🚀 Just released:
Latio 2026 Application Security Market Report.
Read it in our Whitepapers.
100% Signal 0% Noise
Platform
Invicti Platform
Zero-noise AppSec platform
Scan Code
Secure code before runtime
SAST
Early static security analysis
Open Source (SCA)
Find vulnerable dependencies
SBOM & License Risk
Generate SBOMs and track licenses
Secrets
Detect exposed secrets in applications
Infrastructure as Code
Ingest IaC security findings
Container
Track container image vulnerabilities
Test Runtime
Test live applications like attackers
DAST & AI DAST
Test runtime, prove exploitability
Agentic Pentesting
Automate real-world attack techniques
API Security Testing
Discover and test APIs
Attack Surface Management
Identify exposed apps and endpoints
Cloud AppSec
Get a single-pane view of cloud app risk
AI AppSec
Scan smarter, accelerate remediation
Manage Vulnerabilities
See, prioritize, reduce AppSec risk
Vulnerability Management (ASPM)
Centralize and correlate AppSec findings
Compliance & Executive Reporting
Measure risk and impact
Threat Intelligence
Reachability, exploitability, and business logic
Solutions
API Discovery
Manage Vulnerabilities
Automate Security Workflows
Track AppSec KPIs
Manage Open Source Risk
Pricing
Why Invicti
About Us
Case Studies
Contact Us
Careers
Resources
Resource Library
Blog
Webinars
White Papers
Podcasts
Invicti Learn
Savings Calculator
Live Training
Partners
Documentation
Get a demo
Home
/
Web Application Vulnerabilities
/ Known Vulnerabilities
Web Application Vulnerabilities
Runtime SCA Findings
Looking for the vulnerability index of Invicti's legacy products?
Invicti Enterprise
Acunetix Standard & Premium
v.26.4.2314
Known Vulnerabilities
This page lists
14673 vulnerabilities
in this category.
Critical: 1573
High: 3882
Medium: 8446
Low: 770
Information: 2
Vulnerability Name
CVE
CWE
Severity
PrestaShop CVE-2018-19125 Vulnerability (CVE-2018-19125)
CVE-2018-19125
-
High
PrestaShop Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Vulnerability (CVE-2018-19124)
CVE-2018-19124
CWE-22
High
Lighttpd Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Vulnerability (CVE-2018-19052)
CVE-2018-19052
CWE-22
High
SharePoint CVE-2025-29976 Vulnerability (CVE-2025-29976)
CVE-2025-29976
-
High
PHP NULL Pointer Dereference Vulnerability (CVE-2018-19395)
CVE-2018-19395
CWE-476
High
MOVEit Transfer Improper Privilege Management Vulnerability (CVE-2025-2324)
CVE-2025-2324
CWE-269
High
GeoServer Loop with Unreachable Exit Condition ('Infinite Loop') Vulnerability (CVE-2025-30145)
CVE-2025-30145
CWE-835
High
Jenkins Improper Input Validation Vulnerability (CVE-2018-1999002)
CVE-2018-1999002
CWE-20
High
Jenkins Improper Input Validation Vulnerability (CVE-2018-1999001)
CVE-2018-1999001
CWE-20
High
Envoy Proxy CVE-2025-30157 Vulnerability (CVE-2025-30157)
CVE-2025-30157
-
High
osCommerce Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2018-18573)
CVE-2018-18573
CWE-94
High
osCommerce Unrestricted Upload of File with Dangerous Type Vulnerability (CVE-2018-18572)
CVE-2018-18572
CWE-434
High
Joomla Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2018-17858)
CVE-2018-17858
CWE-352
High
Joomla CVE-2018-17856 Vulnerability (CVE-2018-17856)
CVE-2018-17856
-
High
SharePoint Deserialization of Untrusted Data Vulnerability (CVE-2025-29793)
CVE-2025-29793
CWE-502
High
MyBB Server-Side Request Forgery (SSRF) Vulnerability (CVE-2025-29460)
CVE-2025-29460
CWE-918
High
Moodle Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2018-1133)
CVE-2018-1133
CWE-94
High
Dolibarr Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Vulnerability (CVE-2018-19994)
CVE-2018-19994
CWE-138
High
Moodle Improper Authentication Vulnerability (CVE-2018-1082)
CVE-2018-1082
CWE-287
High
Python CVE-2018-1061 Vulnerability (CVE-2018-1061)
CVE-2018-1061
-
High
Python CVE-2018-1060 Vulnerability (CVE-2018-1060)
CVE-2018-1060
-
High
PostgreSQL CVE-2018-1058 Vulnerability (CVE-2018-1058)
CVE-2018-1058
-
High
PostgreSQL Incorrect Permission Assignment for Critical Resource Vulnerability (CVE-2018-1053)
CVE-2018-1053
CWE-732
High
Jboss EAP Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Vulnerability (CVE-2018-1048)
CVE-2018-1048
CWE-22
High
Jboss EAP Loop with Unreachable Exit Condition ('Infinite Loop') Vulnerability (CVE-2018-1041)
CVE-2018-1041
CWE-835
High
Dolibarr Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Vulnerability (CVE-2018-19998)
CVE-2018-19998
CWE-138
High
MyBB Server-Side Request Forgery (SSRF) Vulnerability (CVE-2025-29458)
CVE-2025-29458
CWE-918
High
PHP Deserialization of Untrusted Data Vulnerability (CVE-2018-19396)
CVE-2018-19396
CWE-502
High
MyBB Server-Side Request Forgery (SSRF) Vulnerability (CVE-2025-29459)
CVE-2025-29459
CWE-918
High
phpMyAdmin Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2018-19969)
CVE-2018-19969
CWE-352
High
PHP NULL Pointer Dereference Vulnerability (CVE-2018-19935)
CVE-2018-19935
CWE-476
High
PHP Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2018-19520)
CVE-2018-19520
CWE-94
High
PHP Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') Vulnerability (CVE-2018-19518)
CVE-2018-19518
CWE-707
High
Vanilla Forums Deserialization of Untrusted Data Vulnerability (CVE-2018-19499)
CVE-2018-19499
CWE-502
High
WebERP Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Vulnerability (CVE-2018-19436)
CVE-2018-19436
CWE-138
High
WebERP Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Vulnerability (CVE-2018-19435)
CVE-2018-19435
CWE-138
High
WebERP Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Vulnerability (CVE-2018-19434)
CVE-2018-19434
CWE-138
High
Jenkins Improper Input Validation Vulnerability (CVE-2017-1000394)
CVE-2017-1000394
CWE-20
High
Nginx Out-of-bounds Read Vulnerability (CVE-2023-27728)
CVE-2023-27728
CWE-125
High
Jenkins Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') Vulnerability (CVE-2017-1000393)
CVE-2017-1000393
CWE-138
High
PHP Other Vulnerability (CVE-2015-4644)
CVE-2015-4644
-
High
Skipper Unintended Proxy or Intermediary ('Confused Deputy') Vulnerability (CVE-2026-24470)
CVE-2026-24470
CWE-441
High
Apache Tomcat CVE-2026-24734 Vulnerability (CVE-2026-24734)
CVE-2026-24734
-
High
concrete5 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Vulnerability (CVE-2015-4724)
CVE-2015-4724
CWE-138
High
Apache Tomcat Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') Vulnerability (CVE-2026-24880)
CVE-2026-24880
-
High
ownCloud Resource Management Errors Vulnerability (CVE-2015-4717)
CVE-2015-4717
-
High
Craft CMS Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Vulnerability (CVE-2026-25495)
CVE-2026-25495
CWE-138
High
Joomla Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Vulnerability (CVE-2015-4654)
CVE-2015-4654
CWE-138
High
Craft CMS Authorization Bypass Through User-Controlled Key Vulnerability (CVE-2026-25497)
CVE-2026-25497
CWE-639
High
Craft CMS Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') Vulnerability (CVE-2026-25498)
CVE-2026-25498
CWE-470
High
Joomla Improper Access Control Vulnerability (CVE-2026-23899)
CVE-2026-23899
CWE-284
High
PHP Improper Input Validation Vulnerability (CVE-2015-4605)
CVE-2015-4605
CWE-20
High
PHP Improper Input Validation Vulnerability (CVE-2015-4604)
CVE-2015-4604
CWE-20
High
axios Improper Check for Unusual or Exceptional Conditions Vulnerability (CVE-2026-25639)
CVE-2026-25639
CWE-754
High
Django Allocation of Resources Without Limits or Throttling Vulnerability (CVE-2026-25673)
CVE-2026-25673
CWE-770
High
Moodle Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2026-26045)
CVE-2026-26045
CWE-94
High
Moodle Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') Vulnerability (CVE-2026-26046)
CVE-2026-26046
CWE-138
High
SharePoint CVE-2026-26106 Vulnerability (CVE-2026-26106)
CVE-2026-26106
-
High
PHP Data Processing Errors Vulnerability (CVE-2015-4147)
CVE-2015-4147
-
High
SharePoint Other Vulnerability (CVE-2026-26113)
CVE-2026-26113
-
High
phpMyFAQ CVE-2026-24422 Vulnerability (CVE-2026-24422)
CVE-2026-24422
-
High
MySQL CVE-2015-4819 Vulnerability (CVE-2015-4819)
CVE-2015-4819
-
High
PHP Data Processing Errors Vulnerability (CVE-2015-4025)
CVE-2015-4025
-
High
Oracle JRE Uncontrolled Resource Consumption Vulnerability (CVE-2026-21945)
CVE-2026-21945
CWE-400
High
Joomla Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Vulnerability (CVE-2026-21630)
CVE-2026-21630
CWE-138
High
CubeCart Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') Vulnerability (CVE-2026-21719)
CVE-2026-21719
CWE-138
High
Grafana Uncontrolled Resource Consumption Vulnerability (CVE-2026-21720)
CVE-2026-21720
CWE-400
High
Grafana Incorrect Authorization Vulnerability (CVE-2026-21721)
CVE-2026-21721
CWE-863
High
Oracle JRE CVE-2026-21932 Vulnerability (CVE-2026-21932)
CVE-2026-21932
-
High
Apache Tomcat Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2015-5351)
CVE-2015-5351
CWE-352
High
Oracle Database Server CVE-2026-21939 Vulnerability (CVE-2026-21939)
CVE-2026-21939
-
High
Apache Tomcat Other Vulnerability (CVE-2015-5346)
CVE-2015-5346
-
High
Moodle Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2015-5338)
CVE-2015-5338
CWE-352
High
Joomla External Control of File Name or Path Vulnerability (CVE-2026-23898)
CVE-2026-23898
CWE-73
High
Jenkins Improper Access Control Vulnerability (CVE-2015-5325)
CVE-2015-5325
CWE-284
High
«
1
...
28
29
30
...
196
»