🚀 Invicti Acquires Kondukto to Deliver Proof-Based Application Security Posture Management
100% Signal 0% Noise
Platform
Platform Overview
ASPM
APIÂ Security
DAST
SAST
SCA
Container Security
AI-Powered AppSec
Features
Solutions
Manage Vulnerabilities
Automate Security Workflows
Track AppSec KPIs
Manage Open Source Risk
Pricing
Why Invicti
About Us
Case Studies
Contact Us
Careers
Resources
Resource Library
Blog
Webinars
White Papers
Podcasts
Invicti Learn
Cost Savings Calc
Live Training
Partners
Documentation
Get a demo
Web Application Vulnerabilities Index
This page lists
144
vulnerabilities categorized as medium severity that can be detected by Invicti.
Select Category
Critical
High
Medium
Low
Best Practice
Information
Select Vulnerability
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
Vulnerability Name
Classification
Severity
Out of Band Code Execution via SSTI (Java FreeMarker)
Out of Band Code Execution via SSTI (Java FreeMarker)
Critical
Out of Band Code Execution via SSTI (Java Velocity)
Out of Band Code Execution via SSTI (Java Velocity)
Critical
Out of Band Code Execution via SSTI (Node.js Dot)
Out of Band Code Execution via SSTI (Node.js Dot)
Critical
Out of Band Code Execution via SSTI (Node.js EJS)
Out of Band Code Execution via SSTI (Node.js EJS)
Critical
Out of Band Code Execution via SSTI (Node.js Marko)
Out of Band Code Execution via SSTI (Node.js Marko)
Critical
Out of Band Code Execution via SSTI (Node.js Nunjucks)
Out of Band Code Execution via SSTI (Node.js Nunjucks)
Critical
Out of Band Code Execution via SSTI (Node.js Pug (Jade))
Out of Band Code Execution via SSTI (Node.js Pug (Jade))
Critical
Out of Band Code Execution via SSTI (PHP Smarty)
Out of Band Code Execution via SSTI (PHP Smarty)
Critical
Out of Band Code Execution via SSTI (PHP Twig)
Out of Band Code Execution via SSTI (PHP Twig)
Critical
Out of Band Code Execution via SSTI (Python Jinja)
Out of Band Code Execution via SSTI (Python Jinja)
Critical
Out of Band Code Execution via SSTI (Python Mako)
Out of Band Code Execution via SSTI (Python Mako)
Critical
Out of Band Code Execution via SSTI (Python Tornado)
Out of Band Code Execution via SSTI (Python Tornado)
Critical
Out of Band Command Injection
Out of Band Command Injection
Critical
Out of Band Remote File Inclusion
Out of Band Remote File Inclusion
Critical
Out of Band SAML Consumer Service XML Entity Injection
Out of Band SAML Consumer Service XML Entity Injection
High
Out of Band SAML Consumer Service XSLT Injection
Out of Band SAML Consumer Service XSLT Injection
High
Out of Band SQL Injection
Out of Band SQL Injection
Critical
Out of Band XML External Entity Injection
Out of Band XML External Entity Injection
High
Out-of-date (ASP.NET MVC)
Out-of-date (ASP.NET MVC)
Information
Out-of-Date (Bootstrap Select)
Out-of-Date (Bootstrap Select)
Information
Out-of-Date (Bootstrap Table)
Out-of-Date (Bootstrap Table)
Information
Out-of-Date (Bootstrap Typeahead)
Out-of-Date (Bootstrap Typeahead)
Information
Out-of-date Component ({applicationName})
Out-of-date Component ({applicationName})
Low
Out-of-date (FrontPage)
Out-of-date (FrontPage)
Information
Out-of-Date (JQuery placeholder.js)
Out-of-Date (JQuery placeholder.js)
Information
Out-of-date (Mongrel)
Out-of-date (Mongrel)
Information
Out-of-date (Oracle Application Server)
Out-of-date (Oracle Application Server)
Information
Out-of-date (Phusion Passenger)
Out-of-date (Phusion Passenger)
Information
Out-of-date (SharePoint)
Out-of-date (SharePoint)
Information
Out-of-date (Taleo Web Server)
Out-of-date (Taleo Web Server)
Information
Out-of-date (Varnish)
Out-of-date (Varnish)
Information
Out-of-date Version (AbanteCart)
Out-of-date Version (AbanteCart)
Information
Out-of-date Version (Ampache)
Out-of-date Version (Ampache)
Information
Out-of-date Version (Angular)
Out-of-date Version (Angular)
Information
Out-of-date Version (AngularJS)
Out-of-date Version (AngularJS)
Information
Out-of-date Version (Apache)
Out-of-date Version (Apache)
Information
Out-of-date Version (Apache Coyote)
Out-of-date Version (Apache Coyote)
Information
Out-of-date Version (Apache Traffic Server)
Out-of-date Version (Apache Traffic Server)
Information
Out-of-date Version (Artifactory DevOps Solution)
Out-of-date Version (Artifactory DevOps Solution)
Information
Out-of-date Version (ASP.NET SignalR)
Out-of-date Version (ASP.NET SignalR)
Information
Out-of-date Version (Atlassian Confluence)
Out-of-date Version (Atlassian Confluence)
Information
Out-of-date Version (Atlassian Jira)
Out-of-date Version (Atlassian Jira)
Information
Out-of-date Version (Atlassian Proxy)
Out-of-date Version (Atlassian Proxy)
Information
Out-of-date Version (ATutor)
Out-of-date Version (ATutor)
Information
Out-of-date Version (axios)
Out-of-date Version (axios)
Information
Out-of-date Version (Axway SecureTransport Server)
Out-of-date Version (Axway SecureTransport Server)
Information
Out-of-date Version (b2evolution)
Out-of-date Version (b2evolution)
Information
Out-of-date Version (Backbone.js)
Out-of-date Version (Backbone.js)
Information
Out-of-date Version (bluebird)
Out-of-date Version (bluebird)
Information
Out-of-date Version (Bootbox.js)
Out-of-date Version (Bootbox.js)
Information
Out-of-date Version (Bootstrap)
Out-of-date Version (Bootstrap)
Information
Out-of-date Version (Bootstrap 3 Date/Time Picker)
Out-of-date Version (Bootstrap 3 Date/Time Picker)
Information
Out-of-date Version (Bootstrap Toggle)
Out-of-date Version (Bootstrap Toggle)
Information
Out-of-date Version (CakePHP Framework)
Out-of-date Version (CakePHP Framework)
Information
Out-of-date Version (CanvasJS)
Out-of-date Version (CanvasJS)
Information
Out-of-date Version (Chamilo)
Out-of-date Version (Chamilo)
Information
Out-of-date Version (Chart.js)
Out-of-date Version (Chart.js)
Information
Out-of-date Version (Cherokee)
Out-of-date Version (Cherokee)
Information
Out-of-date Version (CherryPy)
Out-of-date Version (CherryPy)
Information
Out-of-date Version (CKEditor)
Out-of-date Version (CKEditor)
Information
Out-of-date Version (Claroline)
Out-of-date Version (Claroline)
Information
Out-of-date Version (ClipBucket)
Out-of-date Version (ClipBucket)
Information
Out-of-date Version (Collabtive)
Out-of-date Version (Collabtive)
Information
Out-of-date Version (Concerte5)
Out-of-date Version (Concerte5)
Information
Out-of-date Version (contao)
Out-of-date Version (contao)
Information
Out-of-date Version (cookieconsent2)
Out-of-date Version (cookieconsent2)
Information
Out-of-date Version (Coppermine)
Out-of-date Version (Coppermine)
Information
Out-of-date Version (Cowboy HTTP Server)
Out-of-date Version (Cowboy HTTP Server)
Information
Out-of-date Version (CubeCart)
Out-of-date Version (CubeCart)
Information
Out-of-date Version (D3.js)
Out-of-date Version (D3.js)
Information
Out-of-date Version (Daiquiri)
Out-of-date Version (Daiquiri)
Information
Out-of-date Version (DataTables)
Out-of-date Version (DataTables)
Information
Out-of-date Version (Django)
Out-of-date Version (Django)
Information
Out-of-date Version (Dojo)
Out-of-date Version (Dojo)
Information
1