Go
Pages44
Integer overflow in allocation size calculations
Integer overflow in allocation size calculations
Binding to all network interfaces
Binding network interfaces beyond the service's intended access scope
Plaintext logging of sensitive information
Plaintext logging of sensitive information
Use of a fixed OAuth2 state value
Use of a fixed OAuth2 state value
Sensitive cookie set without the Secure flag
Sensitive cookie set without the Secure flag
Cookie exposure without HttpOnly
Script access to sensitive cookies without HttpOnly
Denial of service from decompression bombs
Unbounded resource consumption during decompression
TLS certificate verification disabled
TLS certificate verification disabled
Information exposure through directory listings
File and information exposure through directory listings
Email header and body injection
Email header and body injection
Cleartext transmission of sensitive information
Cleartext transmission of sensitive information
Incorrect integer conversions
Incorrect integer conversions
An SSLv3 minimum-version setting
An SSLv3 minimum-version setting
Insecure temporary file creation
Insecure temporary file creation
Weak or risky TLS cipher suites
Weak or risky TLS cipher suites
Log injection
Log injection
Weak password hashing with MD5
Use of a broken or risky cryptographic algorithm
Parsing user-controlled JWTs without signature verification
Parsing user-controlled JWTs without signature verification
Review the minimum TLS version
Review the minimum TLS version
Open redirect
Open redirect
Unsafe password storage or use of fast hashes
Unsafe password storage or use of fast hashes
Exposed pprof debugging endpoints
Exposed pprof debugging endpoints
Bypassing incomplete regular-expression validation
Bypassing incomplete regular-expression validation
Bit shifts at or beyond the integer type width
Bit shifts at or beyond the integer type width
SQL injection
SQL injection
Key exchange without server identity verification
Key exchange without server identity verification
Server-side request forgery (SSRF)
Server-side request forgery (SSRF)
Stack trace exposure
Stack trace exposure
Cross-site scripting (XSS)
Cross-site scripting (XSS)
Cross-site scripting (XSS)
Cross-site scripting (XSS)
Excessive memory allocation from user input
Excessive memory allocation from user input
Cross-site scripting (XSS)
Cross-site scripting (XSS)
Cross-site scripting (XSS)
Cross-site scripting (XSS)
Cross-site scripting (XSS)
Cross-site scripting
Unsafe symbolic links during archive extraction
Unsafe symbolic-link creation during archive extraction
Use of the unsafe package
Use of the unsafe package
Use of weak cryptographic algorithms
Use of weak cryptographic algorithms
Cryptographically weak random generation
Cryptographically weak random generation
Weak RSA key length
Weak RSA key length
XPath injection
XPath injection
XML external entity (XXE) vulnerability
XML external entity (XXE) vulnerability
Zip Slip archive path traversal
Zip Slip archive path traversal
Operating system command injection
Operating system command injection
Path traversal
Path traversal