Severity Critical High Medium Low Informational Vulnerability Categories Abuse Of Functionality Acumonitor Api Bfla Api Bola Api Broken Auth Api Broken Object Prop Auth Api Dos Api Improper Inventory Management Api Misconfiguration Api Ssrf Arbitrary File Creation Arbitrary File Read Arbitrary File Write Authentication Bypass BOLA Bruteforce Possible Buffer Overflow CSRF CSTI Code Execution Configuration Crlf Injection Deepscan Default Credentials Denial-of-service Dev Files Directory Listing Directory Traversal Eli Injection Error Handling File Inclusion Http Parameter Pollution Http Response Splitting Information Disclosure Insecure Admin Access Insecure Deserialization Internal Ip Disclosure Known Vulnerabilitie Known Vulnerabilities LLM Ldap Injection Llm Excessive Agency Llm Insecure Output Handling Llm Prompt Injection Llm Sensitive Information Disclosure Malware Missing Update Path Traversal Privilege Escalation Remote Code Execution SSRF SSTI Sensitive Data Not Over Ssl Server Side Template Injection Session Fixation Source Code Disclosure Sql Injection Test Files Unauthenticated File Upload Url Redirection Weak Credentials Weak Crypto XFS XSS XXE Xpath Injection Xss - Known Vulnerabilities Vulnerability Name CVE CWE CWE Severity Squid Out-of-bounds Read Vulnerability (CVE-2021-28116) CVE-2021-28116 CWE-125 CWE-125 Medium Squid Out-of-bounds Write Vulnerability (CVE-2019-12521) CVE-2019-12521 CWE-787 CWE-787 Medium Squid Permissions, Privileges, and Access Controls Vulnerability (CVE-2012-2213) CVE-2012-2213 CWE-264 CWE-264 Medium Squid Permissions, Privileges, and Access Controls Vulnerability (CVE-2014-9749) CVE-2014-9749 CWE-264 CWE-264 Medium Squid Permissions, Privileges, and Access Controls Vulnerability (CVE-2015-5400) CVE-2015-5400 CWE-264 CWE-264 Medium Squid Resource Management Errors Vulnerability (CVE-2011-4096) CVE-2011-4096 Medium Squid Uncontrolled Resource Consumption Vulnerability (CVE-2021-46784) CVE-2021-46784 CWE-400 CWE-400 Medium SSL/TLS Not Implemented CWE-319 CWE-319 Medium SSL Certificate Is About To Expire CWE-298 CWE-298 Medium SSL Certificate Name Hostname Mismatch CWE-295 CWE-295 Medium SSL Secure renegotiation is not supported CVE-2009-3555 CWE-295 CWE-295 Medium SSL Untrusted Root Certificate CWE-295 CWE-295 Medium Stack Trace Disclosure (ColdFusion) CWE-209 CWE-209 Medium Stack Trace Disclosure (Java) CWE-209 CWE-209 Medium Stack Trace Disclosure (Laravel) CWE-209 CWE-209 Medium Stack Trace Disclosure (Python) CWE-209 CWE-209 Medium Stack Trace Disclosure (RoR) CWE-209 CWE-209 Medium Struts 2 Config Browser plugin enabled CWE-16 CWE-16 Medium SugarCRM Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2011-3803) CVE-2011-3803 CWE-200 CWE-200 Medium SugarCRM Gain Sensitive Information Vulnerability (CVE-2004-1226) CVE-2004-1226 Medium SugarCRM Improper Input Validation Vulnerability (CVE-2011-0745) CVE-2011-0745 CWE-20 CWE-20 Medium SugarCRM Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Vulnerability (CVE-2008-2045) CVE-2008-2045 CWE-22 CWE-22 Medium SugarCRM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2010-0465) CVE-2010-0465 CWE-707 CWE-707 Medium SugarCRM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2017-14510) CVE-2017-14510 CWE-707 CWE-707 Medium SugarCRM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2018-5715) CVE-2018-5715 CWE-707 CWE-707 Medium SugarCRM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2018-17784) CVE-2018-17784 CWE-707 CWE-707 Medium SugarCRM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2019-14974) CVE-2019-14974 CWE-707 CWE-707 Medium SugarCRM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2020-17372) CVE-2020-17372 CWE-707 CWE-707 Medium SugarCRM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2020-28955) CVE-2020-28955 CWE-707 CWE-707 Medium SugarCRM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2020-28956) CVE-2020-28956 CWE-707 CWE-707 Medium SugarCRM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2020-36501) CVE-2020-36501 CWE-707 CWE-707 Medium SugarCRM Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Vulnerability (CVE-2020-17373) CVE-2020-17373 CWE-138 CWE-138 Medium SugarCRM Other Vulnerability (CVE-2005-0266) CVE-2005-0266 Medium SugarCRM Other Vulnerability (CVE-2006-2460) CVE-2006-2460 Medium SugarCRM Other Vulnerability (CVE-2006-6712) CVE-2006-6712 Medium SugarCRM Other Vulnerability (CVE-2009-2146) CVE-2009-2146 Medium Swagger UI Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2016-5682) CVE-2016-5682 CWE-707 CWE-707 Medium Symfony debug mode enabled (Invicti IAST) CWE-16 CWE-16 Medium Symfony Profiler open CWE-200 CWE-200 Medium Symfony running in dev mode CWE-16 CWE-16 Medium Symfony web debug toolbar CWE-489 CWE-489 Medium TCExam Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2011-3806) CVE-2011-3806 CWE-200 CWE-200 Medium TCExam Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2020-5743) CVE-2020-5743 CWE-200 CWE-200 Medium TCExam Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Vulnerability (CVE-2020-5744) CVE-2020-5744 CWE-22 CWE-22 Medium TCExam Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2012-4602) CVE-2012-4602 CWE-707 CWE-707 Medium TCExam Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2018-13422) CVE-2018-13422 CWE-707 CWE-707 Medium TCExam Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2020-5746) CVE-2020-5746 CWE-707 CWE-707 Medium TCExam Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2020-5747) CVE-2020-5747 CWE-707 CWE-707 Medium TCExam Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2020-5748) CVE-2020-5748 CWE-707 CWE-707 Medium TCExam Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2020-5749) CVE-2020-5749 CWE-707 CWE-707 Medium TCExam Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2020-5750) CVE-2020-5750 CWE-707 CWE-707 Medium TCExam Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2020-5751) CVE-2020-5751 CWE-707 CWE-707 Medium TCExam Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2021-20111) CVE-2021-20111 CWE-707 CWE-707 Medium TCExam Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2021-20112) CVE-2021-20112 CWE-707 CWE-707 Medium TCExam Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2021-20115) CVE-2021-20115 CWE-707 CWE-707 Medium TCExam Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2021-20116) CVE-2021-20116 CWE-707 CWE-707 Medium TCExam Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Vulnerability (CVE-2012-4237) CVE-2012-4237 CWE-138 CWE-138 Medium TCExam Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Vulnerability (CVE-2012-4601) CVE-2012-4601 CWE-138 CWE-138 Medium TCExam Missing Authorization Vulnerability (CVE-2023-6554) CVE-2023-6554 CWE-862 CWE-862 Medium TCExam Observable Differences in Behavior to Error Inputs Vulnerability (CVE-2021-20113) CVE-2021-20113 Medium TCExam Other Vulnerability (CVE-2010-2153) CVE-2010-2153 Medium Test CGI script leaking environment variables Medium TestRail Information Disclosure (CVE-2021-40875) CVE-2021-40875 CWE-425 CWE-425 Medium The FREAK attack CVE-2015-0204 CWE-310 CWE-310 Medium The POODLE attack (SSLv3 with CBC cipher suites) CVE-2014-3566 CWE-326 CWE-326 Medium TinyMCE Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2019-1010091) CVE-2019-1010091 CWE-707 CWE-707 Medium TinyMCE Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2020-12648) CVE-2020-12648 CWE-707 CWE-707 Medium TinyMCE Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2020-17480) CVE-2020-17480 CWE-707 CWE-707 Medium TinyMCE Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2020-23066) CVE-2020-23066 CWE-707 CWE-707 Medium TinyMCE Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2022-23494) CVE-2022-23494 CWE-707 CWE-707 Medium TinyMCE Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2023-45818) CVE-2023-45818 CWE-707 CWE-707 Medium TinyMCE Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2023-45819) CVE-2023-45819 CWE-707 CWE-707 Medium TinyMCE Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2023-48219) CVE-2023-48219 CWE-707 CWE-707 Medium TinyMCE Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2024-21908) CVE-2024-21908 CWE-707 CWE-707 Medium TinyMCE Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2024-21910) CVE-2024-21910 CWE-707 CWE-707 Medium 1...96979899...109 97 / 109