🚀 Just released:
Latio 2026 Application Security Market Report.
Read it in our Whitepapers.
100% Signal 0% Noise
Platform
Invicti Platform
Zero-noise AppSec platform
Scan Code
Secure code before runtime
SAST
Early static security analysis
Open Source (SCA)
Find vulnerable dependencies
SBOM & License Risk
Generate SBOMs and track licenses
Secrets
Detect exposed secrets in applications
Infrastructure as Code
Ingest IaC security findings
Container
Track container image vulnerabilities
Test Runtime
Test live applications like attackers
DAST & AI DAST
Test runtime, prove exploitability
Agentic Pentesting
Automate real-world attack techniques
API Security Testing
Discover and test APIs
Attack Surface Management
Identify exposed apps and endpoints
Cloud AppSec
Get a single-pane view of cloud app risk
AI AppSec
Scan smarter, accelerate remediation
Manage Vulnerabilities
See, prioritize, reduce AppSec risk
Vulnerability Management (ASPM)
Centralize and correlate AppSec findings
Compliance & Executive Reporting
Measure risk and impact
Threat Intelligence
Reachability, exploitability, and business logic
Solutions
API Discovery
Manage Vulnerabilities
Automate Security Workflows
Track AppSec KPIs
Manage Open Source Risk
Pricing
Why Invicti
About Us
Case Studies
Contact Us
Careers
Resources
Resource Library
Blog
Webinars
White Papers
Podcasts
Invicti Learn
Savings Calculator
Live Training
Partners
Documentation
Get a demo
Home
/
Web Application Vulnerabilities
/ Known Vulnerabilities
Web Application Vulnerabilities
Runtime SCA Findings
Looking for the vulnerability index of Invicti's legacy products?
Invicti Enterprise
Acunetix Standard & Premium
v.26.4.2314
Known Vulnerabilities
This page lists
14673 vulnerabilities
in this category.
Critical: 1573
High: 3882
Medium: 8446
Low: 770
Information: 2
Vulnerability Name
CVE
CWE
Severity
MySQL CVE-2021-35602 Vulnerability (CVE-2021-35602)
CVE-2021-35602
-
Medium
MySQL CVE-2021-35597 Vulnerability (CVE-2021-35597)
CVE-2021-35597
-
Medium
MySQL CVE-2021-35596 Vulnerability (CVE-2021-35596)
CVE-2021-35596
-
Medium
Drupal Improper Removal of Sensitive Information Before Storage or Transfer Vulnerability (CVE-2022-31043)
CVE-2022-31043
CWE-212
Medium
Drupal Improper Removal of Sensitive Information Before Storage or Transfer Vulnerability (CVE-2022-31042)
CVE-2022-31042
CWE-212
Medium
PHP CVE-2007-4670 Vulnerability (CVE-2007-4670)
CVE-2007-4670
-
Medium
MySQL Numeric Errors Vulnerability (CVE-2007-2583)
CVE-2007-2583
-
Medium
WebLogic Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2021-41182)
CVE-2021-41182
CWE-707
Medium
Grafana Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2021-41174)
CVE-2021-41174
CWE-707
Medium
WordPress Other Vulnerability (CVE-2006-6017)
CVE-2006-6017
-
Medium
Dot CMS Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2021-35360)
CVE-2021-35360
CWE-707
Medium
Drupal Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2021-41182)
CVE-2021-41182
CWE-707
Medium
jQuery UI Autocomplete Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2021-41183)
CVE-2021-41183
CWE-707
Medium
Moodle Other Vulnerability (CVE-2006-4941)
CVE-2006-4941
-
Medium
Moodle Other Vulnerability (CVE-2006-4940)
CVE-2006-4940
-
Medium
Serendipity Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Vulnerability (CVE-2006-6242)
CVE-2006-6242
CWE-22
Medium
MySQL CVE-2021-35577 Vulnerability (CVE-2021-35577)
CVE-2021-35577
-
Medium
SharePoint CVE-2021-34517 Vulnerability (CVE-2021-34517)
CVE-2021-34517
-
Medium
jQuery UI Tooltip Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2021-41183)
CVE-2021-41183
CWE-707
Medium
jQuery UI Dialog Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2021-41182)
CVE-2021-41182
CWE-707
Medium
jQuery UI Tooltip Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2021-41184)
CVE-2021-41184
CWE-707
Medium
Dolibarr Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2022-30875)
CVE-2022-30875
CWE-707
Medium
b2evolution Other Vulnerability (CVE-2006-6197)
CVE-2006-6197
-
Medium
Moodle Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2021-36568)
CVE-2021-36568
CWE-707
Medium
WordPress Other Vulnerability (CVE-2007-3140)
CVE-2007-3140
-
Medium
Lighttpd Other Vulnerability (CVE-2007-3946)
CVE-2007-3946
-
Medium
Atlassian Jira CVE-2021-39121 Vulnerability (CVE-2021-39121)
CVE-2021-39121
-
Medium
Atlassian Jira Improper Authentication Vulnerability (CVE-2021-39119)
CVE-2021-39119
CWE-287
Medium
Atlassian Jira Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2021-39118)
CVE-2021-39118
CWE-200
Medium
Atlassian Jira Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2021-39117)
CVE-2021-39117
CWE-707
Medium
phpList Other Vulnerability (CVE-2006-5524)
CVE-2006-5524
-
Medium
Atlassian Jira CVE-2021-39116 Vulnerability (CVE-2021-39116)
CVE-2021-39116
-
Medium
MediaWiki Insecure Storage of Sensitive Information Vulnerability (CVE-2021-36127)
CVE-2021-36127
CWE-922
Medium
MediaWiki Incorrect Permission Assignment for Critical Resource Vulnerability (CVE-2021-36129)
CVE-2021-36129
CWE-732
Medium
Atlassian Jira URL Redirection to Untrusted Site ('Open Redirect') Vulnerability (CVE-2021-39112)
CVE-2021-39112
CWE-601
Medium
Jenkins Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2022-34171)
CVE-2022-34171
CWE-707
Medium
MediaWiki Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2021-36130)
CVE-2021-36130
CWE-707
Medium
MediaWiki Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2021-36131)
CVE-2021-36131
CWE-707
Medium
Joomla Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') Vulnerability (CVE-2007-4190)
CVE-2007-4190
CWE-138
Medium
Atlassian Jira Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2021-39111)
CVE-2021-39111
CWE-707
Medium
silverstripeCMS Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2021-36150)
CVE-2021-36150
CWE-707
Medium
MediaWiki Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2021-41798)
CVE-2021-41798
CWE-707
Medium
Chamilo Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2021-38745)
CVE-2021-38745
CWE-94
Medium
Liferay DXP Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2021-38269)
CVE-2021-38269
CWE-707
Medium
Atlassian Jira CVE-2021-39122 Vulnerability (CVE-2021-39122)
CVE-2021-39122
-
Medium
phpMyAdmin Other Vulnerability (CVE-2007-4306)
CVE-2007-4306
-
Medium
Joomla Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2007-4189)
CVE-2007-4189
CWE-707
Medium
PHP Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') Vulnerability (CVE-2006-5178)
CVE-2006-5178
CWE-362
Medium
PostgreSQL Other Vulnerability (CVE-2006-5541)
CVE-2006-5541
-
Medium
Oracle Database Server CVE-2007-3854 Vulnerability (CVE-2007-3854)
CVE-2007-3854
-
Medium
Oracle Database Server Other Vulnerability (CVE-2007-3855)
CVE-2007-3855
-
Medium
Oracle Database Server Other Vulnerability (CVE-2007-3856)
CVE-2007-3856
-
Medium
Oracle Database Server Other Vulnerability (CVE-2007-3857)
CVE-2007-3857
-
Medium
phpMyAdmin Other Vulnerability (CVE-2006-5117)
CVE-2006-5117
-
Medium
WordPress Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2021-39201)
CVE-2021-39201
CWE-707
Medium
WordPress Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2021-39200)
CVE-2021-39200
CWE-200
Medium
Next.js Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2021-39178)
CVE-2021-39178
CWE-707
Medium
PHP CVE-2022-31629 Vulnerability (CVE-2022-31629)
CVE-2022-31629
-
Medium
PleskWin Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2021-35976)
CVE-2021-35976
CWE-707
Medium
Apache HTTP Server Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2007-4465)
CVE-2007-4465
CWE-707
Medium
Atlassian Jira Exposure of Resource to Wrong Sphere Vulnerability (CVE-2021-39127)
CVE-2021-39127
CWE-668
Medium
PHP Other Vulnerability (CVE-2007-4441)
CVE-2007-4441
-
Medium
PostgreSQL Other Vulnerability (CVE-2006-5540)
CVE-2006-5540
-
Medium
PHP Loop with Unreachable Exit Condition ('Infinite Loop') Vulnerability (CVE-2022-31628)
CVE-2022-31628
CWE-835
Medium
osCommerce Other Vulnerability (CVE-2006-5190)
CVE-2006-5190
-
Medium
Atlassian Jira Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2021-39125)
CVE-2021-39125
CWE-200
Medium
Ampache Improper Authentication Vulnerability (CVE-2007-4438)
CVE-2007-4438
CWE-287
Medium
Liferay Portal Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2021-38269)
CVE-2021-38269
CWE-707
Medium
Liferay Portal Incorrect Default Permissions Vulnerability (CVE-2021-38268)
CVE-2021-38268
CWE-276
Medium
Beego Framework Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2021-39391)
CVE-2021-39391
CWE-707
Medium
osTicket Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2022-32074)
CVE-2022-32074
CWE-707
Medium
PHP Numeric Errors Vulnerability (CVE-2007-3996)
CVE-2007-3996
-
Medium
Chamilo Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2021-37391)
CVE-2021-37391
CWE-707
Medium
Chamilo Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2021-37390)
CVE-2021-37390
CWE-707
Medium
Moodle Authorization Bypass Through User-Controlled Key Vulnerability (CVE-2021-36400)
CVE-2021-36400
CWE-639
Medium
«
1
...
74
75
76
...
196
»