🚀 Just released:
Latio 2026 Application Security Market Report.
Read it in our Whitepapers.
100% Signal 0% Noise
Platform
Invicti Platform
Zero-noise AppSec platform
Scan Code
Secure code before runtime
SAST
Early static security analysis
Open Source (SCA)
Find vulnerable dependencies
SBOM & License Risk
Generate SBOMs and track licenses
Secrets
Detect exposed secrets in applications
Infrastructure as Code
Ingest IaC security findings
Container
Track container image vulnerabilities
Test Runtime
Test live applications like attackers
DAST & AI DAST
Test runtime, prove exploitability
Agentic Pentesting
Automate real-world attack techniques
API Security Testing
Discover and test APIs
Attack Surface Management
Identify exposed apps and endpoints
Cloud AppSec
Get a single-pane view of cloud app risk
AI AppSec
Scan smarter, accelerate remediation
Manage Vulnerabilities
See, prioritize, reduce AppSec risk
Vulnerability Management (ASPM)
Centralize and correlate AppSec findings
Compliance & Executive Reporting
Measure risk and impact
Threat Intelligence
Reachability, exploitability, and business logic
Solutions
API Discovery
Manage Vulnerabilities
Automate Security Workflows
Track AppSec KPIs
Manage Open Source Risk
Pricing
Why Invicti
About Us
Case Studies
Contact Us
Careers
Resources
Resource Library
Blog
Webinars
White Papers
Podcasts
Invicti Learn
Savings Calculator
Live Training
Partners
Documentation
Get a demo
Home
/
Web Application Vulnerabilities
/ High Severity
Web Application Vulnerabilities
Runtime SCA Findings
Looking for the vulnerability index of Invicti's legacy products?
Invicti Enterprise
Acunetix Standard & Premium
v.26.4.2314
High Severity Vulnerabilities
Found
13053 vulnerabilities
at
High
severity.
Vulnerability Name
CVE
CWE
Severity
MySQL Use of Externally-Controlled Format String Vulnerability (CVE-2009-2446)
CVE-2009-2446
CWE-134
High
Nginx Out-of-bounds Write Vulnerability (CVE-2009-2629)
CVE-2009-2629
CWE-787
High
Apache HTTP Server Improper Locking Vulnerability (CVE-2009-2699)
CVE-2009-2699
CWE-667
High
WordPress Credentials Management Errors Vulnerability (CVE-2009-2762)
CVE-2009-2762
-
High
Piwigo Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Vulnerability (CVE-2009-2933)
CVE-2009-2933
CWE-138
High
SugarCRM Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Vulnerability (CVE-2009-2978)
CVE-2009-2978
CWE-138
High
PHP Improper Input Validation Vulnerability (CVE-2009-3291)
CVE-2009-3291
CWE-20
High
PHP CVE-2009-3292 Vulnerability (CVE-2009-3292)
CVE-2009-3292
-
High
PHP CVE-2009-3293 Vulnerability (CVE-2009-3293)
CVE-2009-3293
-
High
Apache Tomcat Credentials Management Errors Vulnerability (CVE-2009-3548)
CVE-2009-3548
-
High
PHP CVE-2009-3559 Vulnerability (CVE-2009-3559)
CVE-2009-3559
-
High
TYPO3 Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2009-3631)
CVE-2009-3631
CWE-94
High
phpMyAdmin Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Vulnerability (CVE-2009-3697)
CVE-2009-3697
CWE-138
High
CubeCart Permissions, Privileges, and Access Controls Vulnerability (CVE-2009-3904)
CVE-2009-3904
CWE-264
High
XOOPS CVE-2009-3963 Vulnerability (CVE-2009-3963)
CVE-2009-3963
-
High
PHP Permissions, Privileges, and Access Controls Vulnerability (CVE-2009-4018)
CVE-2009-4018
CWE-264
High
Frontaccounting Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Vulnerability (CVE-2009-4037)
CVE-2009-4037
CWE-138
High
Frontaccounting Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Vulnerability (CVE-2009-4045)
CVE-2009-4045
CWE-138
High
CubeCart Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Vulnerability (CVE-2009-4060)
CVE-2009-4060
CWE-138
High
e107 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Vulnerability (CVE-2009-4084)
CVE-2009-4084
CWE-138
High
Moodle Credentials Management Errors Vulnerability (CVE-2009-4304)
CVE-2009-4304
-
High
ZenCart Other Vulnerability (CVE-2009-4323)
CVE-2009-4323
-
High
Trac CVE-2009-4405 Vulnerability (CVE-2009-4405)
CVE-2009-4405
-
High
MySQL Out-of-bounds Write Vulnerability (CVE-2009-4484)
CVE-2009-4484
CWE-787
High
Zenphoto Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Vulnerability (CVE-2009-4566)
CVE-2009-4566
CWE-138
High
TYPO3 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Vulnerability (CVE-2009-4855)
CVE-2009-4855
CWE-138
High
Jetty Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2009-5045)
CVE-2009-5045
CWE-200
High
Ruby Improper Input Validation Vulnerability (CVE-2009-5147)
CVE-2009-5147
CWE-20
High
osTicket Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Vulnerability (CVE-2010-0605)
CVE-2010-0605
CWE-138
High
OpenSSL Cryptographic Issues Vulnerability (CVE-2010-0742)
CVE-2010-0742
-
High
Oracle Database Server CVE-2010-0853 Vulnerability (CVE-2010-0853)
CVE-2010-0853
-
High
Oracle Database Server CVE-2010-0860 Vulnerability (CVE-2010-0860)
CVE-2010-0860
-
High
Oracle Database Server CVE-2010-0903 Vulnerability (CVE-2010-0903)
CVE-2010-0903
-
High
Oracle Database Server CVE-2010-0911 Vulnerability (CVE-2010-0911)
CVE-2010-0911
-
High
Opencart Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Vulnerability (CVE-2010-0956)
CVE-2010-0956
CWE-138
High
PHP Improper Input Validation Vulnerability (CVE-2010-1129)
CVE-2010-1129
CWE-20
High
PostgreSQL Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2010-1169)
CVE-2010-1169
CWE-94
High
Internet Information Services Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2010-1256)
CVE-2010-1256
CWE-94
High
Joomla Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2010-1432)
CVE-2010-1432
CWE-200
High
Joomla Session Fixation Vulnerability (CVE-2010-1434)
CVE-2010-1434
CWE-384
High
PostgreSQL Permissions, Privileges, and Access Controls Vulnerability (CVE-2010-1447)
CVE-2010-1447
CWE-264
High
Python Integer Overflow or Wraparound Vulnerability (CVE-2010-1449)
CVE-2010-1449
CWE-190
High
Python Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') Vulnerability (CVE-2010-1450)
CVE-2010-1450
CWE-120
High
Moodle Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Vulnerability (CVE-2010-1615)
CVE-2010-1615
CWE-138
High
phpBB CVE-2010-1630 Vulnerability (CVE-2010-1630)
CVE-2010-1630
-
High
PHP Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2010-1868)
CVE-2010-1868
CWE-94
High
Serendipity Permissions, Privileges, and Access Controls Vulnerability (CVE-2010-1916)
CVE-2010-1916
CWE-264
High
CubeCart Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Vulnerability (CVE-2010-1931)
CVE-2010-1931
CWE-138
High
e107 Other Vulnerability (CVE-2010-2098)
CVE-2010-2098
-
High
e107 Permissions, Privileges, and Access Controls Vulnerability (CVE-2010-2099)
CVE-2010-2099
CWE-264
High
PHP Resource Management Errors Vulnerability (CVE-2010-2225)
CVE-2010-2225
-
High
Oracle Database Server CVE-2010-2390 Vulnerability (CVE-2010-2390)
CVE-2010-2390
-
High
Ruby Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability (CVE-2010-2489)
CVE-2010-2489
CWE-119
High
Joomla Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Vulnerability (CVE-2010-2679)
CVE-2010-2679
CWE-138
High
phpMyAdmin Permissions, Privileges, and Access Controls Vulnerability (CVE-2010-3055)
CVE-2010-3055
CWE-264
High
Family Connections Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2010-3419)
CVE-2010-3419
CWE-94
High
Oracle Database Server CVE-2010-3600 Vulnerability (CVE-2010-3600)
CVE-2010-3600
-
High
TYPO3 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Vulnerability (CVE-2010-3662)
CVE-2010-3662
CWE-138
High
TYPO3 Unrestricted Upload of File with Dangerous Type Vulnerability (CVE-2010-3663)
CVE-2010-3663
CWE-434
High
TYPO3 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') Vulnerability (CVE-2010-3668)
CVE-2010-3668
CWE-138
High
Jboss EAP Improper Input Validation Vulnerability (CVE-2010-3708)
CVE-2010-3708
CWE-20
High
TYPO3 Permissions, Privileges, and Access Controls Vulnerability (CVE-2010-3714)
CVE-2010-3714
CWE-264
High
OpenSSL Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') Vulnerability (CVE-2010-3864)
CVE-2010-3864
CWE-362
High
Joomla Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Vulnerability (CVE-2010-4166)
CVE-2010-4166
CWE-138
High
OpenSSL Improper Authentication Vulnerability (CVE-2010-4252)
CVE-2010-4252
CWE-287
High
Collabtive Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Vulnerability (CVE-2010-4269)
CVE-2010-4269
CWE-138
High
CakePHP Improper Input Validation Vulnerability (CVE-2010-4335)
CVE-2010-4335
CWE-20
High
phpMyFAQ Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2010-4558)
CVE-2010-4558
CWE-94
High
XWiki Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Vulnerability (CVE-2010-4641)
CVE-2010-4641
CWE-138
High
PHP Missing Release of Resource after Effective Lifetime Vulnerability (CVE-2010-4657)
CVE-2010-4657
CWE-772
High
Joomla Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Vulnerability (CVE-2010-4696)
CVE-2010-4696
CWE-138
High
CubeCart Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Vulnerability (CVE-2010-4903)
CVE-2010-4903
CWE-138
High
Zenphoto Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Vulnerability (CVE-2010-4906)
CVE-2010-4906
CWE-138
High
MyBB Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Vulnerability (CVE-2010-5096)
CVE-2010-5096
CWE-138
High
Trac Incorrect Default Permissions Vulnerability (CVE-2010-5108)
CVE-2010-5108
CWE-276
High
« Previous
1
...
20
21
22
23
24
25
26
27
...
175
Next »