🚀 Invicti Acquires Kondukto to Deliver Proof-Based Application Security Posture Management
100% Signal 0% Noise
Platform
Platform Overview
ASPM
APIÂ Security
DAST
SAST
SCA
Container Security
AI-Powered AppSec
Features
Pricing
Why Invicti
About Us
Case Studies
Contact Us
Resources
Resource Library
Blog
Webinars
White Papers
Podcasts
Case Studies
Invicti Learn
Live Training
Partners
Documentation
Get a demo
Web Application Vulnerabilities Index
This page lists
144
vulnerabilities categorized as medium severity that can be detected by Invicti.
Select Category
Critical
High
Medium
Low
Best Practice
Information
Select Vulnerability
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
Vulnerability Name
Classification
Severity
Sensitive Data Exposure - Jenkins Secret
Sensitive Data Exposure - Jenkins Secret
Medium
Sensitive Data Exposure - LinkedIn API Key
Sensitive Data Exposure - LinkedIn API Key
Medium
Sensitive Data Exposure - MailChimp API Key
Sensitive Data Exposure - MailChimp API Key
Medium
Sensitive Data Exposure - MailGun API Key
Sensitive Data Exposure - MailGun API Key
Medium
Sensitive Data Exposure - Mapbox Token
Sensitive Data Exposure - Mapbox Token
Medium
Sensitive Data Exposure - NPM Access Token
Sensitive Data Exposure - NPM Access Token
Medium
Sensitive Data Exposure - Nexmo Secret
Sensitive Data Exposure - Nexmo Secret
Medium
Sensitive Data Exposure - NuGet API Key
Sensitive Data Exposure - NuGet API Key
Medium
Sensitive Data Exposure - Okta Secret Key
Sensitive Data Exposure - Okta Secret Key
Medium
Sensitive Data Exposure - Omise Secret Key
Sensitive Data Exposure - Omise Secret Key
Medium
Sensitive Data Exposure - Paypal Access Token
Sensitive Data Exposure - Paypal Access Token
Medium
Sensitive Data Exposure - Picatic API key
Sensitive Data Exposure - Picatic API key
Medium
Sensitive Data Exposure - SSH Key
Sensitive Data Exposure - SSH Key
Medium
Sensitive Data Exposure - SendGrid API Key
Sensitive Data Exposure - SendGrid API Key
Medium
Sensitive Data Exposure - Sentry Auth Token
Sensitive Data Exposure - Sentry Auth Token
Medium
Sensitive Data Exposure - Slack Token
Sensitive Data Exposure - Slack Token
Medium
Sensitive Data Exposure - Slack Webhook
Sensitive Data Exposure - Slack Webhook
Medium
Sensitive Data Exposure - Slack v1.x Token
Sensitive Data Exposure - Slack v1.x Token
Medium
Sensitive Data Exposure - SonarQube User Token
Sensitive Data Exposure - SonarQube User Token
Medium
Sensitive Data Exposure - Square OAuth Secret
Sensitive Data Exposure - Square OAuth Secret
Medium
Sensitive Data Exposure - Square Personal Access Token
Sensitive Data Exposure - Square Personal Access Token
Medium
Sensitive Data Exposure - Stripe API key
Sensitive Data Exposure - Stripe API key
Medium
Sensitive Data Exposure - Symfony Application Secret
Sensitive Data Exposure - Symfony Application Secret
Medium
Sensitive Data Exposure - Teams Webhook
Sensitive Data Exposure - Teams Webhook
Medium
Sensitive Data Exposure - Telegram Bot API Token
Sensitive Data Exposure - Telegram Bot API Token
Medium
Sensitive Data Exposure - Twilio API Key
Sensitive Data Exposure - Twilio API Key
Medium
Sensitive Data Exposure - Twitter API Secret Key
Sensitive Data Exposure - Twitter API Secret Key
Medium
Sensitive Data Exposure - Twitter Access Token Secret
Sensitive Data Exposure - Twitter Access Token Secret
Medium
Sensitive Data Exposure - WordPress Authentication Key/Salt
Sensitive Data Exposure - WordPress Authentication Key/Salt
Medium
Server-Side Request Forgery
Server-Side Request Forgery
Medium
Server-Side Request Forgery (Time Based)
Server-Side Request Forgery (Time Based)
Medium
Session Cookie Not Marked as Secure
Session Cookie Not Marked as Secure
Medium
Source Code Disclosure (ASP.NET)
Source Code Disclosure (ASP.NET)
Medium
Source Code Disclosure (ColdFusion)
Source Code Disclosure (ColdFusion)
Medium
Source Code Disclosure (Generic)
Source Code Disclosure (Generic)
Medium
Source Code Disclosure (JSP)
Source Code Disclosure (JSP)
Medium
Source Code Disclosure (Java Servlet)
Source Code Disclosure (Java Servlet)
Medium
Source Code Disclosure (Java)
Source Code Disclosure (Java)
Medium
Source Code Disclosure (PHP)
Source Code Disclosure (PHP)
Medium
Source Code Disclosure (Perl)
Source Code Disclosure (Perl)
Medium
Source Code Disclosure (Python)
Source Code Disclosure (Python)
Medium
Source Code Disclosure (Ruby)
Source Code Disclosure (Ruby)
Medium
Source Code Disclosure (Tomcat)
Source Code Disclosure (Tomcat)
Medium
Spring Boot Actuator Endpoint Detected
Spring Boot Actuator Endpoint Detected
Medium
Spring Boot Misconfiguration: Actuator endpoint security disabled
Spring Boot Misconfiguration: Actuator endpoint security disabled
Medium
Spring Boot Misconfiguration: Admin MBean enabled
Spring Boot Misconfiguration: Admin MBean enabled
Medium
Spring Boot Misconfiguration: All Spring Boot Actuator endpoints are web exposed
Spring Boot Misconfiguration: All Spring Boot Actuator endpoints are web exposed
Medium
Spring Boot Misconfiguration: Datasource credentials stored in the properties file
Spring Boot Misconfiguration: Datasource credentials stored in the properties file
Medium
Spring Boot Misconfiguration: Developer tools enabled on production
Spring Boot Misconfiguration: Developer tools enabled on production
Medium
Spring Boot Misconfiguration: H2 console enabled
Spring Boot Misconfiguration: H2 console enabled
Medium
Spring Boot Misconfiguration: MongoDB credentials stored in the properties file
Spring Boot Misconfiguration: MongoDB credentials stored in the properties file
Medium
Spring Boot Misconfiguration: Overly long session timeout
Spring Boot Misconfiguration: Overly long session timeout
Medium
Spring Boot Misconfiguration: Spring Boot Actuator shutdown endpoint is web exposed
Spring Boot Misconfiguration: Spring Boot Actuator shutdown endpoint is web exposed
Medium
Spring Boot Misconfiguration: Unsafe value for session tracking
Spring Boot Misconfiguration: Unsafe value for session tracking
Medium
Spring Misconfiguration: HTML Escaping disabled
Spring Misconfiguration: HTML Escaping disabled
Medium
Stack Trace Disclosure (ColdFusion)
Stack Trace Disclosure (ColdFusion)
Medium
Stack Trace Disclosure (Django)
Stack Trace Disclosure (Django)
Medium
Stack Trace Disclosure (Java)
Stack Trace Disclosure (Java)
Medium
Stack Trace Disclosure (Laravel)
Stack Trace Disclosure (Laravel)
Medium
Stack Trace Disclosure (Python)
Stack Trace Disclosure (Python)
Medium
Stack Trace Disclosure (RoR)
Stack Trace Disclosure (RoR)
Medium
Stack Trace Disclosure (Ruby-Sinatra Framework)
Stack Trace Disclosure (Ruby-Sinatra Framework)
Medium
Struts 2 Config Browser plugin enabled
Struts 2 Config Browser plugin enabled
Medium
Struts 2 Development Mode Enabled
Struts 2 Development Mode Enabled
Medium
Sublime SFTP Config File Detected
Sublime SFTP Config File Detected
Medium
TLS/SSL Certificate Key Size Too Small
TLS/SSL Certificate Key Size Too Small
Medium
Unicode Transformation (Best-Fit Mapping)
Unicode Transformation (Best-Fit Mapping)
Medium
Unsafe value for session tracking in WEB-INF/web.xml
Unsafe value for session tracking in WEB-INF/web.xml
Medium
ViewState MAC Disabled
ViewState MAC Disabled
Medium
Weak Ciphers Enabled
Weak Ciphers Enabled
Medium
WordPress Setup Configuration File
WordPress Setup Configuration File
Medium
ZSH History File Detected
ZSH History File Detected
Medium
1