Vulnerabilities

VulnerabilityCVECWESeverity
Missing_X-Frame-OptionsCWE-1021MEDIUM
Missing "Strict-Transport-Security" HeaderCWE-319LOW
Missing "Content-Type" Header (Functional Testing)CWE-16LOW
Missing "Content-Security-Policy" Security Header (Functional Testing)CWE-16LOW
Null Origin Allowed In Cross-Origin RequestsCWE-942MEDIUM
Missing "X-Content-Type-Options" Response HeaderCWE-79LOW
API Operation Publicly Accessible (Leaky APIs)CWE-284MEDIUM
API Operation Publicly Accessible (By Design)CWE-284LOW
Azure-hosted API Without Rate LimitingCWE-400MEDIUM
RESTful API Discloses "X-Asp-Net-Version" Fingerprinting HeaderCWE-200LOW
RESTful API Discloses - "X-Powered-By" Fingerprinting HeaderCWE-200LOW
Test HTTP MethodsCWE-749INFO
JWT Authentication Bypass via Flawed Signature VerificationCWE-347HIGH
Lack of Rate LimitingCWE-770MEDIUM
JWT Expiration TimeCWE-613HIGH
JWT Sensitive Data DisclosureCWE-311LOW
Failing Response TimeCWE-400MEDIUM
Sending JWT in URL ParametersCWE-384MEDIUM
Null Value AcceptanceCWE-704MEDIUM
JWT Authentication Bypass via JWK Header InjectionCWE-347HIGH
Massive Data on ResponseCWE-400MEDIUM
Sequential IDs AttackCWE-22HIGH
Server-Side Request Forgery (SSRF)CWE-918HIGH
URL Contains Sensitive Data - IP addressCWE-200MEDIUM
Mass Assignment - Response BodyCWE-915MEDIUM
Sensitive Information Disclosure - PII - TCKNCWE-200MEDIUM
URL Contains Sensitive Data - TCKNCWE-200MEDIUM
URL Contains Sensitive Data - SSNCWE-200MEDIUM
URL Contains Sensitive Data - EmailCWE-200MEDIUM
URL Contains Sensitive Data - Google API KeyCWE-200MEDIUM
URL Contains Sensitive Data - Credit Card NumberCWE-200MEDIUM
Improper Input ValidationCWE-20MEDIUM
Sensitive Information Disclosure - PII - SSNCWE-200MEDIUM
Sensitive Information Disclosure - PII - Credit Card NumberCWE-200MEDIUM
Sensitive Information Disclosure - Google API KeyCWE-200MEDIUM
Sensitive Information Disclosure - EmailCWE-200MEDIUM
Sensitive Information Disclosure - Full Path DisclosureCWE-200MEDIUM
Improper Assets Management - Version in EndpointCWE-937MEDIUM
Improper Assets Management - Version in Query StringCWE-937MEDIUM
401&403 Bypass With X-F-F HeaderCWE-290HIGH
Improper Assets Management - Version in HTTP HeaderCWE-937HIGH
CORS (Cross-Origin Resource Sharing)CWE-942MEDIUM
Graphql IntrospectionCWE-200LOW
Sensitive Information Disclosure - Internal IP AddressCWE-200MEDIUM
Information Leakage - Swagger DocumentationCWE-200LOW
Prototype Pollution via __proto__CWE-1321HIGH
Sensitive Information Disclosure - Bitcoin Wallet AddressCWE-200MEDIUM
Sensitive Information Disclosure - IPv6 AddressCWE-200MEDIUM
Sensitive Information Disclosure - MAC AddressCWE-200MEDIUM
Improper Error HandlingCWE-703HIGH
NoSQL Injection - MongoDBCWE-943HIGH
Insecure Direct Object Reference (IDOR)CWE-639HIGH
Open RedirectCWE-601MEDIUM
HTTP Parameter PollutionCWE-20MEDIUM
Missing Referrer-PolicyCWE-200MEDIUM
Missing Cache-ControlCWE-525MEDIUM
Missing Clear-Site-DataCWE-359MEDIUM
Missing Cross-Origin-Embedder-PolicyCWE-829HIGH
Missing Cross-Origin-Opener-PolicyCWE-829HIGH
Missing Cross-Origin-Resource-PolicyCWE-829HIGH
Missing Permissions-PolicyCWE-284MEDIUM
Missing X-Permitted-Cross-Domain-PoliciesCWE-829HIGH
Missing X-XSS-ProtectionCWE-79MEDIUM
Information Disclosure via K-Proxy-Request HeaderCWE-200MEDIUM
Information Disclosure via Liferay-Portal HeaderCWE-200MEDIUM
Information Disclosure via OracleCommerceCloud-Version HeaderCWE-200MEDIUM
Information Disclosure via Pega-Host HeaderCWE-200MEDIUM
Information Disclosure via Powered-By HeaderCWE-200LOW
Information Disclosure via Product HeaderCWE-200MEDIUM
Information Disclosure via Server HeaderCWE-200MEDIUM
Information Disclosure via SourceMap HeaderCWE-200HIGH
Information Disclosure via X-AspNetMvc-Version HeaderCWE-200MEDIUM
Information Disclosure via X-Atmosphere-error HeaderCWE-209MEDIUM
Information Disclosure via X-Atmosphere-first-request HeaderCWE-200MEDIUM
Information Disclosure via X-Atmosphere-tracking-id HeaderCWE-200MEDIUM
Information Disclosure via X-B3-ParentSpanId HeaderCWE-200MEDIUM
Information Disclosure via X-B3-Sampled HeaderCWE-200MEDIUM
Information Disclosure via X-B3-SpanId HeaderCWE-200MEDIUM
Information Disclosure via X-B3-TraceId HeaderCWE-200MEDIUM
Information Disclosure via X-BEServer HeaderCWE-200MEDIUM
Information Disclosure via X-Backside-Transport HeaderCWE-200MEDIUM
Information Disclosure via X-CF-Powered-By HeaderCWE-200MEDIUM
Information Disclosure via X-CMS HeaderCWE-200MEDIUM
Information Disclosure via X-CalculatedBETarget HeaderCWE-200MEDIUM
Information Disclosure via X-Cocoon-Version HeaderCWE-200MEDIUM
Information Disclosure via X-Content-Encoded-By HeaderCWE-200MEDIUM
Information Disclosure via X-DiagInfo HeaderCWE-209MEDIUM
Information Disclosure via X-Envoy-Attempt-Count HeaderCWE-200MEDIUM
Information Disclosure via X-Envoy-External-Address HeaderCWE-200MEDIUM
Information Disclosure via X-Envoy-Internal HeaderCWE-200MEDIUM
Information Disclosure via X-Envoy-Original-Dst-Host HeaderCWE-200MEDIUM
X-Envoy-Upstream-Service-TimeCWE-200MEDIUM
Information Disclosure via X-FEServer HeaderCWE-200MEDIUM
Information Disclosure via X-Framework HeaderCWE-200MEDIUM
Information Disclosure via X-Generated-By HeaderCWE-200MEDIUM
Information Disclosure via X-Generator HeaderCWE-200MEDIUM
Information Disclosure via X-Jitsi-Release HeaderCWE-200MEDIUM
Information Disclosure via X-Joomla-Version HeaderCWE-200MEDIUM
Information Disclosure via X-Kubernetes-PF-FlowSchema-UI HeaderCWE-200MEDIUM
Information Disclosure via X-Kubernetes-PF-PriorityLevel-UID HeaderCWE-200MEDIUM
Information Disclosure via X-LiteSpeed-Cache HeaderCWE-200MEDIUM
Information Disclosure via X-LiteSpeed-Purge HeaderCWE-200MEDIUM
Information Disclosure via X-LiteSpeed-Tag HeaderCWE-200MEDIUM
Information Disclosure via X-LiteSpeed-Vary HeaderCWE-200MEDIUM
Information Disclosure via X-Litespeed-Cache-Control HeaderCWE-200MEDIUM
Information Disclosure via X-Mod-Pagespeed HeaderCWE-200MEDIUM
Information Disclosure via X-Nextjs-Cache HeaderCWE-200MEDIUM
Information Disclosure via X-Nextjs-Matched-Path HeaderCWE-200MEDIUM
Information Disclosure via X-Nextjs-Page HeaderCWE-200MEDIUM
Information Disclosure via X-Nextjs-Redirect HeaderCWE-200MEDIUM
Information Disclosure via X-OWA-Version HeaderCWE-200MEDIUM
Information Disclosure via X-Old-Content-Length HeaderCWE-200MEDIUM
Information Disclosure via X-OneAgent-JS-Injection HeaderCWE-200MEDIUM
Information Disclosure via X-Page-Speed HeaderCWE-200MEDIUM
Information Disclosure via X-Php-Version HeaderCWE-200MEDIUM
Information Disclosure via X-Powered-By-Plesk HeaderCWE-200MEDIUM
Information Disclosure via X-Powered-CMS HeaderCWE-200MEDIUM
Information Disclosure via X-Redirect-By HeaderCWE-200MEDIUM
Information Disclosure via X-Server-Powered-By HeaderCWE-200MEDIUM
Information Disclosure via X-SourceFiles HeaderCWE-200MEDIUM
Information Disclosure via X-SourceMap HeaderCWE-200HIGH
Information Disclosure via X-Turbo-Charged-By HeaderCWE-200MEDIUM
Information Disclosure via X-Umbraco-Version HeaderCWE-200MEDIUM
Information Disclosure via X-Varnish-Backend HeaderCWE-200MEDIUM
Information Disclosure via X-Varnish-Server HeaderCWE-200MEDIUM
Information Disclosure via X-dtAgentId HeaderCWE-200MEDIUM
Information Disclosure via X-dtHealthCheck HeaderCWE-200MEDIUM
Information Disclosure via X-dtInjectedServlet HeaderCWE-200MEDIUM
Information Disclosure via X-ruxit-JS-Agent HeaderCWE-200MEDIUM