Vulnerability Name CVE Severity
Amazon S3 public bucket
Apache 2.x version older than 2.0.48 CVE-2003-0542 CVE-2003-0789
Apache Axis2 information disclosure
Apache balancer-manager application publicly accessible
Apache httpOnly cookie disclosure CVE-2012-0053
Apache perl-status enabled
Apache Server-Info Detected
Apache Server-Status Detected
Apache Tomcat examples directory vulnerabilities
Apache Tomcat sample files
Apache Tomcat version older than 4.1.37 CVE-2005-3164 CVE-2007-1355 CVE-2007-2449 CVE-2007-2450 CVE-2007-3382 CVE-2007-3383 CVE-2007-3385 CVE-2007-5333 CVE-2007-5461
Apache Tomcat version older than 5.5.26 CVE-2007-5333 CVE-2007-5342 CVE-2007-5461 CVE-2007-6286
Apache Tomcat version older than 6.0.11 CVE-2005-2090 CVE-2007-1355
apc.php page found
Arbitrary file existence disclosure in Action Pack CVE-2014-7829
ASP.NET application-level tracing enabled
ASP.NET Core Development Mode enabled
ASP.NET CustomErrors Is Disabled
ASP.NET diagnostic page
ASP.NET error message
ASP.NET viewstate encryption disabled
ASP.NET WCF service include exception details
Atlassian Confluence Access Restriction Bypass CVE-2017-9505
Atlassian Confluence Stored Cross Site Scripting CVE-2016-6283
Bitrix server test script publicly accessible
Chrome Logger information disclosure
Citrix ADC NetScaler Local File Inclusion (CVE-2020-8193) CVE-2020-8193
Clockwork PHP dev tool enabled
CodeIgniter development mode enabled
ColdFusion Request Debugging information disclosure
ColdFusion Robust Exception enabled
Core dump checker PHP script
Credit card number disclosed
CVS Detected
Development configuration files
Directory listings
Django Debug Mode Enabled
Django Debug Toolbar
Drupal Views module information disclosure vulnerability
Express running in development mode
Frontpage authors.pwd available
Full public read access Azure blob storage
GIT Detected
Global.asa backup file found
Golang runtime profiling data
Go web application binary disclosure
Grails database console
GraphiQL Explorer/Playground Enabled
GraphQL Field Suggestions Enabled
GraphQL Introspection Query Enabled
GraphQL Unhandled Error Leakage
InfluxDB Unauthorized Access Vulnerability
Insecure transition from HTTP to HTTPS in form post
JBoss status servlet information leak CVE-2010-1429
Jenkins dashboard
JetBrains .idea project directory
Jetty ConcatServlet Information Disclosure (CVE-2021-28169) CVE-2021-28169
Jetty Information Disclosure (CVE-2021-34429) CVE-2021-34429
Jira Unauthorized User Enumeration (CVE-2020-14181) CVE-2020-14181
Joomla! Core improper access check in webservice endpoints CVE-2023-23752
Joomla Debug Console enabled
Joomla J!Dump extension enabled
JSONP enabled by default in MappingJackson2JsonView CVE-2018-11040
Laravel log file publicly accessible
Laravel LogViewer open
Laravel Telescope open
Magento Config File Disclosure
Microsoft Access Database File Detected
MongoDB HTTP status interface
nginx range filter integer overflow CVE-2017-7529
Node.js Running in Development Mode
NodeBB Arbitrary JSON File Read (CVE-2021-43788) CVE-2021-43788
npm log file publicly accessible (npm-debug.log)
Oracle applications logs publicy available
Oracle E-Business Suite iStore open user registration
Password found in server response
Payara Micro File Read (CVE-2021-41381) CVE-2021-41381
PHP-CS-Fixer cache file publicly accessible (.php_cs.cache)
PHP-FPM Status Page
PHP Console addon enabled
PHP curl_exec() url is controlled by user CVE-2009-0037
PHP Debug Bar enabled
Phpfastcache phpinfo publicly accessible (CVE-2021-37704) CVE-2021-37704
phpinfo() Output Detected
PHPinfo pages
PHP opcache-gui publicly accessible
PHP opcache-status page publicly accessible
PHP upload arbitrary file disclosure vulnerability CVE-2000-0860
PHP X Prober publicly accessible
Pyramid DebugToolbar enabled
rack-mini-profiler environment variables disclosure
Rails controller possible sensitive information disclosure
Ruby on Rails Running in Development Mode
SAP ICF /sap/public/info sensitive information disclosure
SAP NetWeaver Java AS WD_CHAT information disclosure vulnerability
SAP NetWeaver server info information disclosure
SAP NetWeaver server info information disclosure BCB
Sensitive Data Exposure
Server-based source code disclosures
SharePoint exposed web services
Social Security Number Disclosure
Source code disclosures
Spring Boot Actuator
Spring Boot Actuator v2
SQLite Database File Found
Stack Trace Disclosure (ColdFusion)
Stack Trace Disclosure (Java)
Stack Trace Disclosure (Laravel)
Stack Trace Disclosure (Python)
Stack Trace Disclosure (RoR)
Struts 2 Config Browser plugin enabled
Symfony debug mode enabled (AcuSensor)
Symfony Profiler open
Symfony running in dev mode
Symfony web debug toolbar
Test CGI script leaking environment variables
Tornado debug mode
Tracy debugging tool enabled
Unencrypted __VIEWSTATE parameter
Unprotected JSON file leaking secrets
Unrestricted access to NGINX+ API interface (read only)
Unrestricted access to NGINX+ Dashboard
Unrestricted access to NGINX+ Upstream HTTP interface
Virtual host directory listing
W3 total cache debug mode
Webalizer script
WebDAV directory listing
WebPageTest Unauthorized Access Vulnerability
WordPress database credentials disclosure
WordPress pingback scanner CVE-2013-0235
WordPress username enumeration
Yii2 debug toolkit
Yii debug mode enabled
Zabbix Guest Access
[Possible] AWStats Detected
[Possible] Backup Folder
[Possible] Database Connection String Detected
[Possible] Password Transmitted over Query String