🚀 Just released:
Latio 2026 Application Security Market Report.
Read it in our Whitepapers.
100% Signal 0% Noise
Platform
Invicti Platform
Zero-noise AppSec platform
Scan Code
Secure code before runtime
SAST
Early static security analysis
Open Source (SCA)
Find vulnerable dependencies
SBOM & License Risk
Generate SBOMs and track licenses
Secrets
Detect exposed secrets in applications
Infrastructure as Code
Ingest IaC security findings
Container
Track container image vulnerabilities
Test Runtime
Test live applications like attackers
DAST & AI DAST
Test runtime, prove exploitability
Agentic Pentesting
Automate real-world attack techniques
API Security Testing
Discover and test APIs
Attack Surface Management
Identify exposed apps and endpoints
Cloud AppSec
Get a single-pane view of cloud app risk
AI AppSec
Scan smarter, accelerate remediation
Manage Vulnerabilities
See, prioritize, reduce AppSec risk
Vulnerability Management (ASPM)
Centralize and correlate AppSec findings
Compliance & Executive Reporting
Measure risk and impact
Threat Intelligence
Reachability, exploitability, and business logic
Solutions
API Discovery
Manage Vulnerabilities
Automate Security Workflows
Track AppSec KPIs
Manage Open Source Risk
Pricing
Why Invicti
About Us
Case Studies
Contact Us
Careers
Resources
Resource Library
Blog
Webinars
White Papers
Podcasts
Invicti Learn
Savings Calculator
Live Training
Partners
Documentation
Get a demo
Home
/
Web Application Vulnerabilities
/ Known Vulnerabilities
Web Application Vulnerabilities
Runtime SCA Findings
Looking for the vulnerability index of Invicti's legacy products?
Invicti Enterprise
Acunetix Standard & Premium
v.26.4.2314
Known Vulnerabilities
This page lists
14673 vulnerabilities
in this category.
Critical: 1573
High: 3882
Medium: 8446
Low: 770
Information: 2
Vulnerability Name
CVE
CWE
Severity
Chamilo Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2021-37389)
CVE-2021-37389
CWE-707
Medium
Nexus Repository Manager Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2021-37152)
CVE-2021-37152
CWE-707
Medium
PHP Improper Input Validation Vulnerability (CVE-2007-3998)
CVE-2007-3998
CWE-20
Medium
PHP Other Vulnerability (CVE-2007-4010)
CVE-2007-4010
-
Medium
Moodle Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2021-36401)
CVE-2021-36401
CWE-707
Medium
CKEditor Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2021-37695)
CVE-2021-37695
CWE-707
Medium
Drupal Other Vulnerability (CVE-2007-4063)
CVE-2007-4063
-
Medium
Moodle CVE-2021-36402 Vulnerability (CVE-2021-36402)
CVE-2021-36402
-
Medium
SharePoint CVE-2021-36940 Vulnerability (CVE-2021-36940)
CVE-2021-36940
-
Medium
Wordpress Plugin Backup Migration Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2021-36884)
CVE-2021-36884
CWE-707
Medium
DataTables Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2021-36713)
CVE-2021-36713
CWE-707
Medium
Drupal Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2007-4064)
CVE-2007-4064
CWE-707
Medium
Nginx Use After Free Vulnerability (CVE-2022-32414)
CVE-2022-32414
CWE-416
Medium
Moodle CVE-2021-36403 Vulnerability (CVE-2021-36403)
CVE-2021-36403
-
Medium
Lighttpd Other Vulnerability (CVE-2007-3950)
CVE-2007-3950
-
Medium
Next.js URL Redirection to Untrusted Site ('Open Redirect') Vulnerability (CVE-2021-37699)
CVE-2021-37699
CWE-601
Medium
Liferay DXP Incorrect Default Permissions Vulnerability (CVE-2021-38268)
CVE-2021-38268
CWE-276
Medium
Joomla Other Vulnerability (CVE-2007-4185)
CVE-2007-4185
-
Medium
Liferay DXP Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2021-38267)
CVE-2021-38267
CWE-707
Medium
Jenkins Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2022-34170)
CVE-2022-34170
CWE-707
Medium
Drupal Other Vulnerability (CVE-2006-5475)
CVE-2006-5475
-
Medium
Liferay Portal Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2021-38267)
CVE-2021-38267
CWE-707
Medium
Lighttpd Other Vulnerability (CVE-2007-3947)
CVE-2007-3947
-
Medium
Lighttpd Other Vulnerability (CVE-2007-3948)
CVE-2007-3948
-
Medium
Liferay DXP Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2021-38265)
CVE-2021-38265
CWE-707
Medium
Liferay Portal Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2021-38265)
CVE-2021-38265
CWE-707
Medium
Moodle Other Vulnerability (CVE-2006-5219)
CVE-2006-5219
-
Medium
Moodle Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2021-36399)
CVE-2021-36399
CWE-707
Medium
Liferay Portal Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2021-38264)
CVE-2021-38264
CWE-707
Medium
Dolphin Other Vulnerability (CVE-2006-5410)
CVE-2006-5410
-
Medium
Liferay Portal Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2021-38263)
CVE-2021-38263
CWE-707
Medium
Liferay DXP Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2021-38263)
CVE-2021-38263
CWE-707
Medium
WordPress Other Vulnerability (CVE-2007-4165)
CVE-2007-4165
-
Medium
WordPress Other Vulnerability (CVE-2007-4154)
CVE-2007-4154
-
Medium
Moodle CVE-2021-36397 Vulnerability (CVE-2021-36397)
CVE-2021-36397
-
Medium
Opencart Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Vulnerability (CVE-2021-37823)
CVE-2021-37823
CWE-138
Medium
Moodle Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2021-36398)
CVE-2021-36398
CWE-707
Medium
Oracle Application Server CVE-2007-3854 Vulnerability (CVE-2007-3854)
CVE-2007-3854
-
Medium
Seo Panel Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2021-39413)
CVE-2021-39413
CWE-707
Medium
Ruby on Rails Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2007-3227)
CVE-2007-3227
CWE-707
Medium
Apache Tomcat Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2007-3382)
CVE-2007-3382
CWE-200
Medium
MySQL CVE-2021-35641 Vulnerability (CVE-2021-35641)
CVE-2021-35641
-
Medium
Elgg Authorization Bypass Through User-Controlled Key Vulnerability (CVE-2021-3964)
CVE-2021-3964
CWE-639
Medium
Apache HTTP Server CVE-2007-3304 Vulnerability (CVE-2007-3304)
CVE-2007-3304
-
Medium
PHP Permissions, Privileges, and Access Controls Vulnerability (CVE-2007-3378)
CVE-2007-3378
CWE-264
Medium
MySQL CVE-2021-35642 Vulnerability (CVE-2021-35642)
CVE-2021-35642
-
Medium
MySQL CVE-2021-35643 Vulnerability (CVE-2021-35643)
CVE-2021-35643
-
Medium
MySQL CVE-2021-35644 Vulnerability (CVE-2021-35644)
CVE-2021-35644
-
Medium
WordPress Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2007-4139)
CVE-2007-4139
CWE-707
Medium
OpenVPN AS Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2021-3824)
CVE-2021-3824
CWE-707
Medium
MySQL CVE-2021-35637 Vulnerability (CVE-2021-35637)
CVE-2021-35637
-
Medium
Magento Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2022-34257)
CVE-2022-34257
CWE-707
Medium
CakePHP Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Vulnerability (CVE-2006-5031)
CVE-2006-5031
CWE-22
Medium
YOURLS Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2021-3785)
CVE-2021-3785
CWE-707
Medium
YOURLS Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2021-3783)
CVE-2021-3783
CWE-707
Medium
Apache Tomcat Other Vulnerability (CVE-2007-3383)
CVE-2007-3383
-
Medium
Apache Tomcat Other Vulnerability (CVE-2007-3384)
CVE-2007-3384
-
Medium
Apache Tomcat Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2007-3385)
CVE-2007-3385
CWE-200
Medium
Python Uncontrolled Resource Consumption Vulnerability (CVE-2021-3733)
CVE-2021-3733
CWE-400
Medium
MySQL CVE-2021-35638 Vulnerability (CVE-2021-35638)
CVE-2021-35638
-
Medium
Apache HTTP Server Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2007-3303)
CVE-2007-3303
CWE-94
Medium
MySQL CVE-2021-35645 Vulnerability (CVE-2021-35645)
CVE-2021-35645
-
Medium
WordPress Other Vulnerability (CVE-2007-3239)
CVE-2007-3239
-
Medium
GibbonEdu Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2021-40492)
CVE-2021-40492
CWE-707
Medium
phpMyAdmin Other Vulnerability (CVE-2006-5718)
CVE-2006-5718
-
Medium
jQuery UI Autocomplete Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2022-31160)
CVE-2022-31160
CWE-707
Medium
Magento CVE-2022-34259 Vulnerability (CVE-2022-34259)
CVE-2022-34259
-
Medium
MySQL CVE-2021-35630 Vulnerability (CVE-2021-35630)
CVE-2021-35630
-
Medium
MySQL CVE-2021-35631 Vulnerability (CVE-2021-35631)
CVE-2021-35631
-
Medium
WordPress Other Vulnerability (CVE-2007-3238)
CVE-2007-3238
-
Medium
SharePoint CVE-2021-40486 Vulnerability (CVE-2021-40486)
CVE-2021-40486
-
Medium
MySQL CVE-2021-35632 Vulnerability (CVE-2021-35632)
CVE-2021-35632
-
Medium
MediaWiki Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2012-2698)
CVE-2012-2698
CWE-707
Medium
MySQL CVE-2021-35634 Vulnerability (CVE-2021-35634)
CVE-2021-35634
-
Medium
WordPress Other Vulnerability (CVE-2007-3240)
CVE-2007-3240
-
Medium
«
1
...
75
76
77
...
196
»