Plugins
Settings
Links
Tenable Cloud
Tenable Community & Support
Tenable University
Severity
VPR
CVSS v2
CVSS v3
CVSS v4
Theme
Light
Dark
Auto
Help
Plugins
Overview
Plugins Pipeline
Newest
Updated
Search
Nessus Families
WAS Families
NNM Families
Tenable OT Security Families
About Plugin Families
Release Notes
Audits
Overview
Newest
Updated
Search Audit Files
Search Items
References
Authorities
Documentation
Download All Audit Files
Indicators
Overview
Search
Indicators of Attack
Indicators of Exposure
Release Notes
CVEs
Overview
Newest
Updated
Search
Attack Path Techniques
Overview
Search
Links
Tenable Cloud
Tenable Community & Support
Tenable University
Settings
Severity
VPR
CVSS v2
CVSS v3
CVSS v4
Theme
Light
Dark
Auto
Detections
Plugins
Overview
Plugins Pipeline
Release Notes
Newest
Updated
Search
Nessus Families
WAS Families
NNM Families
Tenable OT Security Families
About Plugin Families
Audits
Overview
Newest
Updated
Search Audit Files
Search Items
References
Authorities
Documentation
Download All Audit Files
Indicators
Overview
Search
Indicators of Attack
Indicators of Exposure
Release Notes
Analytics
CVEs
Overview
Newest
Updated
Search
Attack Path Techniques
Overview
Search
Plugins
Web App Scanning Release Notes
202501070844
Web App Scanning Release Notes
was Plugin Feed 202501070844
Jan 7, 2025, 8:44 AM
Modified Detection
112290
Apache Tomcat 9.0.0.M1 < 9.0.10 Multiple Vulnerabilities
112439
Server-Side Request Forgery
112524
Oracle WebLogic WSAT Remote Code Execution
112526
Missing 'X-XSS-Protection' Header (deprecated)
112541
SSL/TLS Certificate Common Name Mismatch
112544
HTTP to HTTPS Redirect Not Enabled
112545
Oracle WebLogic Server Administration Console Detected
112685
Symfony Secret Fragments Remote Code Execution
112686
JSON Web Token Detected
112703
JSON Web Token None Hashing Algorithm
112704
Oracle WebLogic 10.3.6.0.0 / 12.1.3.0.0 Remote Code Execution
112706
Oracle WebLogic 10.3.6.0.0 / 12.1.3.0.0 / 12.2.1.3.0 Remote Code Execution
112720
Rails < 4.2.11.3 / 5.x < 5.0.1 Remote Code Execution
112907
GraphQL Interface Detected
113029
Microsoft IIS Unsupported Version
113031
Out-of-Date JQuery UI Detected
113034
Out-of-Date MediaElement.Js Detected
113057
Microsoft Exchange Server Autodiscover Cross-Site Scripting
113058
Apache 2.4.10 < 2.4.44 Source Code Disclosure
113059
OPcache UI Detected
113067
Basic Authentication Bruteforced
113078
AngularJS Unsupported Version
113123
Dockerfile Detected
113150
Google Cloud Service Account Private Key Disclosure (deprecated)
113158
Package Dependencies Detected
113162
MySQLjs SQL Injection Authentication Bypass
113164
AWS Credentials Disclosure (deprecated)
113168
Docker Compose Configuration Detected
113195
Spring Boot Actuator Detected
113217
Spring Framework < 5.2.20 / 5.3.x < 5.3.18 Remote Code Execution (Spring4Shell)
113219
Insecure Redirect Chain
113258
OpenAPI Permissive Input Validation
113310
Blind XPath Injection (differential analysis)
113337
NoSQL Injection Authentication Bypass
113369
BackupBuddy Plugin for WordPress < 8.7.5 Arbitrary File Read
113373
Atlassian Bitbucket Remote Code Execution
113448
Microsoft Access Database Detected
113452
WordPress Plugins Detected
113634
Server-Side Inclusion Injection
113900
Cross-Site Request Forgery Token Validation Bypass
113906
Advanced Custom Fields for WordPress 6.0.x < 6.1.6 Cross-Site Scripting
113908
Advanced Custom Fields Pro for WordPress 6.0.x < 6.1.6 Cross-Site Scripting
113943
Disclosed Hong Kong Identity Number
113973
Web Services Description Language (WSDL) File Detected
114006
Web Cache Poisoning Denial of Service
114029
Well-Known URIs Detected
114064
MediaWiki Status Module Information Disclosure
114116
XML Injection
114128
External Backend API Detected
114129
Generic Secret Disclosure
114146
Subdomain Takeover
114166
SOAP API Detected
114168
Jenkins < 2.442 / < LTS 2.426.3 Arbitrary File Read
114200
Google Cloud Platform Detected
114232
PHP Development Server < 7.4.22 Source Disclosure
114247
Authentication Check Pattern Found in Unauthenticated Browser
114258
LayerSlider Plugin for WordPress 7.9.11 < 7.10.1 SQL Injection
114262
Request URL Override
114276
Database Connection String Disclosure
114313
Flowise Chatflow Detected
114357
Polyfill Detected
114386
External Broken Resources Detected
114400
Apache OFBiz < 18.12.11 Server-Side Request Forgery
114434
Flask Weak Secret Key
114450
Mura/Masa CMS SQL Injection
114502
Cross-Site WebSocket Hijacking
114549
Apache Struts < 6.4.0 Unrestricted File Upload (S2-067)
115540
Cookie Without SameSite Flag Detected
98000
Scan Information
98008
Web Application Firewall Detected
98054
Unvalidated Redirection
98056
Missing HTTP Strict Transport Security Policy
98062
Cookie Set For Parent Domain
98063
Cookie Without HttpOnly Flag Detected
98064
Cookie Without Secure Flag Detected
98070
Common Administration Interfaces Detection
98071
Common Files Detection
98074
Backup File
98080
Form-based File Upload
98083
CAPTCHA Detection
98091
Mixed Resource Detection
98099
Publicly writable directory
98100
Path Traversal
98101
Response Splitting
98104
Cross-Site Scripting (XSS)
98107
Cross-Site Scripting (XSS) in path
98109
DOM-based Cross-Site Scripting (XSS)
98110
DOM-based Cross-Site Scripting (XSS) in attribute context
98112
Cross-Site Request Forgery
98113
XML External Entity
98115
SQL Injection
98117
Blind SQL Injection (differential analysis)
98119
Blind NoSQL Injection (differential analysis)
98123
Operating System Command Injection
98125
Local File Inclusion
98146
Password Submitted Using GET Method
98201
Drupal User Registration Form Detected
98202
WordPress User Registration Form Detected
98205
Joomla! User Registration Form Detected
98209
Drupal User Enumeration
98228
Drupal Unsupported Version
98230
PHP Unsupported Version
98538
Environment Configuration File Detected
98611
Error Message
98623
Host Header Injection
98646
.DS_Store File Detected
98648
Missing 'Content-Type' Header
98779
Source Code Passive Disclosure
98920
Disclosed US Social Security Number
New
114546
Apache Tomcat 11.0.0-M1 < 11.0.2 Multiple Vulnerabilities
114547
Apache Tomcat 10.1.0-M1 < 10.1.34 Multiple Vulnerabilities
114548
Apache Tomcat 9.0.0-M1 < 9.0.98 Multiple Vulnerabilities