🚀 Just released:
Latio 2026 Application Security Market Report.
Read it in our Whitepapers.
100% Signal 0% Noise
Platform
Invicti Platform
Zero-noise AppSec platform
Scan Code
Secure code before runtime
SAST
Early static security analysis
Open Source (SCA)
Find vulnerable dependencies
SBOM & License Risk
Generate SBOMs and track licenses
Secrets
Detect exposed secrets in applications
Infrastructure as Code
Ingest IaC security findings
Container
Track container image vulnerabilities
Test Runtime
Test live applications like attackers
DAST & AI DAST
Test runtime, prove exploitability
Agentic Pentesting
Automate real-world attack techniques
API Security Testing
Discover and test APIs
Attack Surface Management
Identify exposed apps and endpoints
Cloud AppSec
Get a single-pane view of cloud app risk
AI AppSec
Scan smarter, accelerate remediation
Manage Vulnerabilities
See, prioritize, reduce AppSec risk
Vulnerability Management (ASPM)
Centralize and correlate AppSec findings
Compliance & Executive Reporting
Measure risk and impact
Threat Intelligence
Reachability, exploitability, and business logic
Solutions
API Discovery
Manage Vulnerabilities
Automate Security Workflows
Track AppSec KPIs
Manage Open Source Risk
Pricing
Why Invicti
About Us
Case Studies
Contact Us
Careers
Resources
Resource Library
Blog
Webinars
White Papers
Podcasts
Invicti Learn
Savings Calculator
Live Training
Partners
Documentation
Get a demo
Home
/
Web Application Vulnerabilities
Web Application Vulnerabilities
Runtime SCA Findings
Looking for the vulnerability index of Invicti's legacy products?
Invicti Enterprise
Acunetix Standard & Premium
v.26.4.2314
Web Application Vulnerabilities
This page lists
24254 vulnerabilities
in
62 categories
.
Critical: 1581
High: 13032
Medium: 8704
Low: 868
Information: 69
Vulnerability Name
CVE
CWE
Severity
Drupal Core 9.3.x Security Bypass (9.3.0 - 9.3.13)
CVE-2022-29248
CWE-264
High
Drupal Core 9.3.x Security Bypass (9.3.0 - 9.3.15)
CVE-2022-31043
CWE-284
High
Drupal Core 9.3.x Security Bypass (9.3.0 - 9.3.18)
CVE-2022-25278
CWE-264
High
Drupal Core 9.3.x Security Bypass (9.3.0 - 9.3.5)
CVE-2022-25271
CWE-20
High
Drupal Core 9.3.x Security Bypass (9.3.0 - 9.3.8)
CVE-2022-24775
CWE-20
High
Drupal Core 9.4.x Cross-Site Scripting (9.4.0 - 9.4.2)
CVE-2022-25276
CWE-79
High
Drupal Core 9.4.x Remote Code Execution (9.4.0 - 9.4.2)
CVE-2022-25277
CWE-434
High
Drupal Core 9.4.x Security Bypass (9.4.0 - 9.4.2)
CVE-2022-25275
CWE-264
High
Drupal Core Cross-Site Scripting (8.0.0 - 9.1.15)
CVE-2021-41184
CWE-79
High
Drupal Core Cross-Site Scripting (8.0.0 - 9.2.21)
CVE-2022-25276
CWE-79
High
Drupal Core Multiple Vulnerabilities (8.0.0 - 9.1.15)
CVE-2022-24729
CWE-400
High
Drupal Core Open Redirect
-
CWE-601
Low
Drupal Core Remote Code Execution (8.0.0 - 9.2.21)
CVE-2022-25277
CWE-434
High
Drupal Core Security Bypass (8.0.0 - 9.1.15)
CVE-2022-24775
CWE-20
High
Drupal Core Security Bypass (8.0.0 - 9.2.21)
CVE-2022-25275
CWE-264
High
Drupal Credentials Management Errors Vulnerability (CVE-2009-2374)
CVE-2009-2374
-
Medium
Drupal Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2007-5594)
CVE-2007-5594
CWE-352
Medium
Drupal Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2007-6752)
CVE-2007-6752
CWE-352
Medium
Drupal Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2008-0272)
CVE-2008-0272
CWE-352
Medium
Drupal Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2008-3220)
CVE-2008-3220
CWE-352
Medium
Drupal Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2008-3221)
CVE-2008-3221
CWE-352
Medium
Drupal Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2008-3743)
CVE-2008-3743
CWE-352
Medium
Drupal Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2008-3744)
CVE-2008-3744
CWE-352
Medium
Drupal Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2008-6532)
CVE-2008-6532
CWE-352
Medium
Drupal Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2009-4066)
CVE-2009-4066
CWE-352
Medium
Drupal Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2012-0826)
CVE-2012-0826
CWE-352
Medium
Drupal Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2015-6660)
CVE-2015-6660
CWE-352
Medium
Drupal Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2017-6379)
CVE-2017-6379
CWE-352
High
Drupal Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2020-13663)
CVE-2020-13663
CWE-352
High
Drupal Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2020-13674)
CVE-2020-13674
CWE-352
Medium
Drupal Cryptographic Issues Vulnerability (CVE-2013-6386)
CVE-2013-6386
-
Medium
Drupal CVE-2007-0626 Vulnerability (CVE-2007-0626)
CVE-2007-0626
-
Medium
Drupal CVE-2008-1729 Vulnerability (CVE-2008-1729)
CVE-2008-1729
-
Medium
Drupal CVE-2008-4793 Vulnerability (CVE-2008-4793)
CVE-2008-4793
-
High
Drupal CVE-2009-1576 Vulnerability (CVE-2009-1576)
CVE-2009-1576
-
Medium
Drupal CVE-2009-3352 Vulnerability (CVE-2009-3352)
CVE-2009-3352
-
Critical
Drupal CVE-2014-1475 Vulnerability (CVE-2014-1475)
CVE-2014-1475
-
High
Drupal CVE-2014-9016 Vulnerability (CVE-2014-9016)
CVE-2014-9016
-
Medium
Drupal CVE-2017-6919 Vulnerability (CVE-2017-6919)
CVE-2017-6919
-
High
Drupal CVE-2017-6925 Vulnerability (CVE-2017-6925)
CVE-2017-6925
-
Critical
Drupal CVE-2017-6930 Vulnerability (CVE-2017-6930)
CVE-2017-6930
-
High
Drupal CVE-2018-14773 Vulnerability (CVE-2018-14773)
CVE-2018-14773
-
Medium
Drupal CVE-2018-7602 Vulnerability (CVE-2018-7602)
CVE-2018-7602
-
Critical
Drupal CVE-2020-13665 Vulnerability (CVE-2020-13665)
CVE-2020-13665
-
Critical
Drupal CVE-2020-28949 Vulnerability (CVE-2020-28949)
CVE-2020-28949
-
High
Drupal CVE-2022-25278 Vulnerability (CVE-2022-25278)
CVE-2022-25278
-
Medium
Drupal Data Processing Errors Vulnerability (CVE-2016-3171)
CVE-2016-3171
-
High
Drupal Data Processing Errors Vulnerability (CVE-2017-6920)
CVE-2017-6920
-
Critical
Drupal Deserialization of Untrusted Data Vulnerability (CVE-2019-6338)
CVE-2019-6338
CWE-502
High
Drupal Deserialization of Untrusted Data Vulnerability (CVE-2019-6340)
CVE-2019-6340
CWE-502
High
Drupal Deserialization of Untrusted Data Vulnerability (CVE-2020-28948)
CVE-2020-28948
CWE-502
High
Drupal Deserialization of Untrusted Data Vulnerability (CVE-2024-55636)
CVE-2024-55636
CWE-502
Critical
Drupal Deserialization of Untrusted Data Vulnerability (CVE-2024-55637)
CVE-2024-55637
CWE-502
Critical
Drupal Deserialization of Untrusted Data Vulnerability (CVE-2024-55638)
CVE-2024-55638
CWE-502
Critical
Drupal Exposure of Resource to Wrong Sphere Vulnerability (CVE-2020-13670)
CVE-2020-13670
CWE-668
High
Drupal Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2011-3730)
CVE-2011-3730
CWE-200
Medium
Drupal Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2012-0825)
CVE-2012-0825
CWE-200
Medium
Drupal Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2012-2922)
CVE-2012-2922
CWE-200
Medium
Drupal Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2012-5652)
CVE-2012-5652
CWE-200
Medium
Drupal Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2014-2983)
CVE-2014-2983
CWE-200
Medium
Drupal Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2015-3231)
CVE-2015-3231
CWE-200
Medium
Drupal Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2015-6661)
CVE-2015-6661
CWE-200
Medium
Drupal Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2016-3170)
CVE-2016-3170
CWE-200
Medium
Drupal Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2016-6212)
CVE-2016-6212
CWE-200
Medium
Drupal Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2016-9449)
CVE-2016-9449
CWE-200
Medium
Drupal Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2017-6926)
CVE-2017-6926
CWE-200
High
Drupal Files or Directories Accessible to External Parties Vulnerability (CVE-2017-6922)
CVE-2017-6922
CWE-552
Medium
Drupal Improper Access Control Vulnerability (CVE-2015-2559)
CVE-2015-2559
CWE-284
Low
Drupal Improper Access Control Vulnerability (CVE-2016-3162)
CVE-2016-3162
CWE-284
High
Drupal Improper Access Control Vulnerability (CVE-2016-3165)
CVE-2016-3165
CWE-284
High
Drupal Improper Access Control Vulnerability (CVE-2016-5385)
CVE-2016-5385
CWE-284
High
Drupal Improper Access Control Vulnerability (CVE-2020-13677)
CVE-2020-13677
CWE-284
High
Drupal Improper Authentication Vulnerability (CVE-2006-1228)
CVE-2006-1228
CWE-287
Medium
Drupal Improper Authentication Vulnerability (CVE-2010-3091)
CVE-2010-3091
CWE-287
Medium
Drupal Improper Authentication Vulnerability (CVE-2010-3685)
CVE-2010-3685
CWE-287
Medium
«
1
...
33
34
35
...
324
»