🚀 Invicti Acquires Kondukto to Deliver Proof-Based Application Security Posture Management
100% Signal 0% Noise
Platform
Platform Overview
ASPM
APIÂ Security
DAST
SAST
SCA
Container Security
AI-Powered AppSec
Features
Pricing
Why Invicti
About Us
Case Studies
Contact Us
Resources
Resource Library
Blog
Webinars
White Papers
Podcasts
Case Studies
Invicti Learn
Live Training
Partners
Documentation
Get a demo
Web Application Vulnerabilities Index
This page lists
144
vulnerabilities categorized as medium severity that can be detected by Invicti.
Select Category
Critical
High
Medium
Low
Best Practice
Information
Select Vulnerability
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
Vulnerability Name
Classification
Severity
ASP.NET Cookieless Authentication Is Enabled
ASP.NET Cookieless Authentication Is Enabled
Medium
ASP.NET Cookieless Session State Is Enabled
ASP.NET Cookieless Session State Is Enabled
Medium
ASP.NET CustomErrors Is Disabled
ASP.NET CustomErrors Is Disabled
Medium
ASP.NET Login Credentials Stored In Plain Text
ASP.NET Login Credentials Stored In Plain Text
Medium
ASP.NET ValidateRequest Is Globally Disabled
ASP.NET ValidateRequest Is Globally Disabled
Medium
ASP.NET: Failure To Require SSL For Authentication Cookies
ASP.NET: Failure To Require SSL For Authentication Cookies
Medium
Active Mixed Content over HTTPS
Active Mixed Content over HTTPS
Medium
Anonymous Ciphers Supported
Anonymous Ciphers Supported
Medium
Apache Server-Info Detected
Apache Server-Info Detected
Medium
Apache Server-Status Detected
Apache Server-Status Detected
Medium
Axis Development Mode Enabled in WEB-INF/server-config.wsdd
Axis Development Mode Enabled in WEB-INF/server-config.wsdd
Medium
Axis system configuration listing enabled in WEB-INF/server-config.wsdd
Axis system configuration listing enabled in WEB-INF/server-config.wsdd
Medium
B.R.E.A.C.H. Attack Detected
B.R.E.A.C.H. Attack Detected
Medium
BREACH Attack Detected
BREACH Attack Detected
Medium
Base Tag Hijacking
Base Tag Hijacking
Medium
CVS Detected
CVS Detected
Medium
Critical Form Send to HTTP
Critical Form Send to HTTP
Medium
Critical Form Served over HTTP
Critical Form Served over HTTP
Medium
Custom Error Pages Are Not Configured in WEB-INF/web.xml
Custom Error Pages Are Not Configured in WEB-INF/web.xml
Medium
Expired SSL Certificate
Expired SSL Certificate
Medium
Express Development Mode Is Enabled
Express Development Mode Is Enabled
Medium
Express express-session Weak Secret Key Detected
Express express-session Weak Secret Key Detected
Medium
Frame Injection
Frame Injection
Medium
GIT Detected
GIT Detected
Medium
HTTP Header Injection
HTTP Header Injection
Medium
HTTP Header Injection (IAST)
HTTP Header Injection (IAST)
Medium
HTTP Parameter Pollution
HTTP Parameter Pollution
Medium
HTTP Strict Transport Security (HSTS) Errors and Warnings
HTTP Strict Transport Security (HSTS) Errors and Warnings
Medium
HTTP Strict Transport Security (HSTS) Policy Not Enabled
HTTP Strict Transport Security (HSTS) Policy Not Enabled
Medium
Insecure HTTP Usage
Insecure HTTP Usage
Medium
Invalid SSL Certificate
Invalid SSL Certificate
Medium
Java Verb Tampering Via Misconfigured Security Constraint
Java Verb Tampering Via Misconfigured Security Constraint
Medium
JavaMelody Interface Detected
JavaMelody Interface Detected
Medium
JetBrains .idea Project Directory Detected
JetBrains .idea Project Directory Detected
Medium
Microsoft Access Database File Detected
Microsoft Access Database File Detected
Medium
Node.js Web Application does not handle uncaughtException
Node.js Web Application does not handle uncaughtException
Medium
Node.js Web Application does not handle unhandledRejection
Node.js Web Application does not handle unhandledRejection
Medium
Open Policy Crossdomain.xml Detected
Open Policy Crossdomain.xml Detected
Medium
Open Redirection
Open Redirection
Medium
Open Redirection (DOM based)
Open Redirection (DOM based)
Medium
Open Silverlight Client Access Policy
Open Silverlight Client Access Policy
Medium
Overly Long Session Timeout
Overly Long Session Timeout
Medium
PHP enable_dl Is Enabled
PHP enable_dl Is Enabled
Medium
PHP magic_quotes_gpc Is Disabled
PHP magic_quotes_gpc Is Disabled
Medium
PHP register_globals Is Enabled
PHP register_globals Is Enabled
Medium
PHP session.use_only_cookies Is Disabled
PHP session.use_only_cookies Is Disabled
Medium
PHP session.use_trans_sid Is Enabled
PHP session.use_trans_sid Is Enabled
Medium
Password Transmitted over Query String
Password Transmitted over Query String
Medium
RSA Private Key Detected
RSA Private Key Detected
Medium
Revoked SSL Certificate
Revoked SSL Certificate
Medium
SAML Consumer Service KeyInfo RetrievalMethod SSRF
SAML Consumer Service KeyInfo RetrievalMethod SSRF
Medium
SAML Consumer Service XSS Vulnerability
SAML Consumer Service XSS Vulnerability
Medium
SQLite Database File Found
SQLite Database File Found
Medium
SSL Certificate Is About To Expire
SSL Certificate Is About To Expire
Medium
SSL Certificate Name Hostname Mismatch
SSL Certificate Name Hostname Mismatch
Medium
SSL Untrusted Root Certificate
SSL Untrusted Root Certificate
Medium
SSL/TLS Not Implemented
SSL/TLS Not Implemented
Medium
Sensitive Data Exposure
Sensitive Data Exposure
Medium
Sensitive Data Exposure - Amazon AWS Access Key Id
Sensitive Data Exposure - Amazon AWS Access Key Id
Medium
Sensitive Data Exposure - Amazon AWS Secret Key
Sensitive Data Exposure - Amazon AWS Secret Key
Medium
Sensitive Data Exposure - Amazon MWS Auth Token
Sensitive Data Exposure - Amazon MWS Auth Token
Medium
Sensitive Data Exposure - Amazon SES SMTP Password
Sensitive Data Exposure - Amazon SES SMTP Password
Medium
Sensitive Data Exposure - Consul Token
Sensitive Data Exposure - Consul Token
Medium
Sensitive Data Exposure - Database Connection String - MongoDB - MySQL
Sensitive Data Exposure - Database Connection String - MongoDB - MySQL
Medium
Sensitive Data Exposure - Database Connection String - PostgreSQL
Sensitive Data Exposure - Database Connection String - PostgreSQL
Medium
Sensitive Data Exposure - Devise Secret Key
Sensitive Data Exposure - Devise Secret Key
Medium
Sensitive Data Exposure - Facebook Access Token
Sensitive Data Exposure - Facebook Access Token
Medium
Sensitive Data Exposure - Facebook App ID
Sensitive Data Exposure - Facebook App ID
Medium
Sensitive Data Exposure - Facebook App Secret
Sensitive Data Exposure - Facebook App Secret
Medium
Sensitive Data Exposure - Gitlab Personal Access Token
Sensitive Data Exposure - Gitlab Personal Access Token
Medium
Sensitive Data Exposure - Google Cloud API Key
Sensitive Data Exposure - Google Cloud API Key
Medium
Sensitive Data Exposure - Google OAuth Access Token
Sensitive Data Exposure - Google OAuth Access Token
Medium
Sensitive Data Exposure - Heroku API Key
Sensitive Data Exposure - Heroku API Key
Medium
Sensitive Data Exposure - JDBC Database Connection String
Sensitive Data Exposure - JDBC Database Connection String
Medium
1