🚀 Just released:
Latio 2026 Application Security Market Report.
Read it in our Whitepapers.
100% Signal 0% Noise
Platform
Invicti Platform
Zero-noise AppSec platform
Scan Code
Secure code before runtime
SAST
Early static security analysis
Open Source (SCA)
Find vulnerable dependencies
SBOM & License Risk
Generate SBOMs and track licenses
Secrets
Detect exposed secrets in applications
Infrastructure as Code
Ingest IaC security findings
Container
Track container image vulnerabilities
Test Runtime
Test live applications like attackers
DAST & AI DAST
Test runtime, prove exploitability
Agentic Pentesting
Automate real-world attack techniques
API Security Testing
Discover and test APIs
Attack Surface Management
Identify exposed apps and endpoints
Cloud AppSec
Get a single-pane view of cloud app risk
AI AppSec
Scan smarter, accelerate remediation
Manage Vulnerabilities
See, prioritize, reduce AppSec risk
Vulnerability Management (ASPM)
Centralize and correlate AppSec findings
Compliance & Executive Reporting
Measure risk and impact
Threat Intelligence
Reachability, exploitability, and business logic
Solutions
API Discovery
Manage Vulnerabilities
Automate Security Workflows
Track AppSec KPIs
Manage Open Source Risk
Pricing
Why Invicti
About Us
Case Studies
Contact Us
Careers
Resources
Resource Library
Blog
Webinars
White Papers
Podcasts
Invicti Learn
Savings Calculator
Live Training
Partners
Documentation
Get a demo
Home
/
Web Application Vulnerabilities
/ Known Vulnerabilities
Web Application Vulnerabilities
Runtime SCA Findings
Looking for the vulnerability index of Invicti's legacy products?
Invicti Enterprise
Acunetix Standard & Premium
v.26.4.2314
Known Vulnerabilities
This page lists
14673 vulnerabilities
in this category.
Critical: 1573
High: 3882
Medium: 8446
Low: 770
Information: 2
Vulnerability Name
CVE
CWE
Severity
PHP Other Vulnerability (CVE-2007-2369)
CVE-2007-2369
-
Medium
MediaWiki CVE-2021-42049 Vulnerability (CVE-2021-42049)
CVE-2021-42049
-
Medium
AbanteCart Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2021-42050)
CVE-2021-42050
CWE-707
Medium
Mailman Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2021-43331)
CVE-2021-43331
CWE-707
Medium
phpMyAdmin Improper Input Validation Vulnerability (CVE-2006-6943)
CVE-2006-6943
CWE-20
Medium
Apache Denial of service in mod_lua r:parsebody Vulnerability (CVE-2022-29404)
CVE-2022-29404
-
Medium
Oracle Database Server Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Vulnerability (CVE-2007-2111)
CVE-2007-2111
CWE-138
Medium
Nexus Repository Manager Server-Side Request Forgery (SSRF) Vulnerability (CVE-2021-43293)
CVE-2021-43293
CWE-918
Medium
WebLogic Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2022-29577)
CVE-2022-29577
CWE-707
Medium
Oracle Database Server CVE-2007-2112 Vulnerability (CVE-2007-2112)
CVE-2007-2112
-
Medium
LimeSurvey Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2022-29710)
CVE-2022-29710
CWE-707
Medium
SharePoint CVE-2021-43242 Vulnerability (CVE-2021-43242)
CVE-2021-43242
-
Medium
Oracle Database Server CVE-2007-2115 Vulnerability (CVE-2007-2115)
CVE-2007-2115
-
Medium
Oracle Database Server CVE-2007-2117 Vulnerability (CVE-2007-2117)
CVE-2007-2117
-
Medium
Caddy Web Server URL Redirection to Untrusted Site ('Open Redirect') Vulnerability (CVE-2022-29718)
CVE-2022-29718
CWE-601
Medium
Nexus Repository Manager Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2021-42568)
CVE-2021-42568
CWE-200
Medium
SharePoint CVE-2021-28450 Vulnerability (CVE-2021-28450)
CVE-2021-28450
-
Medium
SharePoint Authentication Bypass by Spoofing Vulnerability (CVE-2021-42320)
CVE-2021-42320
CWE-290
Medium
AbanteCart Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2021-42051)
CVE-2021-42051
CWE-707
Medium
SharePoint Incorrect Permission Assignment for Critical Resource Vulnerability (CVE-2021-42309)
CVE-2021-42309
CWE-732
Medium
SharePoint CVE-2021-42294 Vulnerability (CVE-2021-42294)
CVE-2021-42294
-
Medium
Oracle Application Server Other Vulnerability (CVE-2007-2119)
CVE-2007-2119
-
Medium
Dolibarr Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2021-42220)
CVE-2021-42220
CWE-707
Medium
MediaWiki Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2022-29903)
CVE-2022-29903
CWE-352
Medium
phpMyAdmin Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2006-6942)
CVE-2006-6942
CWE-707
Medium
MediaWiki Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2022-29905)
CVE-2022-29905
CWE-352
Medium
Oracle Database Server Other Vulnerability (CVE-2007-2119)
CVE-2007-2119
-
Medium
MediaWiki Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2022-29907)
CVE-2022-29907
CWE-707
Medium
LimeSurvey Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2021-42112)
CVE-2021-42112
CWE-707
Medium
Mailman Improper Restriction of Excessive Authentication Attempts Vulnerability (CVE-2021-42096)
CVE-2021-42096
CWE-307
Medium
Jenkins Other Vulnerability (CVE-2022-2048)
CVE-2022-2048
-
Medium
WebLogic Improper Input Validation Vulnerability (CVE-2021-45105)
CVE-2021-45105
CWE-20
Medium
PHP Other Vulnerability (CVE-2007-1835)
CVE-2007-1835
-
Medium
Oracle Database Server Other Vulnerability (CVE-2007-0277)
CVE-2007-0277
-
Medium
PHP Other Vulnerability (CVE-2007-1582)
CVE-2007-1582
-
Medium
Liferay DXP Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2022-26596)
CVE-2022-26596
CWE-707
Medium
PHP Other Vulnerability (CVE-2007-1521)
CVE-2007-1521
-
Medium
reveal.js Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2022-0776)
CVE-2022-0776
CWE-707
Medium
Liferay DXP Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2022-26597)
CVE-2022-26597
CWE-707
Medium
Liferay Portal Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2022-26597)
CVE-2022-26597
CWE-707
Medium
Oracle Database Server CVE-2007-0268 Vulnerability (CVE-2007-0268)
CVE-2007-0268
-
Medium
Dolibarr Other Vulnerability (CVE-2022-0746)
CVE-2022-0746
-
Medium
Dolibarr Incorrect Authorization Vulnerability (CVE-2022-0731)
CVE-2022-0731
CWE-863
Medium
Chamilo Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2022-27422)
CVE-2022-27422
CWE-707
Medium
Zope Web Application Server Other Vulnerability (CVE-2007-0240)
CVE-2007-0240
-
Medium
PHP Other Vulnerability (CVE-2007-1522)
CVE-2007-1522
-
Medium
PHP Other Vulnerability (CVE-2007-1583)
CVE-2007-1583
-
Medium
Liferay Portal Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2022-26596)
CVE-2022-26596
CWE-707
Medium
Chamilo Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2022-27425)
CVE-2022-27425
CWE-707
Medium
PHP Other Vulnerability (CVE-2007-1584)
CVE-2007-1584
-
Medium
Dolibarr Other Vulnerability (CVE-2022-0414)
CVE-2022-0414
-
Medium
WordPress Other Vulnerability (CVE-2007-1599)
CVE-2007-1599
-
Medium
Oracle Application Server Other Vulnerability (CVE-2007-1609)
CVE-2007-1609
-
Medium
WordPress Other Vulnerability (CVE-2007-1622)
CVE-2007-1622
-
Medium
Moodle Exposure of Resource to Wrong Sphere Vulnerability (CVE-2022-0334)
CVE-2022-0334
CWE-668
Medium
Oracle Application Server Other Vulnerability (CVE-2007-0222)
CVE-2007-0222
-
Medium
Nexus Repository Manager Server-Side Request Forgery (SSRF) Vulnerability (CVE-2022-27907)
CVE-2022-27907
CWE-918
Medium
Joomla CVE-2022-27911 Vulnerability (CVE-2022-27911)
CVE-2022-27911
-
Medium
Joomla Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2022-27912)
CVE-2022-27912
CWE-200
Medium
Joomla Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2022-27913)
CVE-2022-27913
CWE-707
Medium
PHP Other Vulnerability (CVE-2007-1484)
CVE-2007-1484
-
Medium
PHP Other Vulnerability (CVE-2007-1475)
CVE-2007-1475
-
Medium
Joomla Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2022-27914)
CVE-2022-27914
CWE-707
Medium
Oracle Database Server Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability (CVE-2007-0270)
CVE-2007-0270
CWE-119
Medium
Oracle Database Server Other Vulnerability (CVE-2007-0276)
CVE-2007-0276
-
Medium
Oracle Database Server CVE-2007-0274 Vulnerability (CVE-2007-0274)
CVE-2007-0274
-
Medium
WebLogic CVE-2022-21252 Vulnerability (CVE-2022-21252)
CVE-2022-21252
-
Medium
Oracle JRE CVE-2022-21248 Vulnerability (CVE-2022-21248)
CVE-2022-21248
-
Medium
MySQL CVE-2022-21245 Vulnerability (CVE-2022-21245)
CVE-2022-21245
-
Medium
Jenkins Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2022-20612)
CVE-2022-20612
CWE-352
Medium
Oracle Database Server CVE-2007-0273 Vulnerability (CVE-2007-0273)
CVE-2007-0273
-
Medium
Bootstrap Table Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2022-1726)
CVE-2022-1726
CWE-707
Medium
Oracle Database Server CVE-2007-0271 Vulnerability (CVE-2007-0271)
CVE-2007-0271
-
Medium
OpenSSL Use of a Broken or Risky Cryptographic Algorithm Vulnerability (CVE-2022-1434)
CVE-2022-1434
CWE-327
Medium
YetiForce CRM Unrestricted Upload of File with Dangerous Type Vulnerability (CVE-2022-1411)
CVE-2022-1411
CWE-434
Medium
«
1
...
81
82
83
...
196
»