🚀 Just released:
Latio 2026 Application Security Market Report.
Read it in our Whitepapers.
100% Signal 0% Noise
Platform
Invicti Platform
Zero-noise AppSec platform
Scan Code
Secure code before runtime
SAST
Early static security analysis
Open Source (SCA)
Find vulnerable dependencies
SBOM & License Risk
Generate SBOMs and track licenses
Secrets
Detect exposed secrets in applications
Infrastructure as Code
Ingest IaC security findings
Container
Track container image vulnerabilities
Test Runtime
Test live applications like attackers
DAST & AI DAST
Test runtime, prove exploitability
Agentic Pentesting
Automate real-world attack techniques
API Security Testing
Discover and test APIs
Attack Surface Management
Identify exposed apps and endpoints
Cloud AppSec
Get a single-pane view of cloud app risk
AI AppSec
Scan smarter, accelerate remediation
Manage Vulnerabilities
See, prioritize, reduce AppSec risk
Vulnerability Management (ASPM)
Centralize and correlate AppSec findings
Compliance & Executive Reporting
Measure risk and impact
Threat Intelligence
Reachability, exploitability, and business logic
Solutions
API Discovery
Manage Vulnerabilities
Automate Security Workflows
Track AppSec KPIs
Manage Open Source Risk
Pricing
Why Invicti
About Us
Case Studies
Contact Us
Careers
Resources
Resource Library
Blog
Webinars
White Papers
Podcasts
Invicti Learn
Savings Calculator
Live Training
Partners
Documentation
Get a demo
Home
/
Web Application Vulnerabilities
/ Known Vulnerabilities
Web Application Vulnerabilities
Runtime SCA Findings
Looking for the vulnerability index of Invicti's legacy products?
Invicti Enterprise
Acunetix Standard & Premium
v.26.4.2314
Known Vulnerabilities
This page lists
14673 vulnerabilities
in this category.
Critical: 1573
High: 3882
Medium: 8446
Low: 770
Information: 2
Vulnerability Name
CVE
CWE
Severity
XWiki Missing Authorization Vulnerability (CVE-2024-43401)
CVE-2024-43401
CWE-862
High
Moodle Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2024-43425)
CVE-2024-43425
CWE-94
High
Oracle Database Server CVE-2019-2518 Vulnerability (CVE-2019-2518)
CVE-2019-2518
-
High
Oracle Database Server CVE-2019-2516 Vulnerability (CVE-2019-2516)
CVE-2019-2516
-
High
Sqlite NULL Pointer Dereference Vulnerability (CVE-2019-19923)
CVE-2019-19923
CWE-476
High
SharePoint Improper Input Validation Vulnerability (CVE-2019-1257)
CVE-2019-1257
CWE-20
High
Atlassian Jira Uncontrolled Search Path Element Vulnerability (CVE-2019-20400)
CVE-2019-20400
CWE-427
High
Envoy Proxy CVE-2024-45807 Vulnerability (CVE-2024-45807)
CVE-2024-45807
-
High
Sqlite Other Vulnerability (CVE-2019-20218)
CVE-2019-20218
-
High
Envoy Proxy NULL Pointer Dereference Vulnerability (CVE-2024-45809)
CVE-2024-45809
CWE-476
High
OpenSSL Cryptographic Issues Vulnerability (CVE-2019-1543)
CVE-2019-1543
-
High
SharePoint Improper Input Validation Vulnerability (CVE-2019-1296)
CVE-2019-1296
CWE-20
High
SharePoint Improper Input Validation Vulnerability (CVE-2019-1295)
CVE-2019-1295
CWE-20
High
SharePoint Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2019-1261)
CVE-2019-1261
CWE-352
High
Envoy Proxy CVE-2024-45810 Vulnerability (CVE-2024-45810)
CVE-2024-45810
-
High
SharePoint CVE-2019-1205 Vulnerability (CVE-2019-1205)
CVE-2019-1205
-
High
Atlassian Jira CVE-2019-20413 Vulnerability (CVE-2019-20413)
CVE-2019-20413
-
High
SharePoint CVE-2019-1201 Vulnerability (CVE-2019-1201)
CVE-2019-1201
-
High
Microsoft SQL Server Remote Code Execution Vulnerability (CVE-2019-1068)
CVE-2019-1068
-
High
SharePoint CVE-2019-1035 Vulnerability (CVE-2019-1035)
CVE-2019-1035
-
High
SharePoint CVE-2019-1034 Vulnerability (CVE-2019-1034)
CVE-2019-1034
-
High
SharePoint Improper Certificate Validation Vulnerability (CVE-2019-1006)
CVE-2019-1006
CWE-295
High
Sqlite Other Vulnerability (CVE-2019-19959)
CVE-2019-19959
-
High
Artifactory Improper Input Validation Vulnerability (CVE-2019-19937)
CVE-2019-19937
CWE-20
High
Sqlite NULL Pointer Dereference Vulnerability (CVE-2019-19926)
CVE-2019-19926
CWE-476
High
Sqlite Unrestricted Upload of File with Dangerous Type Vulnerability (CVE-2019-19925)
CVE-2019-19925
CWE-434
High
Atlassian Confluence Uncontrolled Search Path Element Vulnerability (CVE-2019-20406)
CVE-2019-20406
CWE-427
High
Atlassian Jira Uncontrolled Search Path Element Vulnerability (CVE-2019-20419)
CVE-2019-20419
CWE-427
High
Oracle HTTP Server CVE-2019-2414 Vulnerability (CVE-2019-2414)
CVE-2019-2414
-
High
Dolibarr Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Vulnerability (CVE-2019-25450)
CVE-2019-25450
CWE-138
High
MongoDb CVE-2019-2390 Vulnerability (CVE-2019-2390)
CVE-2019-2390
-
High
MongoDb Insufficient Session Expiration Vulnerability (CVE-2019-2386)
CVE-2019-2386
CWE-613
High
SharePoint CVE-2024-43503 Vulnerability (CVE-2024-43503)
CVE-2024-43503
-
High
phpBB Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Vulnerability (CVE-2019-25685)
CVE-2019-25685
CWE-22
High
qdPM Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Vulnerability (CVE-2019-25669)
CVE-2019-25669
CWE-138
High
osCommerce Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Vulnerability (CVE-2019-25497)
CVE-2019-25497
CWE-138
High
osCommerce Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Vulnerability (CVE-2019-25496)
CVE-2019-25496
CWE-138
High
osCommerce Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Vulnerability (CVE-2019-25495)
CVE-2019-25495
CWE-138
High
Dolibarr Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Vulnerability (CVE-2019-25452)
CVE-2019-25452
CWE-138
High
Django CVE-2024-45230 Vulnerability (CVE-2024-45230)
CVE-2024-45230
-
High
Squid CVE-2024-45802 Vulnerability (CVE-2024-45802)
CVE-2024-45802
-
High
MongoDb Incorrect Comparison Vulnerability (CVE-2019-20925)
CVE-2019-20925
CWE-697
High
Handlebars Loop with Unreachable Exit Condition ('Infinite Loop') Vulnerability (CVE-2019-20922)
CVE-2019-20922
CWE-835
High
Handlebars Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2019-20920)
CVE-2019-20920
CWE-94
High
Python Loop with Unreachable Exit Condition ('Infinite Loop') Vulnerability (CVE-2019-20907)
CVE-2019-20907
CWE-835
High
Atlassian Jira CVE-2019-20898 Vulnerability (CVE-2019-20898)
CVE-2019-20898
-
High
Contao Unrestricted Upload of File with Dangerous Type Vulnerability (CVE-2024-45398)
CVE-2024-45398
CWE-434
High
Cherokee Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability (CVE-2019-20799)
CVE-2019-20799
CWE-119
High
Cherokee Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2019-20798)
CVE-2019-20798
CWE-707
High
Moodle Incorrect Default Permissions Vulnerability (CVE-2024-45690)
CVE-2024-45690
CWE-276
High
GeoServer Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2024-34711)
CVE-2024-34711
CWE-200
High
MediaWiki Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) Vulnerability (CVE-2024-34507)
CVE-2024-34507
CWE-707
High
PHP Out-of-bounds Write Vulnerability (CVE-2024-11233)
CVE-2024-11233
CWE-787
High
GibbonEdu Deserialization of Untrusted Data Vulnerability (CVE-2024-24725)
CVE-2024-24725
CWE-502
High
Apache Tomcat CVE-2024-24549 Vulnerability (CVE-2024-24549)
CVE-2024-24549
-
High
Sqlite NULL Pointer Dereference Vulnerability (CVE-2020-35525)
CVE-2020-35525
CWE-476
High
Django CVE-2024-24680 Vulnerability (CVE-2024-24680)
CVE-2024-24680
-
High
Restlet Framework Deserialization of Untrusted Data Vulnerability (CVE-2013-4271)
CVE-2013-4271
CWE-502
High
Envoy mishandles dropped and truncated datagrams Issue (CVE-2020-35471)
CVE-2020-35471
-
High
Envoy Wrong DOWNSTREAM_REMOTE_ADDRESS logged Issue (CVE-2020-35470)
CVE-2020-35470
-
High
Apache HTTP Server Out-of-bounds Write Vulnerability (CVE-2020-35452)
CVE-2020-35452
CWE-787
High
CakePHP Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2020-35239)
CVE-2020-35239
CWE-352
High
GeoServer Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Vulnerability (CVE-2024-24749)
CVE-2024-24749
CWE-22
High
Joomla Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2020-35611)
CVE-2020-35611
CWE-200
High
Squid Uncontrolled Recursion Vulnerability (CVE-2024-25111)
CVE-2024-25111
CWE-674
High
TYPO3 CVE-2024-25121 Vulnerability (CVE-2024-25121)
CVE-2024-25121
-
High
Oracle HTTP Server Other Vulnerability (CVE-2020-35164)
CVE-2020-35164
-
High
Liferay Portal CVE-2024-25148 Vulnerability (CVE-2024-25148)
CVE-2024-25148
-
High
Dolibarr Improper Neutralization of Special Elements used in a Command ('Command Injection') Vulnerability (CVE-2020-35136)
CVE-2020-35136
CWE-138
High
Oracle Database Server CVE-2020-2968 Vulnerability (CVE-2020-2968)
CVE-2020-2968
-
High
WebLogic CVE-2020-2967 Vulnerability (CVE-2020-2967)
CVE-2020-2967
-
High
WebLogic CVE-2020-2963 Vulnerability (CVE-2020-2963)
CVE-2020-2963
-
High
Liferay DXP CVE-2024-25148 Vulnerability (CVE-2024-25148)
CVE-2024-25148
-
High
Joomla CVE-2020-35610 Vulnerability (CVE-2020-35610)
CVE-2020-35610
-
High
Joomla Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Vulnerability (CVE-2020-35612)
CVE-2020-35612
CWE-22
High
«
1
...
53
54
55
...
196
»