Vulnerability Name CVE Severity
Artifactory Insufficiently Protected Credentials Vulnerability (CVE-2018-1000424) CVE-2018-1000424
Artifactory Insufficiently Protected Credentials Vulnerability (CVE-2020-2164) CVE-2020-2164
Artifactory Insufficiently Protected Credentials Vulnerability (CVE-2020-2165) CVE-2020-2165
Artifactory Insufficient Verification of Data Authenticity Vulnerability (CVE-2018-19971) CVE-2018-19971
Artifactory Missing Authorization Vulnerability (CVE-2019-10322) CVE-2019-10322
Artifactory Missing Authorization Vulnerability (CVE-2019-10323) CVE-2019-10323
Artifactory Unrestricted Upload of File with Dangerous Type Vulnerability (CVE-2016-10036) CVE-2016-10036
Artifactory Weak Password Requirements Vulnerability (CVE-2019-17444) CVE-2019-17444
ASP.NET: Failure To Require SSL For Authentication Cookies
ASP.NET application-level tracing enabled
ASP.NET ASPX debugging enabled
ASP.NET connection strings stored in plaintext
ASP.NET cookieless authentication enabled
ASP.NET Cookieless session state enabled
ASP.NET cookies accessible from client-side scripts
ASP.NET Core Development Mode enabled
ASP.NET CustomErrors Is Disabled
ASP.NET debugging enabled
ASP.NET Deny missing from authorization rule on location
ASP.NET diagnostic page
ASP.NET error message
ASP.NET event validation disabled
ASP.NET expired session IDs are not regenerated
ASP.NET forms authentication using inadequate protection
ASP.NET header checking is disabled in web.config
ASP.NET login credentials stored in plain text
ASP.NET MVC Improper Authentication Vulnerability (CVE-2018-8171) CVE-2018-8171
ASP.NET MVC Improper Input Validation Vulnerability (CVE-2017-0247) CVE-2017-0247
ASP.NET MVC Improper Input Validation Vulnerability (CVE-2017-0249) CVE-2017-0249
ASP.NET MVC Improper Input Validation Vulnerability (CVE-2017-0256) CVE-2017-0256
ASP.NET MVC Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2014-4075) CVE-2014-4075
ASP.NET path disclosure
ASP.NET potential HTTP Verb Tampering
ASP.NET SignalR Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2013-5042) CVE-2013-5042
ASP.NET ValidateRequest Is Globally Disabled
ASP.NET viewstate encryption disabled
ASP.NET ViewStateUserKey Is Not Set
ASP.NET WCF metadata enabled for behavior
ASP.NET WCF replay attacks are not detected
ASP.NET WCF service include exception details
Atlassian Confluence Access Restriction Bypass CVE-2017-9505
Atlassian Confluence Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2012-6342) CVE-2012-6342
Atlassian Confluence CVE-2020-29448 Vulnerability (CVE-2020-29448) CVE-2020-29448
Atlassian Confluence CVE-2023-22503 Vulnerability (CVE-2023-22503) CVE-2023-22503
Atlassian Confluence CVE-2023-22505 Vulnerability (CVE-2023-22505) CVE-2023-22505
Atlassian Confluence CVE-2023-22508 Vulnerability (CVE-2023-22508) CVE-2023-22508
Atlassian Confluence CVE-2023-22515 Vulnerability (CVE-2023-22515) CVE-2023-22515
Atlassian Confluence CVE-2024-21683 Vulnerability (CVE-2024-21683) CVE-2024-21683
Atlassian Confluence Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2015-8399) CVE-2015-8399
Atlassian Confluence Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2016-6668) CVE-2016-6668
Atlassian Confluence Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2017-7415) CVE-2017-7415
Atlassian Confluence Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2018-20237) CVE-2018-20237
Atlassian Confluence Improper Control of Dynamically-Managed Code Resources Vulnerability (CVE-2019-15006) CVE-2019-15006
Atlassian Confluence Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2023-22526) CVE-2023-22526
Atlassian Confluence Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2024-21672) CVE-2024-21672
Atlassian Confluence Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2024-21673) CVE-2024-21673
Atlassian Confluence Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2024-21674) CVE-2024-21674
Atlassian Confluence Improper Input Validation Vulnerability (CVE-2018-13389) CVE-2018-13389
Atlassian Confluence Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Vulnerability (CVE-2019-3394) CVE-2019-3394
Atlassian Confluence Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Vulnerability (CVE-2019-3396) CVE-2019-3396
Atlassian Confluence Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Vulnerability (CVE-2019-3398) CVE-2019-3398
Atlassian Confluence Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2015-8398) CVE-2015-8398
Atlassian Confluence Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2016-4317) CVE-2016-4317
Atlassian Confluence Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2016-6283) CVE-2016-6283
Atlassian Confluence Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2017-16856) CVE-2017-16856
Atlassian Confluence Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2017-18083) CVE-2017-18083
Atlassian Confluence Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2017-18084) CVE-2017-18084
Atlassian Confluence Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2017-18085) CVE-2017-18085
Atlassian Confluence Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2017-18086) CVE-2017-18086
Atlassian Confluence Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2018-20239) CVE-2018-20239
Atlassian Confluence Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2019-20102) CVE-2019-20102
Atlassian Confluence Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2020-14175) CVE-2020-14175
Atlassian Confluence Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2020-29444) CVE-2020-29444
Atlassian Confluence Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2020-36290) CVE-2020-36290
Atlassian Confluence Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') Vulnerability (CVE-2020-4027) CVE-2020-4027