🚀 Invicti Acquires Kondukto to Deliver Proof-Based Application Security Posture Management
100% Signal 0% Noise
Platform
Platform Overview
ASPM
APIÂ Security
DAST
SAST
SCA
Container Security
AI-Powered AppSec
Features
Solutions
Manage Vulnerabilities
Automate Security Workflows
Track AppSec KPIs
Manage Open Source Risk
Pricing
Why Invicti
About Us
Case Studies
Contact Us
Careers
Resources
Resource Library
Blog
Webinars
White Papers
Podcasts
Invicti Learn
Cost Savings Calc
Live Training
Partners
Documentation
Get a demo
Web Application Vulnerabilities Index
This page lists
144
vulnerabilities categorized as medium severity that can be detected by Invicti.
Select Category
Critical
High
Medium
Low
Best Practice
Information
Select Vulnerability
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
Vulnerability Name
Classification
Severity
Out-of-date Version (React)
Out-of-date Version (React)
Information
Out-of-date Version (RequireJS)
Out-of-date Version (RequireJS)
Information
Out-of-date Version (Resin Application Server)
Out-of-date Version (Resin Application Server)
Information
Out-of-date Version (Respond.js)
Out-of-date Version (Respond.js)
Information
Out-of-date Version (Restlet Framework)
Out-of-date Version (Restlet Framework)
Information
Out-of-date Version (Reveal.js)
Out-of-date Version (Reveal.js)
Information
Out-of-date Version (Revive Adserver)
Out-of-date Version (Revive Adserver)
Information
Out-of-date Version (Rickshaw)
Out-of-date Version (Rickshaw)
Information
Out-of-date Version (Riot.js)
Out-of-date Version (Riot.js)
Information
Out-of-date Version (RoR)
Out-of-date Version (RoR)
Information
Out-of-date Version (Roundcube)
Out-of-date Version (Roundcube)
Information
Out-of-date Version (Ruby)
Out-of-date Version (Ruby)
Information
Out-of-date Version (RubyGems)
Out-of-date Version (RubyGems)
Information
Out-of-date Version (Rukovoditel)
Out-of-date Version (Rukovoditel)
Information
Out-of-date Version (ScrollReveal)
Out-of-date Version (ScrollReveal)
Information
Out-of-date Version (Select2)
Out-of-date Version (Select2)
Information
Out-of-date Version (Semantic UI)
Out-of-date Version (Semantic UI)
Information
Out-of-date Version (SeoPanel)
Out-of-date Version (SeoPanel)
Information
Out-of-date Version (Serendipity)
Out-of-date Version (Serendipity)
Information
Out-of-date Version (Silverstripe CMS)
Out-of-date Version (Silverstripe CMS)
Information
Out-of-date Version (slick)
Out-of-date Version (slick)
Information
Out-of-date Version (Snap.svg)
Out-of-date Version (Snap.svg)
Information
Out-of-date Version (Sortable)
Out-of-date Version (Sortable)
Information
Out-of-date Version (SQLite)
Out-of-date Version (SQLite)
High
Out-of-date Version (Squid)
Out-of-date Version (Squid)
Information
Out-of-date Version (SugarCRM)
Out-of-date Version (SugarCRM)
Information
Out-of-date Version (Swagger UI)
Out-of-date Version (Swagger UI)
Information
Out-of-date Version (SweetAlert2)
Out-of-date Version (SweetAlert2)
Information
Out-of-date Version (TCExam)
Out-of-date Version (TCExam)
Information
Out-of-date Version (Telerik Web UI)
Out-of-date Version (Telerik Web UI)
Information
Out-of-date Version (Three.js)
Out-of-date Version (Three.js)
Information
Out-of-date Version (TinyMCE)
Out-of-date Version (TinyMCE)
Information
Out-of-date Version (Tomcat)
Out-of-date Version (Tomcat)
Information
Out-of-date Version (Tornado Web Server)
Out-of-date Version (Tornado Web Server)
Information
Out-of-date Version (Trac Software Project Management Tool)
Out-of-date Version (Trac Software Project Management Tool)
Information
Out-of-date Version (Tracy Debugging Tool)
Out-of-date Version (Tracy Debugging Tool)
Information
Out-of-date Version (TwistedWeb HTTP Server)
Out-of-date Version (TwistedWeb HTTP Server)
Information
Out-of-date Version (typeahead.js)
Out-of-date Version (typeahead.js)
Information
Out-of-date Version (Typo3)
Out-of-date Version (Typo3)
Information
Out-of-date Version (UAParser.js)
Out-of-date Version (UAParser.js)
Information
Out-of-date Version (Underscore.js)
Out-of-date Version (Underscore.js)
Information
Out-of-date Version (Undertow Web Server)
Out-of-date Version (Undertow Web Server)
Information
Out-of-date Version (Vanilla Forums)
Out-of-date Version (Vanilla Forums)
Information
Out-of-date Version (Video.js)
Out-of-date Version (Video.js)
Information
Out-of-date Version (Vue.js)
Out-of-date Version (Vue.js)
Information
Out-of-date Version (W3 Total Cache)
Out-of-date Version (W3 Total Cache)
Information
Out-of-date Version (webERP)
Out-of-date Version (webERP)
Information
Out-of-date Version (WeBid)
Out-of-date Version (WeBid)
Information
Out-of-date Version (WebLogic)
Out-of-date Version (WebLogic)
Information
Out-of-date Version (Werkzeug Python WSGI Library)
Out-of-date Version (Werkzeug Python WSGI Library)
Information
Out-of-date Version (WordPress)
Out-of-date Version (WordPress)
Information
Out-of-date Version (XOOPS)
Out-of-date Version (XOOPS)
Information
Out-of-date Version (XRegExp)
Out-of-date Version (XRegExp)
Information
Out-of-date Version (XWiki)
Out-of-date Version (XWiki)
Information
Out-of-date Version (YetiForce CRM)
Out-of-date Version (YetiForce CRM)
Information
Out-of-date Version (YOURLS)
Out-of-date Version (YOURLS)
Information
Out-of-date Version (YUI)
Out-of-date Version (YUI)
Information
Out-of-date Version (Zen Cart)
Out-of-date Version (Zen Cart)
Information
Out-of-date Version (ZenPhoto)
Out-of-date Version (ZenPhoto)
Information
Out-of-date Version (Zepto.js)
Out-of-date Version (Zepto.js)
Information
Out-of-date Version (Zikula)
Out-of-date Version (Zikula)
Information
Out-of-date Version (Zope)
Out-of-date Version (Zope)
Information
Overly Long Session Timeout
Overly Long Session Timeout
Medium
ownCloud Detected
ownCloud Detected
Information
Palo Alto PAN-OS Management Interface Auth Bypass (CVE-2024-0012/CVE-2024-9474)
Palo Alto PAN-OS Management Interface Auth Bypass (CVE-2024-0012/CVE-2024-9474)
Critical
PAN-OS GlobalProtect XSS (CVE-2025-0133)
PAN-OS GlobalProtect XSS (CVE-2025-0133)
Medium
PAN-OS Management Interface Authentication Bypass (CVE-2025-0108)
PAN-OS Management Interface Authentication Bypass (CVE-2025-0108)
Critical
Pardot Server Identified
Pardot Server Identified
Information
Passive Mixed Content over HTTPS
Passive Mixed Content over HTTPS
Low
Passive Web Backdoor Detected
Passive Web Backdoor Detected
Low
Password Transmitted over HTTP
Password Transmitted over HTTP
High
Password Transmitted over Query String
Password Transmitted over Query String
Medium
Payara Identified
Payara Identified
Information
PdfJs Identified
PdfJs Identified
Information
1