critical
Code Execution via SSTI (Node.js Dot)
Code Execution via SSTI (Node.js Dot)
Critical
Code Execution via SSTI (Node.js EJS)
Code Execution via SSTI (Node.js EJS)
Critical
Code Execution via SSTI (Node.js Marko)
Code Execution via SSTI (Node.js Marko)
Critical
Code Execution via SSTI (Node.js Nunjucks)
Code Execution via SSTI (Node.js Nunjucks)
Critical
Code Execution via SSTI (Node.js Pug (Jade))
Code Execution via SSTI (Node.js Pug (Jade))
Critical
Code Execution via SSTI (PHP Smarty)
Code Execution via SSTI (PHP Smarty)
Critical
Code Execution via SSTI (PHP Twig)
Code Execution via SSTI (PHP Twig)
Critical
Code Execution via SSTI (Python Jinja)
Code Execution via SSTI (Python Jinja)
Critical
Code Execution via SSTI (Python Mako)
Code Execution via SSTI (Python Mako)
Critical
Code Execution via SSTI (Python Tornado)
Code Execution via SSTI (Python Tornado)
Critical
Code Execution via SSTI (Ruby ERB)
Code Execution via SSTI (Ruby ERB)
Critical
Code Execution via SSTI (Ruby Slim)
Code Execution via SSTI (Ruby Slim)
Critical
Code Execution via WebDAV
Code Execution via WebDAV
Critical
Command Injection
Command Injection
Critical
Command Injection (IAST)
Command Injection (IAST)
Critical
Drupal Core - Remote Code Execution (CVE-2019-6340)
Drupal Core - Remote Code Execution (CVE-2019-6340)
Critical
Ivanti ICS and IPS Command Injection - CVE-2024-2188
Ivanti ICS and IPS Command Injection - CVE-2024-2188
Critical
JWT kid Parameter Out of Band Command Injection
JWT kid Parameter Out of Band Command Injection
Critical
LDAP Injection (IAST)
LDAP Injection (IAST)
Critical
Mail Header Injection (IAST)
Mail Header Injection (IAST)
Critical
Malware Identified
Malware Identified
Critical
MongoDB Injection (IAST)
MongoDB Injection (IAST)
Critical
OpenSSL Heartbleed
OpenSSL Heartbleed
Critical
Oracle EBS - Unauthenticated Remote Code Execution
Oracle EBS - Unauthenticated Remote Code Execution
Critical
Oracle WebLogic Remote Code Execution (CVE-2020-14882)
Oracle WebLogic Remote Code Execution (CVE-2020-14882)
Critical
Out of Band Code Evaluation (ASP)
Out of Band Code Evaluation (ASP)
Critical
Out of Band Code Evaluation (Apache Struts 2)
Out of Band Code Evaluation (Apache Struts 2)
Critical
Out of Band Code Evaluation (Apache Struts 2) S2-053
Out of Band Code Evaluation (Apache Struts 2) S2-053
Critical
Out of Band Code Evaluation (Log4j)
Out of Band Code Evaluation (Log4j)
Critical
Out of Band Code Evaluation (Node.js)
Out of Band Code Evaluation (Node.js)
Critical
Out of Band Code Evaluation (PHP)
Out of Band Code Evaluation (PHP)
Critical
Out of Band Code Evaluation (Perl)
Out of Band Code Evaluation (Perl)
Critical
Out of Band Code Evaluation (Python)
Out of Band Code Evaluation (Python)
Critical
Out of Band Code Evaluation (RoR - JSON)
Out of Band Code Evaluation (RoR - JSON)
Critical
Out of Band Code Evaluation (RoR)
Out of Band Code Evaluation (RoR)
Critical
Out of Band Code Evaluation (Ruby)
Out of Band Code Evaluation (Ruby)
Critical
Out of Band Code Execution via SSTI
Out of Band Code Execution via SSTI
Critical
Out of Band Code Execution via SSTI (Java FreeMarker)
Out of Band Code Execution via SSTI (Java FreeMarker)
Critical
Out of Band Code Execution via SSTI (Java Velocity)
Out of Band Code Execution via SSTI (Java Velocity)
Critical
Out of Band Code Execution via SSTI (Node.js Dot)
Out of Band Code Execution via SSTI (Node.js Dot)
Critical
Out of Band Code Execution via SSTI (Node.js EJS)
Out of Band Code Execution via SSTI (Node.js EJS)
Critical
Out of Band Code Execution via SSTI (Node.js Marko)
Out of Band Code Execution via SSTI (Node.js Marko)
Critical
Out of Band Code Execution via SSTI (Node.js Nunjucks)
Out of Band Code Execution via SSTI (Node.js Nunjucks)
Critical
Out of Band Code Execution via SSTI (Node.js Pug (Jade))
Out of Band Code Execution via SSTI (Node.js Pug (Jade))
Critical
Out of Band Code Execution via SSTI (PHP Smarty)
Out of Band Code Execution via SSTI (PHP Smarty)
Critical
1