🚀 Invicti Acquires Kondukto to Deliver Proof-Based Application Security Posture Management
100% Signal 0% Noise
Platform
Platform Overview
ASPM
APIÂ Security
DAST
SAST
SCA
Container Security
AI-Powered AppSec
Features
Solutions
Manage Vulnerabilities
Automate Security Workflows
Track AppSec KPIs
Manage Open Source Risk
Pricing
Why Invicti
About Us
Case Studies
Contact Us
Careers
Resources
Resource Library
Blog
Webinars
White Papers
Podcasts
Invicti Learn
Cost Savings Calc
Live Training
Partners
Documentation
Get a demo
Web Application Vulnerabilities Index
This page lists
144
vulnerabilities categorized as medium severity that can be detected by Invicti.
Select Category
Critical
High
Medium
Low
Best Practice
Information
Select Vulnerability
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
Vulnerability Name
Classification
Severity
markdown-it Identified
markdown-it Identified
Information
Masa CMS Identified
Masa CMS Identified
Information
Mashery Proxy Identified
Mashery Proxy Identified
Information
MathJax Identified
MathJax Identified
Information
MathJs Identified
MathJs Identified
Information
MediaWiki Detected
MediaWiki Detected
Information
Mibew Messenger Detected
Mibew Messenger Detected
Information
Microsoft Access Database File Detected
Microsoft Access Database File Detected
Medium
Microsoft IIS Log File Detected
Microsoft IIS Log File Detected
Low
Microsoft Outlook Personal Folders File (.pst) Found
Microsoft Outlook Personal Folders File (.pst) Found
Low
Mint Detected
Mint Detected
Information
Misconfigured Access-Control-Allow-Origin Header
Misconfigured Access-Control-Allow-Origin Header
Low
Misconfigured Frame
Misconfigured Frame
Low
Missing Content-Type Header
Missing Content-Type Header
Low
Missing frame-ancestors in CSP Declaration
Missing frame-ancestors in CSP Declaration
Information
Missing object-src in CSP Declaration
Missing object-src in CSP Declaration
Information
Missing X-Content-Type-Options Header
Missing X-Content-Type-Options Header
Low
Mithril Identified
Mithril Identified
Information
Modernizr Identified
Modernizr Identified
Information
Mod_Ssl Identified
Mod_Ssl Identified
Information
MODX Detected
MODX Detected
Information
Momentjs Identified
Momentjs Identified
Information
MongoDB Injection (IAST)
MongoDB Injection (IAST)
Critical
MongoDB Operator Injection
MongoDB Operator Injection
High
Mongrel Identified
Mongrel Identified
Information
Moodle Detected
Moodle Detected
Information
MOVEit Identified
MOVEit Identified
Information
Multiple Content Security Policy (CSP) Implementation Detected
Multiple Content Security Policy (CSP) Implementation Detected
Information
Mustachejs Identified
Mustachejs Identified
Information
MyBB Detected
MyBB Detected
Information
Next.js React Framework Identified
Next.js React Framework Identified
Information
Nexus Repository OSS Identified
Nexus Repository OSS Identified
Information
Nginx Web Server Identified
Nginx Web Server Identified
Information
Node.js Web Application does not handle uncaughtException
Node.js Web Application does not handle uncaughtException
Medium
Node.js Web Application does not handle unhandledRejection
Node.js Web Application does not handle unhandledRejection
Medium
Nonce Usage Detected in Content Security Policy (CSP) Directive
Nonce Usage Detected in Content Security Policy (CSP) Directive
Information
No SAML Response Signature Check
No SAML Response Signature Check
High
No Script Block Detected with the Hash Value Declared in Content Security Policy (CSP)
No Script Block Detected with the Hash Value Declared in Content Security Policy (CSP)
Information
NTLM Authorization Required
NTLM Authorization Required
Information
NuSOAP Identified
NuSOAP Identified
Information
Omeka Detected
Omeka Detected
Information
OpenCart Detected
OpenCart Detected
Information
Open Policy Crossdomain.xml Detected
Open Policy Crossdomain.xml Detected
Medium
Open Redirection
Open Redirection
Medium
Open Redirection (DOM based)
Open Redirection (DOM based)
Medium
Open Redirection in POST method
Open Redirection in POST method
Low
OpenResty Web Platform Identified
OpenResty Web Platform Identified
Information
OpenSearch.xml Detected
OpenSearch.xml Detected
Information
Open Silverlight Client Access Policy
Open Silverlight Client Access Policy
Medium
OpenSSL Heartbleed
OpenSSL Heartbleed
Critical
OpenSSL Identified
OpenSSL Identified
Information
OpenVPN Access Server Identified
OpenVPN Access Server Identified
Information
OPTIONS Method Enabled
OPTIONS Method Enabled
Information
Oracle Access Manager 'opensso' Deserialization RCE (CVE-2021-35587)
Oracle Access Manager 'opensso' Deserialization RCE (CVE-2021-35587)
High
Oracle Application Server Identified
Oracle Application Server Identified
Information
Oracle EBS - Unauthenticated Remote Code Execution
Oracle EBS - Unauthenticated Remote Code Execution
Critical
Oracle HTTP Server Identified
Oracle HTTP Server Identified
Information
Oracle WebLogic Authentication Bypass (CVE-2020-14883)
Oracle WebLogic Authentication Bypass (CVE-2020-14883)
High
Oracle WebLogic Remote Code Execution (CVE-2020-14882)
Oracle WebLogic Remote Code Execution (CVE-2020-14882)
Critical
osClass Detected
osClass Detected
Information
osCommerce Detected
osCommerce Detected
Information
osTicket Detected
osTicket Detected
Information
Out of Band Code Evaluation (Apache Struts 2)
Out of Band Code Evaluation (Apache Struts 2)
Critical
Out of Band Code Evaluation (Apache Struts 2) S2-053
Out of Band Code Evaluation (Apache Struts 2) S2-053
Critical
Out of Band Code Evaluation (ASP)
Out of Band Code Evaluation (ASP)
Critical
Out of Band Code Evaluation (Log4j)
Out of Band Code Evaluation (Log4j)
Critical
Out of Band Code Evaluation (Node.js)
Out of Band Code Evaluation (Node.js)
Critical
Out of Band Code Evaluation (Perl)
Out of Band Code Evaluation (Perl)
Critical
Out of Band Code Evaluation (PHP)
Out of Band Code Evaluation (PHP)
Critical
Out of Band Code Evaluation (Python)
Out of Band Code Evaluation (Python)
Critical
Out of Band Code Evaluation (RoR)
Out of Band Code Evaluation (RoR)
Critical
Out of Band Code Evaluation (RoR - JSON)
Out of Band Code Evaluation (RoR - JSON)
Critical
Out of Band Code Evaluation (Ruby)
Out of Band Code Evaluation (Ruby)
Critical
Out of Band Code Execution via SSTI
Out of Band Code Execution via SSTI
Critical
1