| 98117 | Blind SQL Injection (differential analysis) | Web App Scanning | Injection | 3/31/2017 | high |
| 98116 | NoSQL Injection | Web App Scanning | Injection | 3/31/2017 | high |
| 98115 | SQL Injection | Web App Scanning | Injection | 3/31/2017 | high |
| 98114 | XPath Injection | Web App Scanning | Injection | 3/31/2017 | high |
| 98113 | XML External Entity | Web App Scanning | Injection | 3/31/2017 | critical |
| 98112 | Cross-Site Request Forgery | Web App Scanning | Cross Site Request Forgery | 3/31/2017 | medium |
| 98110 | DOM-based Cross-Site Scripting (XSS) in attribute context | Web App Scanning | Cross Site Scripting | 3/31/2017 | medium |
| 98109 | DOM-based Cross-Site Scripting (XSS) | Web App Scanning | Cross Site Scripting | 3/31/2017 | medium |
| 98108 | Cross-Site Scripting (XSS) in event tag of HTML element | Web App Scanning | Cross Site Scripting | 3/31/2017 | medium |
| 98107 | Cross-Site Scripting (XSS) in path | Web App Scanning | Cross Site Scripting | 3/31/2017 | medium |
| 98106 | Cross-Site Scripting (XSS) in attribute context | Web App Scanning | Cross Site Scripting | 3/31/2017 | medium |
| 98105 | Cross-Site Scripting (XSS) in HTML tag | Web App Scanning | Cross Site Scripting | 3/31/2017 | medium |
| 98104 | Cross-Site Scripting (XSS) | Web App Scanning | Cross Site Scripting | 3/31/2017 | medium |
| 98103 | Unvalidated DOM redirect | Web App Scanning | Web Applications | 3/31/2017 | medium |
| 98102 | Session Fixation | Web App Scanning | Authentication & Session | 3/31/2017 | medium |
| 98101 | Response Splitting | Web App Scanning | Web Applications | 3/31/2017 | medium |
| 98100 | Path Traversal | Web App Scanning | Web Applications | 3/31/2017 | high |
| 98099 | Publicly writable directory | Web App Scanning | Web Servers | 3/31/2017 | high |
| 98098 | Source Code Disclosure | Web App Scanning | Data Exposure | 3/31/2017 | medium |
| 98097 | Backdoor Detection | Web App Scanning | Web Servers | 3/31/2017 | critical |
| 98096 | Access Restriction Bypass Via Origin Spoof | Web App Scanning | Authentication & Session | 3/31/2017 | medium |
| 98095 | Misconfiguration in LIMIT directive of .htaccess file | Web App Scanning | Web Servers | 3/31/2017 | medium |
| 98092 | HTML Object | Web App Scanning | Web Servers | 3/31/2017 | info |
| 98091 | Mixed Resource Detection | Web App Scanning | Web Applications | 3/31/2017 | medium |
| 98088 | Exposed Localstart.asp Page | Web App Scanning | Web Applications | 3/31/2017 | medium |
| 98087 | WebDAV | Web App Scanning | Web Servers | 3/31/2017 | info |
| 98083 | CAPTCHA Detection | Web App Scanning | Web Applications | 3/31/2017 | info |
| 98082 | Unencrypted Password Form | Web App Scanning | Authentication & Session | 3/31/2017 | medium |
| 98081 | Password Field With Auto-Complete | Web App Scanning | Authentication & Session | 3/31/2017 | low |
| 98080 | Form-based File Upload | Web App Scanning | Web Applications | 3/31/2017 | info |
| 98079 | CVS/SVN User Disclosure | Web App Scanning | Data Exposure | 3/31/2017 | medium |
| 98078 | E-mail Address Disclosure | Web App Scanning | Data Exposure | 3/31/2017 | info |
| 98077 | Private IP Address Disclosure | Web App Scanning | Data Exposure | 3/31/2017 | info |
| 98074 | Backup File | Web App Scanning | Data Exposure | 3/31/2017 | medium |
| 98073 | Backup Directory | Web App Scanning | Data Exposure | 3/31/2017 | medium |
| 98072 | Common Directories Detection | Web App Scanning | Web Servers | 3/31/2017 | info |
| 98071 | Common Files Detection | Web App Scanning | Web Servers | 3/31/2017 | info |
| 98070 | Common Administration Interfaces Detection | Web App Scanning | Web Applications | 3/31/2017 | info |
| 98068 | Insecure Cross-Domain Policy (allow-http-request-headers-from) | Web App Scanning | Web Applications | 3/31/2017 | low |
| 98067 | Insecure Cross-Domain Policy (allow-access-from) | Web App Scanning | Web Applications | 3/31/2017 | low |
| 98065 | Insecure Client-Access Policy | Web App Scanning | Web Applications | 3/31/2017 | low |
| 98064 | Cookie Without Secure Flag Detected | Web App Scanning | HTTP Security Header | 3/31/2017 | low |
| 98063 | Cookie Without HttpOnly Flag Detected | Web App Scanning | HTTP Security Header | 3/31/2017 | low |
| 98062 | Cookie Set For Parent Domain | Web App Scanning | HTTP Security Header | 3/31/2017 | info |
| 98060 | Missing 'X-Frame-Options' Header | Web App Scanning | HTTP Security Header | 3/31/2017 | low |
| 98057 | Insecure 'Access-Control-Allow-Origin' Header | Web App Scanning | HTTP Security Header | 3/31/2017 | low |
| 98056 | Missing HTTP Strict Transport Security Policy | Web App Scanning | HTTP Security Header | 3/31/2017 | medium |
| 98054 | Unvalidated Redirection | Web App Scanning | Web Applications | 3/31/2017 | medium |
| 98050 | Interesting Response | Web App Scanning | Web Applications | 3/31/2017 | info |
| 98048 | HTTP TRACE Allowed | Web App Scanning | Web Servers | 3/31/2017 | low |