| 6-1 |
Path Traversal |
release |
High |
Active |
| 6-2 |
Path Traversal |
release |
High |
Active |
| 6-3 |
Path Traversal |
release |
High |
Active |
| 6-4 |
Path Traversal |
release |
High |
Active |
| 6-5 |
Path Traversal |
release |
High |
Active |
| 30001 |
Buffer Overflow |
release |
Medium |
Active |
| 40012 |
Cross Site Scripting (Reflected) |
release |
High |
Active |
| 40014-1 |
Cross Site Scripting (Persistent) |
release |
High |
Active |
| 40014-2 |
Cross Site Scripting Weakness (Persistent in JSON Response) |
release |
Low |
Active |
| 40014-3 |
Cross Site Scripting (Persistent) |
release |
High |
Active |
| 40015-1 |
LDAP Injection - activedirectory |
alpha |
High |
Active |
| 40015-2 |
LDAP Injection |
alpha |
High |
Active |
| 40016 |
Cross Site Scripting (Persistent) - Prime |
release |
Informational |
Active |
| 40017 |
Cross Site Scripting (Persistent) - Spider |
release |
Informational |
Active |
| 40018 |
SQL Injection |
release |
High |
Active |
| 40019 |
SQL Injection - MySQL (Time Based) |
release |
High |
Active |
| 40020 |
SQL Injection - Hypersonic SQL (Time Based) |
release |
High |
Active |
| 40021 |
SQL Injection - Oracle (Time Based) |
release |
High |
Active |
| 40022 |
SQL Injection - PostgreSQL (Time Based) |
release |
High |
Active |
| 40024-1 |
SQL Injection - SQLite (Time Based) |
alpha |
High |
Active |
| 40024-2 |
SQL Injection - SQLite (Time Based) |
alpha |
High |
Active |
| 40027 |
SQL Injection - MsSQL (Time Based) |
release |
High |
Active |
| 40028 |
ELMAH Information Leak |
release |
Medium |
Active |
| 40031 |
Out of Band XSS |
beta |
High |
Active |
| 40033 |
NoSQL Injection - MongoDB |
beta |
High |
Active |
| 40039 |
Web Cache Deception |
alpha |
Medium |
Active |
| 40043-1 |
Log4Shell (CVE-2021-44228) |
release |
High |
Active |
| 40043-2 |
Log4Shell (CVE-2021-45046) |
release |
High |
Active |
| 40045 |
Spring4Shell |
release |
High |
Active |
| 40046 |
Server Side Request Forgery |
beta |
High |
Active |
| 40047 |
Text4shell (CVE-2022-42889) |
beta |
High |
Active |
| 40048 |
Remote Code Execution (React2Shell) |
release |
High |
Active |
| 90017 |
XSLT Injection |
release |
Medium |
Active |
| 90019-1 |
Server Side Code Injection - PHP Code Injection |
release |
High |
Active |
| 90019-2 |
Server Side Code Injection - ASP Code Injection |
release |
High |
Active |
| 90020 |
Remote OS Command Injection |
release |
High |
Active |
| 90021 |
XPath Injection |
release |
High |
Active |
| 90023 |
XML External Entity Attack |
release |
High |
Active |
| 90025 |
Expression Language Injection |
beta |
High |
Active |
| 90037 |
Remote OS Command Injection (Time Based) |
release |
High |
Active |
| 90039 |
NoSQL Injection - MongoDB (Time Based) |
beta |
High |
Active |