Web Application Vulnerabilities Index

This page lists X vulnerabilities classified as CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N that can be detected by Invicti.

Vulnerability Name
Classification
Severity
JWT Signature Bypass via None Algorithm
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
, 
CWE-287
, 
OWASP 2017-A2
, 
High
JWT Signature is not Verified
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
, 
CWE-287
, 
OWASP 2017-A2
, 
High
Weak Secret is Used to Sign JWT
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
, 
CWE-347
, 
OWASP 2017-A2
, 
High