Vulnerability Name CVE Severity
Access-Control-Allow-Origin header with wildcard (*) value
Content Security Policy (CSP) Not Implemented
GraphiQL Explorer/Playground Enabled
GraphQL Array-based Query Batching Allowed: Potential Batching Attack Vulnerability
GraphQL Field Suggestions Enabled
GraphQL Introspection Query Enabled
GraphQL Non-JSON Mutations over GET: Potential CSRF Vulnerability
GraphQL Non-JSON Queries over GET: Potential CSRF Vulnerability
GraphQL Non-JSON Queries over POST: Potential CSRF Vulnerability
GraphQL Unhandled Error Leakage
HTTP Strict Transport Security (HSTS) Policy Not Enabled
Insecure Referrer Policy
JWT Signature Bypass via kid Path Traversal
JWT Signature Bypass via kid SQL injection
JWT Signature Bypass via unvalidated jku parameter
JWT Signature Bypass via unvalidated jwk parameter
JWT Signature Bypass via unvalidated x5c parameter
JWT Signature Bypass via unvalidated x5u parameter
Microservice Directory Traversal
Missing Content-Type Header
No SAML Respose signature check
Permissions-Policy header not implemented
SAML Consumer Service XSS vulnerability
SAML Response without signature
SAML Respose signature exclusion
Sensitive Data Exposure
Sensitive pages could be cached
Spring Boot Actuator
Spring Boot Actuator v2
SSL/TLS Not Implemented
Struts 2 development mode
Unvalidated JWT jku parameter
Weak password
Web application default/weak credentials
X-Forwarded-For HTTP header security bypass