angularjs_insecure_url_whitelist_clean.js |
Clean
|
angularjs_insecure_url_whitelist |
β False positive
|
api_key_in_url_clean.js |
Clean
|
API Key in URL |
β Clean (expected)
|
api_key_in_url_clean.py |
Clean
|
API Key in URL |
β Clean (expected)
|
arithmetic_extreme_values_clean.java |
Clean
|
arithmetic_extreme_values |
β Clean (expected)
|
arithmetic_tainted_clean.java |
Clean
|
arithmetic_tainted |
β False positive
|
arithmetic_uncontrolled_clean.java |
Clean
|
arithmetic_uncontrolled |
β Clean (expected)
|
array_construction_tainted_clean.java |
Clean
|
array_construction_tainted |
β Clean (expected)
|
array_index_validation_clean.java |
Clean
|
array_index_validation |
β Clean (expected)
|
aspnet_debug_enabled_clean.cs |
Clean
|
aspnet_debug_enabled |
β Clean (expected)
|
aspnet_directory_listing_clean.cs |
Clean
|
aspnet_directory_listing |
β Clean (expected)
|
aspnet_max_request_length_clean.cs |
Clean
|
aspnet_max_request_length |
β Clean (expected)
|
assembly_path_injection_clean.cs |
Clean
|
assembly_path_injection |
β Clean (expected)
|
autoplay_media_clean.html |
Clean
|
Autoplaying media |
β Clean (expected)
|
bad_tag_filter_clean.js |
Clean
|
bad_tag_filter |
β Clean (expected)
|
bad_tag_filter_clean.py |
Clean
|
bad_tag_filter |
β Clean (expected)
|
base64_credentials_clean.py |
Clean
|
Base64 encoded credentials |
β Clean (expected)
|
base64_eval_clean.js |
Clean
|
Base64 obfuscated code execution |
β Clean (expected)
|
base64_eval_clean.py |
Clean
|
Base64 obfuscated code execution |
β Clean (expected)
|
base64_obfuscation_clean.js |
Clean
|
Suspicious base64 string decoded |
β Clean (expected)
|
batch_query.py |
Clean
|
Potential N+1 Query |
β Clean (expected)
|
broken_crypto_algorithm_clean.js |
Clean
|
broken_crypto_algorithm |
β Clean (expected)
|
build_artifact_leak_clean.js |
Clean
|
build_artifact_leak |
β Clean (expected)
|
button_no_aria_clean.html |
Clean
|
Button without aria-label |
β Clean (expected)
|
button_with_aria.html |
Clean
|
Button without aria-label |
β Clean (expected)
|
button_with_text.html |
Clean
|
Button without aria-label |
β Clean (expected)
|
cache_poisoning_clean.py |
Clean
|
Cache Poisoning |
β Clean (expected)
|
case_sensitive_middleware_path_clean.js |
Clean
|
case_sensitive_middleware_path |
β False positive
|
catch_all_exception_clean.py |
Clean
|
Catch-all exception |
β Clean (expected)
|
catch_all_exception_csharp_clean.cs |
Clean
|
Generic catch (C#) |
β Clean (expected)
|
catch_all_exception_java_clean.java |
Clean
|
Generic catch (Java) |
β Clean (expected)
|
catch_all_exception_php_clean.php |
Clean
|
Generic catch (PHP) |
β Clean (expected)
|
ci_curl_pipe_bash_clean.yml |
Clean
|
Remote script piped to shell |
β Clean (expected)
|
ci_debug_trace_enabled_clean.yml |
Clean
|
CI/CD debug logging enabled |
β Clean (expected)
|
ci_docker_privileged_clean.yml |
Clean
|
Privileged Docker container in CI/CD |
β Clean (expected)
|
ci_insecure_download_clean.yml |
Clean
|
Insecure HTTP download in CI/CD |
β Clean (expected)
|
ci_netcat_reverse_shell_clean.yml |
Clean
|
Netcat reverse shell in CI/CD script |
β Clean (expected)
|
class_manipulation.js |
Clean
|
Inline style in JS |
β Clean (expected)
|
cleartext_cookie_clean.js |
Clean
|
cleartext_cookie |
β Clean (expected)
|
cleartext_logging_clean.js |
Clean
|
cleartext_logging |
β Clean (expected)
|
cleartext_storage_class_clean.java |
Clean
|
cleartext_storage_class |
β False positive
|
cleartext_storage_cookie_clean.java |
Clean
|
cleartext_storage_cookie |
β Clean (expected)
|
cleartext_storage_csharp_clean.cs |
Clean
|
cleartext_storage_csharp |
β Clean (expected)
|
cleartext_storage_properties_clean.java |
Clean
|
cleartext_storage_properties |
β Clean (expected)
|
cleartext_storage_sensitive_clean.js |
Clean
|
cleartext_storage_sensitive |
β Clean (expected)
|
cleartext_storage_sensitive_clean.py |
Clean
|
cleartext_storage_sensitive |
β Clean (expected)
|
client_side_auth_clean.js |
Clean
|
Client-side access control |
β Clean (expected)
|
client_side_ssrf_clean.js |
Clean
|
client_side_ssrf |
β Clean (expected)
|
command_injection_csharp_clean.cs |
Clean
|
Command injection (C#) |
β Clean (expected)
|
command_injection_java_broad_clean.java |
Clean
|
Command Injection (Java) |
β False positive
|
command_injection_java_clean.java |
Clean
|
Command injection (Java) |
β Clean (expected)
|
command_injection_php_clean.php |
Clean
|
Command injection (PHP) |
β Clean (expected)
|
comparison_wider_type_clean.java |
Clean
|
comparison_wider_type |
β Clean (expected)
|
conditional_bypass_clean.js |
Clean
|
conditional_bypass |
β Clean (expected)
|
conditional_bypass_csharp_clean.cs |
Clean
|
conditional_bypass_csharp |
β Clean (expected)
|
conditional_bypass_java_clean.java |
Clean
|
conditional_bypass_java |
β Clean (expected)
|
console_log_residual_clean.js |
Clean
|
Residual console.log |
β Clean (expected)
|
console_write_csharp_clean.cs |
Clean
|
Console.Write in production (C#) |
β Clean (expected)
|
cookie_broad_domain_clean.cs |
Clean
|
cookie_broad_domain |
β Clean (expected)
|
cookie_broad_path_clean.cs |
Clean
|
cookie_broad_path |
β Clean (expected)
|
cookie_injection_clean.py |
Clean
|
cookie_injection |
β Clean (expected)
|
correct_tabindex.html |
Clean
|
Positive tabindex |
β Clean (expected)
|
cors_credentials_wildcard_clean.js |
Clean
|
CORS wildcard with credentials |
β Clean (expected)
|
cors_permissive_csharp_clean.cs |
Clean
|
Permissive CORS (C#) |
β Clean (expected)
|
crud_without_ownership_clean.js |
Clean
|
CRUD without ownership check |
β Clean (expected)
|
cs_deep_nesting_clean 2.cs |
Clean
|
|
β Clean (expected)
|
cs_deep_nesting_clean.cs |
Clean
|
Excessive nesting depth (C#, 6+ levels) |
β Clean (expected)
|
cs_empty_catch_block_clean 2.cs |
Clean
|
|
β Clean (expected)
|
cs_empty_catch_block_clean.cs |
Clean
|
Empty catch block (C#) |
β Clean (expected)
|
cs_high_coupling_clean 2.cs |
Clean
|
|
β Clean (expected)
|
cs_high_coupling_clean.cs |
Clean
|
High coupling β too many C# interfaces (SonarQube S1200) |
β Clean (expected)
|
cs_magic_number_clean 2.cs |
Clean
|
|
β Clean (expected)
|
cs_magic_number_clean.cs |
Clean
|
Magic number in comparison (C#) |
β Clean (expected)
|
cs_string_format_legacy_clean 2.cs |
Clean
|
|
β Clean (expected)
|
cs_string_format_legacy_clean.cs |
Clean
|
string.Format() instead of interpolation (C#) |
β Clean (expected)
|
cs_too_many_params_clean 2.cs |
Clean
|
|
β Clean (expected)
|
cs_too_many_params_clean.cs |
Clean
|
Too many C# method parameters (6+) |
β Clean (expected)
|
csrf_missing_flask_clean 2.py |
Clean
|
|
β False positive
|
csrf_missing_flask_clean.py |
Clean
|
Missing CSRF protection (Flask) |
β Clean (expected)
|
csv_injection_clean.py |
Clean
|
CSV Formula Injection |
β Clean (expected)
|
dangerous_eval_clean.py |
Clean
|
Dangerous Eval/Exec |
β Clean (expected)
|
dangerous_function_java_clean.java |
Clean
|
dangerous_function_java |
β Clean (expected)
|
data_uri_html_clean.js |
Clean
|
Data URI with HTML content |
β Clean (expected)
|
data_uri_html_tag_clean.html |
Clean
|
Data URI HTML in tag |
β Clean (expected)
|
db_connection_string_credentials_clean 2.py |
Clean
|
|
β Clean (expected)
|
db_connection_string_credentials_clean.py |
Clean
|
DB connection string with credentials (Python) |
β Clean (expected)
|
db_connection_string_credentials_js_clean 2.js |
Clean
|
|
β Clean (expected)
|
db_connection_string_credentials_js_clean.js |
Clean
|
DB connection string with credentials (JavaScript) |
β Clean (expected)
|
db_error_exposed_csharp_clean 2.cs |
Clean
|
|
β Clean (expected)
|
db_error_exposed_csharp_clean.cs |
Clean
|
DB error exposed in response (C#) |
β Clean (expected)
|
db_error_exposed_java_clean 2.java |
Clean
|
|
β Clean (expected)
|
db_error_exposed_java_clean.java |
Clean
|
DB error exposed in response (Java) |
β Clean (expected)
|
db_error_exposed_php_clean 2.php |
Clean
|
|
β False positive
|
db_error_exposed_php_clean.php |
Clean
|
DB error exposed in response (PHP) |
β Clean (expected)
|
db_error_exposed_python_clean 2.py |
Clean
|
|
β Clean (expected)
|
db_error_exposed_python_clean.py |
Clean
|
DB error exposed in response (Python) |
β Clean (expected)
|
db_logic_controller_csharp_clean.cs |
Clean
|
DB logic in controller (C#) |
β Clean (expected)
|
db_logic_controller_java_clean.java |
Clean
|
DB logic in controller (Java) |
β Clean (expected)
|
db_logic_controller_php_clean.php |
Clean
|
DB logic in controller (PHP) |
β Clean (expected)
|
db_superuser_connection_csharp_clean 2.cs |
Clean
|
|
β Clean (expected)
|
db_superuser_connection_csharp_clean.cs |
Clean
|
DB connection as superuser (C#) |
β Clean (expected)
|
db_superuser_connection_java_clean 2.java |
Clean
|
|
β Clean (expected)
|
db_superuser_connection_java_clean.java |
Clean
|
DB connection as superuser (Java) |
β Clean (expected)
|
db_superuser_connection_python_clean 2.py |
Clean
|
|
β Clean (expected)
|
db_superuser_connection_python_clean.py |
Clean
|
DB connection as superuser (Python) |
β Clean (expected)
|
db_tls_disabled_java_clean 2.java |
Clean
|
|
β Clean (expected)
|
db_tls_disabled_java_clean.java |
Clean
|
DB connection without TLS (Java) |
β Clean (expected)
|
db_tls_disabled_js_clean 2.js |
Clean
|
|
β Clean (expected)
|
db_tls_disabled_js_clean.js |
Clean
|
DB connection without TLS (JavaScript) |
β Clean (expected)
|
db_tls_disabled_python_clean 2.py |
Clean
|
|
β False positive
|
db_tls_disabled_python_clean.py |
Clean
|
DB connection without TLS (Python) |
β Clean (expected)
|
debug_false.py |
Clean
|
Debug mode enabled |
β Clean (expected)
|
debug_mode_clean.py |
Clean
|
Debug mode enabled |
β Clean (expected)
|
default_credentials_clean.py |
Clean
|
Default Credentials |
β Clean (expected)
|
dependabot_insecure_exec_clean.yml |
Clean
|
Dependabot insecure external code execution |
β Clean (expected)
|
dependency_confusion_clean.js |
Clean
|
Dependency Confusion |
β Clean (expected)
|
dependency_confusion_clean.py |
Clean
|
Dependency Confusion |
β Clean (expected)
|
deprecated_api_clean.py |
Clean
|
Deprecated API |
β Clean (expected)
|
deprecated_api_csharp_clean.cs |
Clean
|
Deprecated API (C#) |
β Clean (expected)
|
deprecated_api_java_clean.java |
Clean
|
Deprecated API (Java) |
β Clean (expected)
|
deprecated_api_javascript_clean.js |
Clean
|
Deprecated API (JavaScript) |
β Clean (expected)
|
deprecated_api_php_clean.php |
Clean
|
Deprecated API (PHP) |
β Clean (expected)
|
destructive_without_backup_clean.py |
Clean
|
Destructive Operation Without Backup |
β Clean (expected)
|
different_kinds_comparison_bypass_clean.js |
Clean
|
different_kinds_comparison_bypass |
β Clean (expected)
|
disable_certificate_validation_clean.js |
Clean
|
disable_certificate_validation |
β Clean (expected)
|
django_clean.py |
Clean
|
@csrf_exempt decorator (Django) |
β Clean (expected)
|
django_csrf_exempt_clean.py |
Clean
|
@csrf_exempt decorator (Django) |
β Clean (expected)
|
django_debug_enabled_clean.py |
Clean
|
DEBUG = True (Django) |
β Clean (expected)
|
django_mark_safe_xss_clean.py |
Clean
|
Django mark_safe() β XSS risk |
β Clean (expected)
|
django_secret_key_weak_clean.py |
Clean
|
Hardcoded SECRET_KEY (Django) |
β Clean (expected)
|
docker_latest_tag_clean.yml |
Clean
|
Docker image with :latest tag |
β Clean (expected)
|
dockerfile_copy_all_clean |
Clean
|
COPY . . in Dockerfile |
β Clean (expected)
|
dockerfile_non_root |
Clean
|
Dockerfile runs as root |
β Clean (expected)
|
dockerfile_unpinned_base_clean |
Clean
|
Unpinned base image |
β Clean (expected)
|
dom_clobbering_clean.html |
Clean
|
DOM Clobbering |
β Clean (expected)
|
dom_manipulation_loop_clean.js |
Clean
|
DOM manipulation in loop |
β Clean (expected)
|
dom_pseudo_eval_clean.js |
Clean
|
dom_pseudo_eval |
β Clean (expected)
|
dont_install_root_cert_clean.cs |
Clean
|
dont_install_root_cert |
β Clean (expected)
|
double_escaping_clean.js |
Clean
|
double_escaping |
β Clean (expected)
|
dynamic_import_clean.py |
Clean
|
Dynamic import |
β Clean (expected)
|
ecb_cipher_mode_clean.py |
Clean
|
Insecure ECB cipher mode |
β Clean (expected)
|
ecb_mode_csharp_clean.cs |
Clean
|
ecb_mode_csharp |
β Clean (expected)
|
elasticsearch_query_injection_clean 2.py |
Clean
|
|
β Clean (expected)
|
elasticsearch_query_injection_clean.py |
Clean
|
Elasticsearch query injection (Python) |
β Clean (expected)
|
electron_insecure_content_clean.js |
Clean
|
electron_insecure_content |
β Clean (expected)
|
electron_node_integration_clean.js |
Clean
|
electron_node_integration |
β Clean (expected)
|
electron_web_security_disabled_clean.js |
Clean
|
electron_web_security_disabled |
β Clean (expected)
|
empty_password_config_clean.js |
Clean
|
empty_password_config |
β Clean (expected)
|
env_aws_key.py |
Clean
|
Hardcoded secret |
β Clean (expected)
|
env_github_token.py |
Clean
|
Hardcoded secret |
β Clean (expected)
|
error_suppressor_php_clean.php |
Clean
|
Error suppressor (PHP @) |
β Clean (expected)
|
eval_injection_php_clean.php |
Clean
|
Code injection (PHP) |
β Clean (expected)
|
eval_template_literal_clean.js |
Clean
|
eval() with template literal |
β Clean (expected)
|
event_listeners_cleanup.js |
Clean
|
Event listeners not cleaned |
β Clean (expected)
|
event_listeners_not_cleaned_clean.js |
Clean
|
Event listeners not cleaned |
β Clean (expected)
|
exec_relative_path_clean.java |
Clean
|
exec_relative_path |
β Clean (expected)
|
exec_tainted_environment_clean.java |
Clean
|
exec_tainted_environment |
β Clean (expected)
|
exec_unescaped_clean.java |
Clean
|
exec_unescaped |
β Clean (expected)
|
exposed_test_endpoint_clean.py |
Clean
|
Exposed Test/Debug Endpoint |
β Clean (expected)
|
exposure_private_information_clean.cs |
Clean
|
exposure_private_information |
β Clean (expected)
|
exposure_transmitted_data_clean.cs |
Clean
|
exposure_transmitted_data |
β Clean (expected)
|
express_clean.js |
Clean
|
Missing Helmet middleware (Express) |
β Clean (expected)
|
express_cors_wildcard_clean.js |
Clean
|
Permissive CORS configuration (Express) |
β Clean (expected)
|
express_no_csrf_clean.js |
Clean
|
Express without CSRF protection |
β Clean (expected)
|
express_no_helmet_clean.js |
Clean
|
Missing Helmet middleware (Express) |
β Clean (expected)
|
extract_usage_php_clean.php |
Clean
|
Variable overwrite (PHP extract) |
β Clean (expected)
|
file_access_to_http_clean.js |
Clean
|
file_access_to_http |
β Clean (expected)
|
file_inclusion_php_clean.php |
Clean
|
File inclusion (PHP) |
β Clean (expected)
|
file_short.py |
Clean
|
File too long |
β Clean (expected)
|
file_too_long_clean.cs |
Clean
|
File too long |
β Clean (expected)
|
file_too_long_clean.java |
Clean
|
File too long |
β Clean (expected)
|
file_too_long_clean.php |
Clean
|
File too long |
β Clean (expected)
|
file_too_long_clean.py |
Clean
|
File too long |
β Clean (expected)
|
file_upload_no_validation_clean.py |
Clean
|
File Upload Without Validation |
β Clean (expected)
|
file_upload_validated.py |
Clean
|
File Upload Without Validation |
β Clean (expected)
|
filesystem_race_condition_clean.js |
Clean
|
filesystem_race_condition |
β Clean (expected)
|
flask_clean.py |
Clean
|
Debug mode enabled (Flask) |
β Clean (expected)
|
flask_debug_enabled_clean.py |
Clean
|
Debug mode enabled (Flask) |
β Clean (expected)
|
flask_secret_key_weak_clean.py |
Clean
|
Hardcoded secret_key (Flask) |
β Clean (expected)
|
focus_outline_kept.js |
Clean
|
Focus outline removed |
β Clean (expected)
|
focus_outline_removed_clean.html |
Clean
|
Focus outline removed |
β Clean (expected)
|
focus_outline_removed_clean.js |
Clean
|
Focus outline removed |
β Clean (expected)
|
format_string_safe.py |
Clean
|
Format String Vulnerability |
β Clean (expected)
|
format_string_safe_java.java |
Clean
|
Format String Vulnerability |
β Clean (expected)
|
format_string_vuln_clean.java |
Clean
|
Format String Vulnerability |
β Clean (expected)
|
format_string_vuln_clean.py |
Clean
|
Format String Vulnerability |
β Clean (expected)
|
fstring_in_logging_clean.py |
Clean
|
F-string in Logging |
β Clean (expected)
|
functionality_untrusted_domain_clean.js |
Clean
|
functionality_untrusted_domain |
β False positive
|
functionality_untrusted_source_clean.js |
Clean
|
functionality_untrusted_source |
β Clean (expected)
|
gha_actor_check_bypass_clean.yml |
Clean
|
Bypassable actor-based security gate |
β Clean (expected)
|
gha_artifact_poisoning_clean.yml |
Clean
|
Artifact poisoning via workflow_run |
β Clean (expected)
|
gha_cache_poisoning_clean.yml |
Clean
|
Cache poisoning risk in release workflow |
β False positive
|
gha_confused_deputy_clean.yml |
Clean
|
Confused deputy auto-merge bypass |
β Clean (expected)
|
gha_credentials_on_disk_clean.yml |
Clean
|
Git credentials persisted on disk |
β Clean (expected)
|
gha_dangerous_artefact_clean.yml |
Clean
|
Sensitive files uploaded as artifact |
β Clean (expected)
|
gha_deprecated_commands_clean.yml |
Clean
|
Deprecated workflow commands |
β Clean (expected)
|
gha_excessive_permissions_clean.txt |
Clean
|
Excessive workflow permissions |
β Clean (expected)
|
gha_excessive_permissions_clean.yml |
Clean
|
Excessive workflow permissions |
β Clean (expected)
|
gha_expression_injection_clean.txt |
Clean
|
GitHub Actions expression injection |
β Clean (expected)
|
gha_expression_injection_clean.yml |
Clean
|
GitHub Actions expression injection |
β Clean (expected)
|
gha_github_app_no_revoke_clean.yml |
Clean
|
GitHub App token not revoked after job |
β Clean (expected)
|
gha_github_env_write_clean.yml |
Clean
|
Untrusted data written to GITHUB_ENV |
β Clean (expected)
|
gha_insecure_commands_env_clean.yml |
Clean
|
Insecure workflow commands enabled |
β Clean (expected)
|
gha_job_all_secrets_clean.yml |
Clean
|
All secrets serialized in workflow |
β Clean (expected)
|
gha_local_action_clean.yml |
Clean
|
Local action usage |
β Clean (expected)
|
gha_missing_permissions_clean.txt |
Clean
|
Missing permissions block |
β Clean (expected)
|
gha_missing_permissions_clean.yml |
Clean
|
Missing permissions block |
β Clean (expected)
|
gha_secret_in_log_clean.yml |
Clean
|
Secret printed in workflow log |
β Clean (expected)
|
gha_secrets_bypass_redaction_clean.yml |
Clean
|
Secrets redaction bypass via JSON |
β Clean (expected)
|
gha_secrets_without_environment_clean.yml |
Clean
|
Secrets used without environment gate on risky trigger |
β Clean (expected)
|
gha_self_hosted_runner_clean.yml |
Clean
|
Self-hosted runner on public repository |
β Clean (expected)
|
gha_unguarded_comment_trigger_clean.txt |
Clean
|
Unguarded comment trigger |
β Clean (expected)
|
gha_unguarded_comment_trigger_clean.yml |
Clean
|
Unguarded comment trigger |
β Clean (expected)
|
gha_unsound_condition_clean.yml |
Clean
|
Unsound if: condition with block scalar |
β Clean (expected)
|
gha_version_comment_missing_clean.yml |
Clean
|
Pinned action SHA without version comment |
β Clean (expected)
|
gha_workflow_dispatch_inputs_clean.yml |
Clean
|
workflow_dispatch with user inputs |
β Clean (expected)
|
gitlab_allow_failure_security_clean.yml |
Clean
|
Security job with allow_failure: true |
β False positive
|
gitlab_double_pipeline_clean.yml |
Clean
|
GitLab CI duplicate pipeline rules |
β False positive
|
gitlab_script_secrets_echo_clean.yml |
Clean
|
GitLab CI token printed to log |
β Clean (expected)
|
gitlab_unsafe_variables_clean.yml |
Clean
|
Unprotected GitLab CI variable |
β Clean (expected)
|
graphql_batching_attack_clean.js |
Clean
|
GraphQL Batching Attack |
β Clean (expected)
|
graphql_introspection_disabled.js |
Clean
|
GraphQL Introspection Enabled |
β Clean (expected)
|
graphql_introspection_disabled_python.py |
Clean
|
GraphQL Introspection Enabled |
β Clean (expected)
|
graphql_introspection_enabled_clean.js |
Clean
|
GraphQL Introspection Enabled |
β Clean (expected)
|
graphql_introspection_enabled_clean.py |
Clean
|
GraphQL Introspection Enabled |
β Clean (expected)
|
graphql_no_depth_limit_clean.js |
Clean
|
GraphQL Without Depth Limit |
β Clean (expected)
|
graphql_no_depth_limit_clean.py |
Clean
|
GraphQL Without Depth Limit |
β Clean (expected)
|
graphql_with_depth_limit.js |
Clean
|
GraphQL Without Depth Limit |
β Clean (expected)
|
groovy_injection_clean.java |
Clean
|
groovy_injection |
β Clean (expected)
|
hardcoded_connection_string_clean.cs |
Clean
|
hardcoded_connection_string |
β Clean (expected)
|
hardcoded_connection_string_java_clean 2.java |
Clean
|
|
β Clean (expected)
|
hardcoded_connection_string_java_clean.java |
Clean
|
Hardcoded DB credentials (Java) |
β Clean (expected)
|
hardcoded_connection_string_php_clean 2.php |
Clean
|
|
β Clean (expected)
|
hardcoded_connection_string_php_clean.php |
Clean
|
Hardcoded DB credentials (PHP) |
β Clean (expected)
|
hardcoded_data_as_code_clean.js |
Clean
|
hardcoded_data_as_code |
β Clean (expected)
|
hardcoded_encryption_key_clean.cs |
Clean
|
hardcoded_encryption_key |
β Clean (expected)
|
hardcoded_internal_ip_clean.py |
Clean
|
Hardcoded Internal IP Address |
β Clean (expected)
|
hardcoded_iv_nonce_clean.py |
Clean
|
Hardcoded IV/Nonce |
β Clean (expected)
|
hardcoded_secret_cicd_clean.yml |
Clean
|
Hardcoded secret in CI/CD configuration |
β Clean (expected)
|
hardcoded_secret_clean.js |
Clean
|
Hardcoded secret |
β Clean (expected)
|
hardcoded_secret_clean.py |
Clean
|
Hardcoded secret |
β Clean (expected)
|
hardcoded_tmp_path_clean.py |
Clean
|
Hardcoded /tmp path |
β Clean (expected)
|
hardcoded_ui_string_clean.html |
Clean
|
Hardcoded UI string |
β Clean (expected)
|
hardcoded_ui_string_clean.js |
Clean
|
Hardcoded UI string |
β Clean (expected)
|
header_injection_clean.py |
Clean
|
header_injection |
β Clean (expected)
|
heading_skip_level_clean.html |
Clean
|
Heading skip level |
β Clean (expected)
|
homebrew_auth_clean.py |
Clean
|
Homebrew authentication |
β Clean (expected)
|
host_header_poisoning_clean.js |
Clean
|
host_header_poisoning |
β Clean (expected)
|
hsts_django_clean.py |
Clean
|
Missing HSTS Header |
β Clean (expected)
|
html_aria_hidden_focusable_clean.html |
Clean
|
Focusable element hidden with aria-hidden |
β Clean (expected)
|
html_autocomplete_invalid_clean.html |
Clean
|
Non-standard autocomplete value |
β Clean (expected)
|
html_button_missing_type_clean.html |
Clean
|
HTML button without type attribute |
β Clean (expected)
|
html_deprecated_tag_clean.html |
Clean
|
Deprecated HTML tag |
β Clean (expected)
|
html_img_missing_dimensions_clean.html |
Clean
|
HTML image without dimensions (width/height) |
β Clean (expected)
|
html_inline_style_clean.html |
Clean
|
Inline CSS style (HTML) |
β Clean (expected)
|
html_input_button_empty_clean.html |
Clean
|
Button input without label (missing value) |
β Clean (expected)
|
html_invalid_aria_role_clean.html |
Clean
|
Empty ARIA role attribute |
β Clean (expected)
|
html_invalid_lang_value_clean.html |
Clean
|
Non-BCP-47 lang attribute value |
β Clean (expected)
|
html_missing_main_landmark_clean.html |
Clean
|
Missing <main> landmark |
β Clean (expected)
|
html_missing_meta_viewport_clean.html |
Clean
|
Missing viewport meta tag (HTML) |
β Clean (expected)
|
html_no_lang_clean.html |
Clean
|
HTML missing lang attribute |
β Clean (expected)
|
html_select_missing_label_clean.html |
Clean
|
Select without accessible label |
β Clean (expected)
|
html_target_blank_noreferrer_clean.html |
Clean
|
target="_blank" without rel="noopener noreferrer" |
β Clean (expected)
|
html_th_scope_missing_clean.html |
Clean
|
Table header without scope attribute |
β Clean (expected)
|
html_video_missing_captions_clean.html |
Clean
|
Video without caption track |
β Clean (expected)
|
html_viewport_zoom_disabled_clean.html |
Clean
|
User zoom disabled (viewport) |
β Clean (expected)
|
http_localhost.py |
Clean
|
HTTP without TLS |
β Clean (expected)
|
http_no_tls_clean.py |
Clean
|
HTTP without TLS |
β Clean (expected)
|
http_response_splitting_clean.java |
Clean
|
http_response_splitting |
β Clean (expected)
|
http_smuggling_clean.py |
Clean
|
HTTP request smuggling |
β Clean (expected)
|
http_to_file_access_clean.js |
Clean
|
http_to_file_access |
β False positive
|
https_url.py |
Clean
|
HTTP without TLS |
β Clean (expected)
|
idor_missing_ownership_clean.cs |
Clean
|
IDOR Missing Ownership |
β Clean (expected)
|
idor_missing_ownership_clean.py |
Clean
|
IDOR Missing Ownership |
β Clean (expected)
|
iframe_no_title_clean.html |
Clean
|
Iframe without title |
β Clean (expected)
|
img_decorative_no_role_clean.html |
Clean
|
Decorative image without role |
β Clean (expected)
|
img_no_alt_clean.html |
Clean
|
Image without alt text |
β Clean (expected)
|
img_with_alt.html |
Clean
|
Image without alt text |
β Clean (expected)
|
improper_code_sanitization_clean.js |
Clean
|
improper_code_sanitization |
β Clean (expected)
|
inappropriate_encoding_clean.cs |
Clean
|
inappropriate_encoding |
β Clean (expected)
|
incomplete_hostname_regexp_clean.js |
Clean
|
incomplete_hostname_regexp |
β Clean (expected)
|
incomplete_hostname_regexp_clean.py |
Clean
|
incomplete_hostname_regexp |
β Clean (expected)
|
incomplete_html_attribute_sanitization_clean.js |
Clean
|
incomplete_html_attribute_sanitization |
β Clean (expected)
|
incomplete_multichar_sanitization_clean.js |
Clean
|
incomplete_multichar_sanitization |
β Clean (expected)
|
incomplete_sanitization_clean.js |
Clean
|
incomplete_sanitization |
β Clean (expected)
|
incomplete_url_sanitization_clean.py |
Clean
|
incomplete_url_sanitization |
β Clean (expected)
|
incomplete_url_scheme_check_clean.js |
Clean
|
incomplete_url_scheme_check |
β Clean (expected)
|
incomplete_url_substring_sanitization_clean.js |
Clean
|
incomplete_url_substring_sanitization |
β Clean (expected)
|
incorrect_suffix_check_clean.js |
Clean
|
incorrect_suffix_check |
β Clean (expected)
|
indirect_command_injection_clean.js |
Clean
|
indirect_command_injection |
β Clean (expected)
|
infinite_loop_user_input_clean.java |
Clean
|
infinite_loop_user_input |
β Clean (expected)
|
inline_event_handler_clean.js |
Clean
|
Inline event handler |
β Clean (expected)
|
inline_event_handler_html_clean.html |
Clean
|
Inline event handler in HTML |
β Clean (expected)
|
inline_style_js_clean.js |
Clean
|
Inline style in JS |
β Clean (expected)
|
input_no_label_clean.html |
Clean
|
Input without label |
β Clean (expected)
|
input_with_label.html |
Clean
|
Input without label |
β Clean (expected)
|
insecure_basic_auth_clean.java |
Clean
|
insecure_basic_auth |
β Clean (expected)
|
insecure_bean_validation_clean.java |
Clean
|
insecure_bean_validation |
β Clean (expected)
|
insecure_cipher_clean.py |
Clean
|
Insecure cipher algorithm |
β Clean (expected)
|
insecure_cloud_config_clean.py |
Clean
|
Insecure Cloud Configuration |
β Clean (expected)
|
insecure_cookie_clean.cs |
Clean
|
Insecure cookie (missing HttpOnly/Secure) |
β False positive
|
insecure_cookie_clean.java |
Clean
|
Insecure cookie (missing HttpOnly/Secure) |
β Clean (expected)
|
insecure_cookie_clean.js |
Clean
|
Insecure cookie (missing HttpOnly/Secure) |
β Clean (expected)
|
insecure_cookie_clean.php |
Clean
|
Insecure cookie (missing HttpOnly/Secure) |
β False positive
|
insecure_cookie_clean.py |
Clean
|
Insecure cookie (missing HttpOnly/Secure) |
β Clean (expected)
|
insecure_cookie_flag_clean.java |
Clean
|
Insecure Cookie Flag |
β Clean (expected)
|
insecure_cookie_no_secure_clean.py |
Clean
|
Cookie without Secure flag |
β Clean (expected)
|
insecure_db_deserialization_python_clean 2.py |
Clean
|
|
β False positive
|
insecure_db_deserialization_python_clean.py |
Clean
|
Insecure DB deserialization (Python) |
β Clean (expected)
|
insecure_dependency_http_clean.js |
Clean
|
insecure_dependency_http |
β Clean (expected)
|
insecure_deserialize_call_clean.py |
Clean
|
Insecure deserialization call |
β Clean (expected)
|
insecure_download_clean.js |
Clean
|
insecure_download |
β Clean (expected)
|
insecure_javamail_clean.java |
Clean
|
insecure_javamail |
β Clean (expected)
|
insecure_ldap_auth_clean.java |
Clean
|
insecure_ldap_auth |
β Clean (expected)
|
insecure_local_storage_clean.js |
Clean
|
Insecure Local Storage |
β Clean (expected)
|
insecure_maven_dependency_clean.java |
Clean
|
insecure_maven_dependency |
β Clean (expected)
|
insecure_random_clean.js |
Clean
|
Insecure RNG |
β Clean (expected)
|
insecure_sql_connection_clean.cs |
Clean
|
insecure_sql_connection |
β Clean (expected)
|
insecure_ssl_version_clean.py |
Clean
|
Insecure SSL/TLS version |
β Clean (expected)
|
insecure_temp_file_clean.js |
Clean
|
insecure_temp_file |
β Clean (expected)
|
insecure_temp_file_clean.py |
Clean
|
insecure_temp_file |
β Clean (expected)
|
insufficient_key_size_clean.js |
Clean
|
Insufficient Cryptographic Key Size |
β Clean (expected)
|
insufficient_key_size_clean.py |
Clean
|
Insufficient Cryptographic Key Size |
β Clean (expected)
|
insufficient_key_size_csharp_clean.cs |
Clean
|
insufficient_key_size_csharp |
β Clean (expected)
|
insufficient_key_size_java_clean.java |
Clean
|
insufficient_key_size_java |
β Clean (expected)
|
insufficient_password_hash_clean.js |
Clean
|
insufficient_password_hash |
β Clean (expected)
|
java_deep_nesting_clean 2.java |
Clean
|
|
β Clean (expected)
|
java_deep_nesting_clean.java |
Clean
|
Excessive nesting depth (Java, 6+ levels) |
β Clean (expected)
|
java_empty_catch_block_clean 2.java |
Clean
|
|
β False positive
|
java_empty_catch_block_clean.java |
Clean
|
Empty catch block (Java) |
β Clean (expected)
|
java_public_field_clean 2.java |
Clean
|
|
β Clean (expected)
|
java_public_field_clean.java |
Clean
|
Non-constant public field (Java) |
β Clean (expected)
|
java_string_concat_loop_clean 2.java |
Clean
|
|
β Clean (expected)
|
java_string_concat_loop_clean.java |
Clean
|
String concatenation in loop (Java) |
β Clean (expected)
|
java_too_many_params_clean 2.java |
Clean
|
|
β Clean (expected)
|
java_too_many_params_clean.java |
Clean
|
Too many Java method parameters (6+) |
β Clean (expected)
|
java_utility_class_constructor_clean 2.java |
Clean
|
|
β Clean (expected)
|
java_utility_class_constructor_clean.java |
Clean
|
Java utility class without private constructor |
β Clean (expected)
|
javascript_uri_clean.js |
Clean
|
javascript: URI β XSS |
β Clean (expected)
|
javascript_uri_html_clean.html |
Clean
|
javascript: URI in HTML attribute |
β Clean (expected)
|
jexl_injection_clean.java |
Clean
|
jexl_injection |
β False positive
|
jinja2_autoescape_false_clean.py |
Clean
|
jinja2_autoescape_false |
β Clean (expected)
|
jndi_injection_java_clean.java |
Clean
|
JNDI Injection (Log4Shell) |
β Clean (expected)
|
js_cognitive_complexity_clean 2.js |
Clean
|
|
β Clean (expected)
|
js_cognitive_complexity_clean.js |
Clean
|
High cognitive complexity (JavaScript) |
β Clean (expected)
|
js_debugger_statement_clean 2.js |
Clean
|
|
β Clean (expected)
|
js_debugger_statement_clean.js |
Clean
|
Debugger statement in production (JavaScript) |
β Clean (expected)
|
js_deep_nesting_clean 2.js |
Clean
|
|
β Clean (expected)
|
js_deep_nesting_clean.js |
Clean
|
Excessive nesting depth (JavaScript, 6+ levels) |
β Clean (expected)
|
js_empty_catch_block_clean 2.js |
Clean
|
|
β Clean (expected)
|
js_empty_catch_block_clean.js |
Clean
|
Empty catch block (JavaScript) |
β Clean (expected)
|
js_no_var_clean 2.js |
Clean
|
|
β Clean (expected)
|
js_no_var_clean.js |
Clean
|
Use of var keyword (JavaScript) |
β Clean (expected)
|
js_too_many_params_clean 2.js |
Clean
|
|
β Clean (expected)
|
js_too_many_params_clean.js |
Clean
|
Too many JavaScript function parameters (6+) |
β Clean (expected)
|
jsx_anchor_href_invalid_clean.jsx |
Clean
|
JSX link with invalid href (href="#" or javascript:) |
β Clean (expected)
|
jsx_img_missing_alt_clean.jsx |
Clean
|
JSX image without alt prop (WCAG 1.1.1) |
β Clean (expected)
|
jsx_label_missing_control_clean.jsx |
Clean
|
JSX label without associated control (missing htmlFor) |
β Clean (expected)
|
jsx_no_access_key_clean.jsx |
Clean
|
accessKey used (JSX) |
β Clean (expected)
|
jsx_no_autofocus_clean.jsx |
Clean
|
autoFocus used (JSX) |
β Clean (expected)
|
jsx_tabindex_positive_clean.jsx |
Clean
|
Positive tabIndex (JSX, WCAG 2.4.3) |
β Clean (expected)
|
jwt_env_secret.py |
Clean
|
JWT Hardcoded Secret |
β Clean (expected)
|
jwt_hardcoded_secret_clean.py |
Clean
|
JWT Hardcoded Secret |
β Clean (expected)
|
jwt_missing_verification_clean.js |
Clean
|
jwt_missing_verification |
β Clean (expected)
|
jwt_none_algorithm_clean.js |
Clean
|
JWT None Algorithm |
β Clean (expected)
|
jwt_none_algorithm_clean.py |
Clean
|
JWT None Algorithm |
β Clean (expected)
|
jwt_safe_algorithm.py |
Clean
|
JWT None Algorithm |
β Clean (expected)
|
jwt_weak_secret_clean.js |
Clean
|
JWT weak secret |
β Clean (expected)
|
ldap_injection_csharp_clean.cs |
Clean
|
LDAP injection (C#) |
β Clean (expected)
|
ldap_injection_java_broad_clean.java |
Clean
|
LDAP Injection (Java) |
β False positive
|
ldap_injection_java_clean.java |
Clean
|
LDAP injection (Java) |
β Clean (expected)
|
ldap_injection_python_clean.py |
Clean
|
LDAP injection (Python) |
β Clean (expected)
|
ldap_java_clean.java |
Clean
|
LDAP injection (Java) |
β Clean (expected)
|
ldap_python_clean.py |
Clean
|
LDAP injection (Python) |
β Clean (expected)
|
link_no_text_clean.html |
Clean
|
Link without text |
β Clean (expected)
|
llm_output_to_sink_clean.py |
Clean
|
LLM Output to Sink |
β Clean (expected)
|
local_time_usage_clean.py |
Clean
|
Local Time Without Timezone |
β Clean (expected)
|
local_unvalidated_arithmetic_clean.cs |
Clean
|
local_unvalidated_arithmetic |
β False positive
|
lock_order_inconsistency_clean.java |
Clean
|
lock_order_inconsistency |
β False positive
|
log4shell_jndi_clean.java |
Clean
|
Log4Shell (JNDI) |
β Clean (expected)
|
log_forging_csharp_clean.cs |
Clean
|
log_forging_csharp |
β Clean (expected)
|
log_injection_clean.js |
Clean
|
Log Injection |
β Clean (expected)
|
log_injection_clean.py |
Clean
|
Log Injection |
β Clean (expected)
|
log_sanitized.py |
Clean
|
Log Injection |
β Clean (expected)
|
loop_bound_injection_clean.js |
Clean
|
loop_bound_injection |
β Clean (expected)
|
manual_createelement_clean.js |
Clean
|
Manual createElement |
β Clean (expected)
|
mass_assignment_csharp_clean 2.cs |
Clean
|
|
β Clean (expected)
|
mass_assignment_csharp_clean.cs |
Clean
|
Mass assignment (C#) |
β Clean (expected)
|
mass_assignment_java_clean 2.java |
Clean
|
|
β Clean (expected)
|
mass_assignment_java_clean.java |
Clean
|
Mass assignment (Java) |
β Clean (expected)
|
mass_assignment_js_clean 2.js |
Clean
|
|
β Clean (expected)
|
mass_assignment_js_clean.js |
Clean
|
Mass assignment (JavaScript) |
β Clean (expected)
|
mass_assignment_laravel_clean.php |
Clean
|
Mass assignment (Laravel) |
β Clean (expected)
|
mass_assignment_python_clean 2.py |
Clean
|
|
β Clean (expected)
|
mass_assignment_python_clean.py |
Clean
|
Mass assignment (Python) |
β Clean (expected)
|
missing_auth_decorator_clean.py |
Clean
|
Missing Authentication Decorator |
β Clean (expected)
|
missing_authorize_attribute_clean.cs |
Clean
|
missing_authorize_attribute |
β Clean (expected)
|
missing_change_management_clean.py |
Clean
|
Missing Change Management |
β Clean (expected)
|
missing_csp_header_clean.py |
Clean
|
Missing Content-Security-Policy |
β Clean (expected)
|
missing_data_retention_clean.py |
Clean
|
Missing Data Retention |
β Clean (expected)
|
missing_doctype_clean.html |
Clean
|
Missing DOCTYPE declaration |
β Clean (expected)
|
missing_global_error_handler_clean.cs |
Clean
|
missing_global_error_handler |
β Clean (expected)
|
missing_health_check_clean.py |
Clean
|
Missing Health Check Endpoint |
β Clean (expected)
|
missing_hsts_clean.py |
Clean
|
Missing HSTS Header |
β Clean (expected)
|
missing_jwt_signature_check_clean.java |
Clean
|
missing_jwt_signature_check |
β Clean (expected)
|
missing_mfa_csharp_clean.cs |
Clean
|
Missing MFA (C#) |
β Clean (expected)
|
missing_mfa_java_clean.java |
Clean
|
Missing MFA (Java) |
β False positive
|
missing_mfa_javascript_clean.js |
Clean
|
Missing MFA (JavaScript) |
β Clean (expected)
|
missing_mfa_php_clean.php |
Clean
|
Missing MFA (PHP) |
β Clean (expected)
|
missing_mfa_python_clean.py |
Clean
|
Missing MFA (Python) |
β Clean (expected)
|
missing_monitoring_clean.py |
Clean
|
Missing Monitoring/Logging |
β Clean (expected)
|
missing_pkce_oauth_clean.js |
Clean
|
Missing PKCE (OAuth) |
β Clean (expected)
|
missing_rate_limit_clean.js |
Clean
|
Missing rate limiting |
β Clean (expected)
|
missing_regexp_anchor_clean.js |
Clean
|
missing_regexp_anchor |
β Clean (expected)
|
missing_security_docs_clean.py |
Clean
|
Undocumented Security Function |
β Clean (expected)
|
missing_session_timeout_clean.py |
Clean
|
Missing Session Timeout |
β Clean (expected)
|
missing_skip_link_clean.html |
Clean
|
Missing skip navigation link |
β Clean (expected)
|
missing_sri_clean.html |
Clean
|
Missing Subresource Integrity |
β Clean (expected)
|
missing_timeout_clean.py |
Clean
|
Missing request timeout |
β Clean (expected)
|
missing_x_frame_options_clean.js |
Clean
|
missing_x_frame_options |
β Clean (expected)
|
missing_x_frame_options_csharp_clean.cs |
Clean
|
missing_x_frame_options_csharp |
β Clean (expected)
|
missing_xml_validation_clean.cs |
Clean
|
missing_xml_validation |
β False positive
|
modern_api.py |
Clean
|
Deprecated API |
β Clean (expected)
|
mongo_operator_injection_clean.js |
Clean
|
MongoDB NoSQL injection |
β Clean (expected)
|
mvel_injection_clean.java |
Clean
|
mvel_injection |
β False positive
|
n_plus_1_query_clean.py |
Clean
|
Potential N+1 Query |
β Clean (expected)
|
n_plus_1_query_java_clean.java |
Clean
|
N+1 query (Java) |
β Clean (expected)
|
n_plus_1_query_js_clean 2.js |
Clean
|
|
β Clean (expected)
|
n_plus_1_query_js_clean.js |
Clean
|
N+1 query (JavaScript) |
β Clean (expected)
|
n_plus_1_query_php_clean 2.php |
Clean
|
|
β Clean (expected)
|
n_plus_1_query_php_clean.php |
Clean
|
N+1 query (PHP) |
β Clean (expected)
|
netty_response_splitting_clean.java |
Clean
|
netty_response_splitting |
β Clean (expected)
|
no_autoplay_media.html |
Clean
|
Autoplaying media |
β Clean (expected)
|
no_default_credentials.py |
Clean
|
Default Credentials |
β Clean (expected)
|
no_security_questions.py |
Clean
|
Security Questions Usage |
β Clean (expected)
|
normal_comment.py |
Clean
|
Unresolved TODO/FIXME |
β Clean (expected)
|
nosql_document_parse_java_clean 2.java |
Clean
|
|
β False positive
|
nosql_document_parse_java_clean.java |
Clean
|
MongoDB Document.parse injection (Java) |
β Clean (expected)
|
nosql_injection_clean.py |
Clean
|
nosql_injection |
β Clean (expected)
|
nosql_injection_mongoose_clean.js |
Clean
|
NoSQL injection via Mongoose $where |
β Clean (expected)
|
nosql_operator_injection_python_clean 2.py |
Clean
|
|
β Clean (expected)
|
nosql_operator_injection_python_clean.py |
Clean
|
MongoDB operator injection (Python) |
β Clean (expected)
|
npm_lifecycle_script_clean.js |
Clean
|
Suspicious npm lifecycle script |
β Clean (expected)
|
numeric_cast_tainted_clean.java |
Clean
|
numeric_cast_tainted |
β Clean (expected)
|
oauth_open_redirect_clean.py |
Clean
|
OAuth Open Redirect |
β Clean (expected)
|
ognl_injection_clean.java |
Clean
|
ognl_injection |
β Clean (expected)
|
open_redirect_clean.js |
Clean
|
Open redirect |
β Clean (expected)
|
open_redirect_csharp_clean.cs |
Clean
|
Open redirect (C#) |
β Clean (expected)
|
open_redirect_java_clean.java |
Clean
|
Open redirect (Java) |
β Clean (expected)
|
open_redirect_php_clean.php |
Clean
|
Open redirect (PHP) |
β Clean (expected)
|
os_system_injection_clean.py |
Clean
|
Shell execution via os.system/popen |
β Clean (expected)
|
overly_large_regex_range_clean.js |
Clean
|
overly_large_regex_range |
β Clean (expected)
|
overly_large_regex_range_clean.py |
Clean
|
overly_large_regex_range |
β Clean (expected)
|
page_no_title_clean.html |
Clean
|
Page without title |
β Clean (expected)
|
page_with_title.html |
Clean
|
Page without title |
β Clean (expected)
|
pam_auth_bypass_clean.py |
Clean
|
pam_auth_bypass |
β Clean (expected)
|
paramiko_no_host_key_clean.py |
Clean
|
Paramiko no host key verification |
β Clean (expected)
|
parser_without_try_clean.py |
Clean
|
Parser without error handling |
β Clean (expected)
|
partial_path_traversal_clean.java |
Clean
|
partial_path_traversal |
β Clean (expected)
|
partial_ssrf_clean.py |
Clean
|
partial_ssrf |
β False positive
|
password_in_config_file_clean.js |
Clean
|
password_in_config_file |
β Clean (expected)
|
password_reversible_storage_java_clean 2.java |
Clean
|
|
β Clean (expected)
|
password_reversible_storage_java_clean.java |
Clean
|
Reversible password storage (Java) |
β Clean (expected)
|
password_reversible_storage_python_clean 2.py |
Clean
|
|
β Clean (expected)
|
password_reversible_storage_python_clean.py |
Clean
|
Reversible password storage (Python) |
β Clean (expected)
|
path_traversal_csharp_clean.cs |
Clean
|
Path traversal (C#) |
β Clean (expected)
|
path_traversal_fis_clean.java |
Clean
|
Path Traversal (FileInputStream) |
β False positive
|
path_traversal_java_clean.java |
Clean
|
Path traversal (Java) |
β Clean (expected)
|
path_traversal_javascript_clean.js |
Clean
|
Path traversal (JavaScript) |
β Clean (expected)
|
path_traversal_os_join_clean.py |
Clean
|
Path traversal via os.path.join |
β Clean (expected)
|
path_traversal_python_clean.py |
Clean
|
Path traversal (Python) |
β Clean (expected)
|
permissive_file_permissions_clean.py |
Clean
|
Permissive file permissions |
β Clean (expected)
|
persistent_cookie_clean.cs |
Clean
|
persistent_cookie |
β Clean (expected)
|
php_deep_nesting_clean 2.php |
Clean
|
|
β Clean (expected)
|
php_deep_nesting_clean.php |
Clean
|
Excessive nesting depth (PHP, 6+ levels) |
β Clean (expected)
|
php_empty_catch_block_clean 2.php |
Clean
|
|
β False positive
|
php_empty_catch_block_clean.php |
Clean
|
Empty catch block (PHP) |
β Clean (expected)
|
php_exit_die_clean 2.php |
Clean
|
|
β Clean (expected)
|
php_exit_die_clean.php |
Clean
|
Use of exit()/die() in PHP |
β Clean (expected)
|
php_public_property_clean 2.php |
Clean
|
|
β Clean (expected)
|
php_public_property_clean.php |
Clean
|
Non-constant public property (PHP) |
β Clean (expected)
|
php_string_concat_loop_clean 2.php |
Clean
|
|
β Clean (expected)
|
php_string_concat_loop_clean.php |
Clean
|
String concatenation in loop (PHP) |
β Clean (expected)
|
php_too_many_params_clean 2.php |
Clean
|
|
β Clean (expected)
|
php_too_many_params_clean.php |
Clean
|
Too many PHP function parameters (6+) |
β Clean (expected)
|
pii_in_tests_clean.py |
Clean
|
PII in Test Code |
β Clean (expected)
|
pii_in_url_clean.py |
Clean
|
PII in URL |
β Clean (expected)
|
pii_logged_clean.py |
Clean
|
PII Logged |
β Clean (expected)
|
pinned_composer.json |
Clean
|
Unpinned Dependency |
β Clean (expected)
|
pinned_csproj.xml |
Clean
|
Unpinned Dependency |
β Clean (expected)
|
pinned_package.json |
Clean
|
Unpinned Dependency |
β Clean (expected)
|
pinned_pom.xml |
Clean
|
Unpinned Dependency |
β Clean (expected)
|
pinned_pyproject.toml |
Clean
|
Unpinned Dependency |
β Clean (expected)
|
pinned_requirements.txt |
Clean
|
Unpinned Dependency |
β Clean (expected)
|
polynomial_redos_java_clean.java |
Clean
|
polynomial_redos_java |
β Clean (expected)
|
positive_tabindex_clean.html |
Clean
|
Positive tabindex |
β Clean (expected)
|
postmessage_no_origin_check_clean.js |
Clean
|
postMessage Without Origin Check |
β Clean (expected)
|
postmessage_origin_check.js |
Clean
|
postMessage Without Origin Check |
β Clean (expected)
|
predictable_seed_clean.java |
Clean
|
predictable_seed |
β Clean (expected)
|
predictable_session_clean.py |
Clean
|
Predictable token/session |
β Clean (expected)
|
private_file_exposure_clean.js |
Clean
|
private_file_exposure |
β Clean (expected)
|
privilege_escalation_clean.py |
Clean
|
Privilege Escalation |
β Clean (expected)
|
prompt_injection_llm_clean.js |
Clean
|
Prompt Injection (LLM) |
β Clean (expected)
|
prompt_injection_llm_clean.py |
Clean
|
Prompt Injection (LLM) |
β Clean (expected)
|
prototype_pollution_clean.js |
Clean
|
Prototype pollution |
β Clean (expected)
|
pull_request_target_checkout_clean.txt |
Clean
|
pull_request_target with fork checkout |
β Clean (expected)
|
pull_request_target_checkout_clean.yml |
Clean
|
pull_request_target with fork checkout |
β False positive
|
py_bare_except_clean 2.py |
Clean
|
|
β Clean (expected)
|
py_bare_except_clean.py |
Clean
|
Bare except clause (no exception type) |
β Clean (expected)
|
py_commented_out_code_clean 2.py |
Clean
|
|
β Clean (expected)
|
py_commented_out_code_clean.py |
Clean
|
Commented-out code (dead code) |
β Clean (expected)
|
py_global_statement_clean 2.py |
Clean
|
|
β Clean (expected)
|
py_global_statement_clean.py |
Clean
|
Global statement inside function |
β Clean (expected)
|
py_magic_value_comparison_clean 2.py |
Clean
|
|
β Clean (expected)
|
py_magic_value_comparison_clean.py |
Clean
|
Magic number comparison |
β Clean (expected)
|
py_missing_class_docstring_clean 2.py |
Clean
|
|
β Clean (expected)
|
py_missing_class_docstring_clean.py |
Clean
|
py_missing_class_docstring |
β Clean (expected)
|
py_too_many_arguments_clean 2.py |
Clean
|
|
β False positive
|
py_too_many_arguments_clean.py |
Clean
|
Too many function arguments (6+) |
β Clean (expected)
|
py_too_many_nested_blocks_clean 2.py |
Clean
|
|
β Clean (expected)
|
py_too_many_nested_blocks_clean.py |
Clean
|
Excessive nesting depth (6+ levels) |
β Clean (expected)
|
race_condition_clean.py |
Clean
|
Race condition (TOCTOU) |
β Clean (expected)
|
race_condition_financial_clean.py |
Clean
|
Race Condition (Financial) |
β Clean (expected)
|
razor_html_raw_clean.cs |
Clean
|
XSS via Html.Raw() |
β Clean (expected)
|
redis_eval_injection_js_clean 2.js |
Clean
|
|
β Clean (expected)
|
redis_eval_injection_js_clean.js |
Clean
|
Redis EVAL injection (JavaScript) |
β Clean (expected)
|
redis_eval_injection_python_clean 2.py |
Clean
|
|
β False positive
|
redis_eval_injection_python_clean.py |
Clean
|
Redis EVAL injection (Python) |
β Clean (expected)
|
redos_nested_quantifier_clean.py |
Clean
|
ReDoS nested quantifier |
β Clean (expected)
|
redos_safe.py |
Clean
|
ReDoS Vulnerable Regex |
β Clean (expected)
|
redos_vulnerable_clean.py |
Clean
|
ReDoS Vulnerable Regex |
β Clean (expected)
|
regex_dos_clean.js |
Clean
|
ReDoS β unsafe regex |
β Clean (expected)
|
regex_injection_clean.js |
Clean
|
regex_injection |
β Clean (expected)
|
regex_injection_csharp_clean.cs |
Clean
|
regex_injection_csharp |
β Clean (expected)
|
regex_injection_java_clean.java |
Clean
|
regex_injection_java |
β Clean (expected)
|
regex_redos_js_clean 2.js |
Clean
|
|
β False positive
|
regex_redos_js_clean.js |
Clean
|
ReDoS via user-controlled RegExp (JavaScript) |
β Clean (expected)
|
remote_property_injection_clean.js |
Clean
|
remote_property_injection |
β Clean (expected)
|
request_validation_disabled_clean.cs |
Clean
|
Request validation disabled |
β Clean (expected)
|
request_validation_disabled_clean.py |
Clean
|
Request validation disabled |
β Clean (expected)
|
resource_exhaustion_clean.js |
Clean
|
resource_exhaustion |
β Clean (expected)
|
resource_injection_csharp_clean.cs |
Clean
|
resource_injection_csharp |
β Clean (expected)
|
rsa_without_oaep_clean.java |
Clean
|
rsa_without_oaep |
β Clean (expected)
|
rsa_without_oaep_csharp_clean.cs |
Clean
|
rsa_without_oaep_csharp |
β Clean (expected)
|
runtime_checks_bypass_clean.cs |
Clean
|
runtime_checks_bypass |
β Clean (expected)
|
safe_deserialization.py |
Clean
|
Unsafe deserialization |
β Clean (expected)
|
safe_exception.py |
Clean
|
Verbose exception |
β Clean (expected)
|
safe_file_access.py |
Clean
|
Race condition (TOCTOU) |
β Clean (expected)
|
safe_import.py |
Clean
|
Dynamic import |
β Clean (expected)
|
safe_no_eval.py |
Clean
|
Dangerous Eval/Exec |
β Clean (expected)
|
samesite_none_cookie_clean.js |
Clean
|
samesite_none_cookie |
β Clean (expected)
|
samesite_none_cookie_clean.py |
Clean
|
samesite_none_cookie |
β False positive
|
sample_cicd_clean.yml |
Clean
|
pull_request_target with fork checkout |
β False positive
|
sample_csharp_clean.cs |
Clean
|
SQL injection (C# concatenation) |
β Clean (expected)
|
sample_data_retention_clean.py |
Clean
|
Missing Data Retention |
β Clean (expected)
|
sample_deprecated_csharp_clean.cs |
Clean
|
Deprecated API (C#) |
β Clean (expected)
|
sample_deprecated_java_clean.java |
Clean
|
Deprecated API (Java) |
β Clean (expected)
|
sample_deprecated_js_clean.js |
Clean
|
Deprecated API (JavaScript) |
β Clean (expected)
|
sample_deprecated_php_clean.php |
Clean
|
Deprecated API (PHP) |
β Clean (expected)
|
sample_dockerfile_clean |
Clean
|
Dockerfile runs as root |
β Clean (expected)
|
sample_frontend_xss_clean.jsx |
Clean
|
XSS via React dangerouslySetInnerHTML |
β Clean (expected)
|
sample_gitlab_clean.yml |
Clean
|
Unprotected GitLab CI variable |
β Clean (expected)
|
sample_hardcoded_ui_html_clean.html |
Clean
|
Hardcoded UI string |
β Clean (expected)
|
sample_hardcoded_ui_string_clean.js |
Clean
|
Hardcoded UI string |
β Clean (expected)
|
sample_java_clean.java |
Clean
|
SQL injection (Java concatenation) |
β Clean (expected)
|
sample_mfa_csharp_clean.cs |
Clean
|
Missing MFA (C#) |
β Clean (expected)
|
sample_mfa_java_clean.java |
Clean
|
Missing MFA (Java) |
β Clean (expected)
|
sample_mfa_js_clean.js |
Clean
|
Missing MFA (JavaScript) |
β Clean (expected)
|
sample_mfa_php_clean.php |
Clean
|
Missing MFA (PHP) |
β Clean (expected)
|
sample_mfa_python_clean.py |
Clean
|
Missing MFA (Python) |
β Clean (expected)
|
sample_orm_js_clean.js |
Clean
|
SQL injection via Sequelize raw query |
β Clean (expected)
|
sample_orm_python_clean.py |
Clean
|
SQL injection via Django raw SQL |
β Clean (expected)
|
sample_php_clean.php |
Clean
|
SQL injection (PHP concatenation) |
β Clean (expected)
|
sample_pii_logged_clean.py |
Clean
|
PII Logged |
β Clean (expected)
|
sample_svelte_xss_clean.svelte |
Clean
|
XSS via Svelte {@html} tag |
β Clean (expected)
|
sample_vue_xss_clean.vue |
Clean
|
XSS via Vue.js v-html directive |
β Clean (expected)
|
script_with_sri.html |
Clean
|
Missing Subresource Integrity |
β Clean (expected)
|
second_order_command_injection_clean.js |
Clean
|
second_order_command_injection |
β Clean (expected)
|
secret_example.py |
Clean
|
Hardcoded secret |
β Clean (expected)
|
secret_in_env.py |
Clean
|
Hardcoded secret |
β Clean (expected)
|
secret_logged_arg_clean.py |
Clean
|
Secret logged (argument) |
β Clean (expected)
|
secret_logged_csharp_clean.cs |
Clean
|
Secret logged (C#) |
β Clean (expected)
|
secret_logged_fstring_clean.py |
Clean
|
Secret logged (f-string) |
β Clean (expected)
|
secret_logged_java_clean.java |
Clean
|
Secret logged (Java) |
β Clean (expected)
|
secret_logged_php_clean.php |
Clean
|
Secret logged (PHP) |
β Clean (expected)
|
secret_masked.py |
Clean
|
Secret logged (f-string) |
β Clean (expected)
|
secret_not_logged_arg.py |
Clean
|
Secret logged (argument) |
β Clean (expected)
|
secure_auth.py |
Clean
|
Homebrew authentication |
β Clean (expected)
|
secure_cookie_java.java |
Clean
|
Insecure cookie (missing HttpOnly/Secure) |
β Clean (expected)
|
secure_cookie_js.js |
Clean
|
Insecure cookie (missing HttpOnly/Secure) |
β Clean (expected)
|
secure_cookie_python.py |
Clean
|
Insecure cookie (missing HttpOnly/Secure) |
β Clean (expected)
|
secure_random.js |
Clean
|
Insecure RNG |
β Clean (expected)
|
secure_session.py |
Clean
|
Predictable token/session |
β Clean (expected)
|
security_questions_clean.py |
Clean
|
Security Questions Usage |
β False positive
|
sensitive_get_query_clean.js |
Clean
|
sensitive_get_query |
β Clean (expected)
|
server_crash_unhandled_clean.js |
Clean
|
server_crash_unhandled |
β False positive
|
server_side_auth.js |
Clean
|
Client-side access control |
β Clean (expected)
|
service_worker_hijack_clean.js |
Clean
|
Service Worker Hijack |
β Clean (expected)
|
session_fixation_clean.js |
Clean
|
session_fixation |
β Clean (expected)
|
session_not_abandoned_clean.cs |
Clean
|
session_not_abandoned |
β Clean (expected)
|
shell_injection_from_env_clean.js |
Clean
|
shell_injection_from_env |
β Clean (expected)
|
smtp_injection_php_clean.php |
Clean
|
SMTP Header Injection (PHP) |
β Clean (expected)
|
smtp_injection_python_clean.py |
Clean
|
SMTP Header Injection (Python) |
β Clean (expected)
|
socket_auth_race_clean.java |
Clean
|
socket_auth_race |
β Clean (expected)
|
specific_exception.py |
Clean
|
Catch-all exception |
β Clean (expected)
|
spel_injection_clean.java |
Clean
|
SpEL injection |
β Clean (expected)
|
spring_actuator_exposed_clean.java |
Clean
|
Spring Actuator Exposed |
β Clean (expected)
|
spring_cors_permissive_clean.java |
Clean
|
Permissive CORS configuration |
β Clean (expected)
|
spring_csrf_disabled_clean.java |
Clean
|
Spring CSRF disabled |
β Clean (expected)
|
sql_injection_concat_clean.py |
Clean
|
SQL Injection (concat) |
β Clean (expected)
|
sql_injection_concat_csharp_clean.cs |
Clean
|
SQL injection (C# concatenation) |
β Clean (expected)
|
sql_injection_concat_java_clean.java |
Clean
|
SQL injection (Java concatenation) |
β Clean (expected)
|
sql_injection_concat_php_clean.php |
Clean
|
SQL injection (PHP concatenation) |
β Clean (expected)
|
sql_injection_dapper_clean.cs |
Clean
|
SQL injection via Dapper raw query |
β Clean (expected)
|
sql_injection_dapper_clean.py |
Clean
|
SQL injection via Dapper raw query |
β Clean (expected)
|
sql_injection_django_raw_clean.py |
Clean
|
SQL injection via Django raw SQL |
β Clean (expected)
|
sql_injection_doctrine_clean.php |
Clean
|
SQL injection via Doctrine DQL |
β Clean (expected)
|
sql_injection_format_java_clean.java |
Clean
|
SQL injection (Java String.format) |
β Clean (expected)
|
sql_injection_format_string_python_clean 2.py |
Clean
|
|
β Clean (expected)
|
sql_injection_format_string_python_clean.py |
Clean
|
SQL injection via % format string (Python) |
β Clean (expected)
|
sql_injection_fstring_clean.py |
Clean
|
SQL Injection (f-string) |
β Clean (expected)
|
sql_injection_java_broad_clean.java |
Clean
|
SQL Injection (Java) |
β Clean (expected)
|
sql_injection_jpa_native_clean.java |
Clean
|
SQL injection via JPA/Hibernate native query |
β Clean (expected)
|
sql_injection_mybatis_clean.java |
Clean
|
SQL injection via MyBatis ${} interpolation |
β Clean (expected)
|
sql_injection_prisma_clean.js |
Clean
|
SQL injection via Prisma $queryRaw |
β Clean (expected)
|
sql_injection_raw_js_clean 2.js |
Clean
|
|
β Clean (expected)
|
sql_injection_raw_js_clean.js |
Clean
|
SQL injection in raw query (JavaScript) |
β Clean (expected)
|
sql_injection_sequelize_clean.js |
Clean
|
SQL injection via Sequelize raw query |
β Clean (expected)
|
sql_injection_sqlalchemy_text_clean.py |
Clean
|
SQL injection via SQLAlchemy text() |
β Clean (expected)
|
sql_injection_string_format_csharp_clean 2.cs |
Clean
|
|
β Clean (expected)
|
sql_injection_string_format_csharp_clean.cs |
Clean
|
SQL injection via string.Format (C#) |
β Clean (expected)
|
sql_injection_typeorm_clean.js |
Clean
|
SQL injection via TypeORM raw query |
β Clean (expected)
|
sql_injection_whereraw_php_clean.php |
Clean
|
SQL injection via Laravel whereRaw/havingRaw |
β Clean (expected)
|
sql_injection_wpdb_clean.php |
Clean
|
SQL injection via WordPress $wpdb |
β Clean (expected)
|
sql_order_by_injection_python_clean 2.py |
Clean
|
|
β Clean (expected)
|
sql_order_by_injection_python_clean.py |
Clean
|
ORDER BY injection (Python) |
β Clean (expected)
|
sql_parameterized.py |
Clean
|
SQL Injection (f-string) |
β Clean (expected)
|
sql_static.py |
Clean
|
SQL Injection (f-string) |
β Clean (expected)
|
ssl_bypass_csharp_clean.cs |
Clean
|
SSL/TLS bypass (C#) |
β Clean (expected)
|
ssl_bypass_java_clean.java |
Clean
|
SSL/TLS bypass (Java) |
β Clean (expected)
|
ssl_no_cert_validation_clean.py |
Clean
|
SSL cert validation disabled |
β Clean (expected)
|
ssrf_csharp_clean.cs |
Clean
|
Server-Side Request Forgery (C#) |
β Clean (expected)
|
ssrf_java_clean.java |
Clean
|
Server-Side Request Forgery (Java) |
β Clean (expected)
|
ssrf_javascript_clean.js |
Clean
|
Server-Side Request Forgery (JavaScript) |
β Clean (expected)
|
ssrf_pdf_generation_clean.py |
Clean
|
SSRF via PDF Generation |
β Clean (expected)
|
ssrf_php_clean.php |
Clean
|
Server-Side Request Forgery (PHP) |
β Clean (expected)
|
ssrf_python_clean.py |
Clean
|
Server-Side Request Forgery (Python) |
β Clean (expected)
|
ssti_javascript_clean.js |
Clean
|
Server-Side Template Injection (JavaScript) |
β Clean (expected)
|
ssti_python_clean.py |
Clean
|
Server-Side Template Injection (Python) |
β Clean (expected)
|
static_initialization_vector_clean.java |
Clean
|
static_initialization_vector |
β Clean (expected)
|
stored_procedure_dynamic_csharp_clean 2.cs |
Clean
|
|
β Clean (expected)
|
stored_procedure_dynamic_csharp_clean.cs |
Clean
|
Dynamic stored procedure (C#) |
β Clean (expected)
|
stored_procedure_dynamic_java_clean 2.java |
Clean
|
|
β Clean (expected)
|
stored_procedure_dynamic_java_clean.java |
Clean
|
Dynamic stored procedure (Java) |
β Clean (expected)
|
stored_procedure_dynamic_php_clean 2.php |
Clean
|
|
β Clean (expected)
|
stored_procedure_dynamic_php_clean.php |
Clean
|
Dynamic stored procedure (PHP) |
β Clean (expected)
|
stored_xss_clean.js |
Clean
|
stored_xss |
β Clean (expected)
|
strong_crypto.py |
Clean
|
Weak cryptographic algorithm |
β Clean (expected)
|
strong_password_policy.py |
Clean
|
Weak Password Policy |
β Clean (expected)
|
sufficient_key_size.py |
Clean
|
Insufficient Cryptographic Key Size |
β Clean (expected)
|
svelte_at_html_clean.js |
Clean
|
Svelte {@html} β XSS risk |
β Clean (expected)
|
svg_inline_html_clean.html |
Clean
|
Inline SVG in HTML |
β Clean (expected)
|
svg_safe_content.html |
Clean
|
SVG With Scriptable Content |
β Clean (expected)
|
svg_scriptable_content_clean.html |
Clean
|
SVG With Scriptable Content |
β Clean (expected)
|
system_out_java_clean.java |
Clean
|
System.out in production (Java) |
β Clean (expected)
|
taint_codeinj_clean.cs |
Clean
|
Taint Code Injection |
β Clean (expected)
|
taint_codeinj_clean.java |
Clean
|
Taint Code Injection |
β Clean (expected)
|
taint_codeinj_clean.js |
Clean
|
Taint Code Injection |
β Clean (expected)
|
taint_codeinj_clean.php |
Clean
|
Taint Code Injection |
β Clean (expected)
|
taint_codeinj_clean.py |
Clean
|
Taint Code Injection |
β Clean (expected)
|
taint_cookie_injection_clean.cs |
Clean
|
taint_cookie_injection |
β Clean (expected)
|
taint_cookie_injection_clean.java |
Clean
|
taint_cookie_injection |
β False positive
|
taint_cookie_injection_clean.js |
Clean
|
taint_cookie_injection |
β Clean (expected)
|
taint_cookie_injection_clean.php |
Clean
|
taint_cookie_injection |
β Clean (expected)
|
taint_cookie_injection_clean.py |
Clean
|
taint_cookie_injection |
β Clean (expected)
|
taint_deserialization_clean.cs |
Clean
|
Taint Deserialization |
β Clean (expected)
|
taint_deserialization_clean.php |
Clean
|
Taint Deserialization |
β Clean (expected)
|
taint_deserialization_clean.py |
Clean
|
Taint Deserialization |
β Clean (expected)
|
taint_graphql_injection_clean.cs |
Clean
|
taint_graphql_injection |
β Clean (expected)
|
taint_graphql_injection_clean.java |
Clean
|
taint_graphql_injection |
β Clean (expected)
|
taint_graphql_injection_clean.js |
Clean
|
taint_graphql_injection |
β Clean (expected)
|
taint_graphql_injection_clean.php |
Clean
|
taint_graphql_injection |
β False positive
|
taint_graphql_injection_clean.py |
Clean
|
taint_graphql_injection |
β False positive
|
taint_header_injection_clean.cs |
Clean
|
taint_header_injection |
β Clean (expected)
|
taint_header_injection_clean.java |
Clean
|
taint_header_injection |
β False positive
|
taint_header_injection_clean.js |
Clean
|
taint_header_injection |
β Clean (expected)
|
taint_header_injection_clean.php |
Clean
|
taint_header_injection |
β Clean (expected)
|
taint_header_injection_clean.py |
Clean
|
taint_header_injection |
β Clean (expected)
|
taint_ldap_clean.cs |
Clean
|
Taint LDAP Injection |
β Clean (expected)
|
taint_ldap_clean.java |
Clean
|
Taint LDAP Injection |
β Clean (expected)
|
taint_ldap_clean.js |
Clean
|
Taint LDAP Injection |
β Clean (expected)
|
taint_ldap_clean.php |
Clean
|
Taint LDAP Injection |
β Clean (expected)
|
taint_ldap_clean.py |
Clean
|
Taint LDAP Injection |
β Clean (expected)
|
taint_log_injection_clean.cs |
Clean
|
Taint Log Injection |
β Clean (expected)
|
taint_log_injection_clean.java |
Clean
|
Taint Log Injection |
β Clean (expected)
|
taint_log_injection_clean.js |
Clean
|
Taint Log Injection |
β Clean (expected)
|
taint_log_injection_clean.php |
Clean
|
Taint Log Injection |
β Clean (expected)
|
taint_log_injection_clean.py |
Clean
|
Taint Log Injection |
β Clean (expected)
|
taint_nosql_clean.cs |
Clean
|
taint_nosql |
β Clean (expected)
|
taint_nosql_clean.java |
Clean
|
taint_nosql |
β Clean (expected)
|
taint_nosql_clean.js |
Clean
|
taint_nosql |
β Clean (expected)
|
taint_nosql_clean.php |
Clean
|
taint_nosql |
β Clean (expected)
|
taint_nosql_clean.py |
Clean
|
taint_nosql |
β False positive
|
taint_open_redirect_clean.cs |
Clean
|
Taint Open Redirect |
β Clean (expected)
|
taint_open_redirect_clean.java |
Clean
|
Taint Open Redirect |
β False positive
|
taint_open_redirect_clean.js |
Clean
|
Taint Open Redirect |
β Clean (expected)
|
taint_open_redirect_clean.php |
Clean
|
Taint Open Redirect |
β Clean (expected)
|
taint_open_redirect_clean.py |
Clean
|
Taint Open Redirect |
β Clean (expected)
|
taint_path_traversal_clean.cs |
Clean
|
Taint Path Traversal |
β Clean (expected)
|
taint_path_traversal_clean.java |
Clean
|
Taint Path Traversal |
β Clean (expected)
|
taint_path_traversal_clean.js |
Clean
|
Taint Path Traversal |
β Clean (expected)
|
taint_path_traversal_clean.php |
Clean
|
Taint Path Traversal |
β Clean (expected)
|
taint_path_traversal_clean.py |
Clean
|
Taint Path Traversal |
β Clean (expected)
|
taint_rce_clean.cs |
Clean
|
Taint RCE |
β False positive
|
taint_rce_clean.php |
Clean
|
Taint RCE |
β Clean (expected)
|
taint_rce_clean.py |
Clean
|
Taint RCE |
β Clean (expected)
|
taint_smtp_injection_clean.cs |
Clean
|
taint_smtp_injection |
β Clean (expected)
|
taint_smtp_injection_clean.java |
Clean
|
taint_smtp_injection |
β False positive
|
taint_smtp_injection_clean.js |
Clean
|
taint_smtp_injection |
β Clean (expected)
|
taint_smtp_injection_clean.php |
Clean
|
taint_smtp_injection |
β Clean (expected)
|
taint_smtp_injection_clean.py |
Clean
|
taint_smtp_injection |
β Clean (expected)
|
taint_sqli_clean.js |
Clean
|
Taint SQL Injection |
β Clean (expected)
|
taint_sqli_clean.php |
Clean
|
Taint SQL Injection |
β Clean (expected)
|
taint_sqli_clean.py |
Clean
|
Taint SQL Injection |
β Clean (expected)
|
taint_ssrf_clean.php |
Clean
|
Taint SSRF |
β Clean (expected)
|
taint_ssrf_clean.py |
Clean
|
Taint SSRF |
β Clean (expected)
|
taint_ssti_clean.cs |
Clean
|
Taint SSTI |
β Clean (expected)
|
taint_ssti_clean.java |
Clean
|
Taint SSTI |
β Clean (expected)
|
taint_ssti_clean.js |
Clean
|
Taint SSTI |
β Clean (expected)
|
taint_ssti_clean.php |
Clean
|
Taint SSTI |
β Clean (expected)
|
taint_ssti_clean.py |
Clean
|
Taint SSTI |
β Clean (expected)
|
taint_xpathi_clean.cs |
Clean
|
Taint XPath Injection |
β Clean (expected)
|
taint_xpathi_clean.java |
Clean
|
Taint XPath Injection |
β False positive
|
taint_xpathi_clean.js |
Clean
|
Taint XPath Injection |
β Clean (expected)
|
taint_xpathi_clean.php |
Clean
|
Taint XPath Injection |
β Clean (expected)
|
taint_xpathi_clean.py |
Clean
|
Taint XPath Injection |
β Clean (expected)
|
taint_xss_clean.cs |
Clean
|
Taint XSS |
β Clean (expected)
|
taint_xss_clean.java |
Clean
|
Taint XSS |
β Clean (expected)
|
taint_xss_clean.js |
Clean
|
Taint XSS |
β Clean (expected)
|
taint_xss_clean.php |
Clean
|
Taint XSS |
β Clean (expected)
|
taint_xss_clean.py |
Clean
|
Taint XSS |
β Clean (expected)
|
taint_xxe_clean.cs |
Clean
|
Taint XXE |
β Clean (expected)
|
taint_xxe_clean.java |
Clean
|
Taint XXE |
β Clean (expected)
|
taint_xxe_clean.js |
Clean
|
Taint XXE |
β Clean (expected)
|
taint_xxe_clean.php |
Clean
|
Taint XXE |
β False positive
|
taint_xxe_clean.py |
Clean
|
Taint XXE |
β Clean (expected)
|
tainted_format_string_clean.js |
Clean
|
tainted_format_string |
β Clean (expected)
|
tainted_permissions_check_clean.java |
Clean
|
tainted_permissions_check |
β Clean (expected)
|
tarfile_unsafe_extract_clean.py |
Clean
|
Unsafe tar extraction |
β Clean (expected)
|
temp_dir_info_disclosure_clean.java |
Clean
|
temp_dir_info_disclosure |
β Clean (expected)
|
template_injection_java_clean.java |
Clean
|
template_injection_java |
β Clean (expected)
|
template_object_injection_clean.js |
Clean
|
template_object_injection |
β False positive
|
toctou_race_condition_clean.java |
Clean
|
toctou_race_condition |
β Clean (expected)
|
todo_unresolved_clean.java |
Clean
|
Unresolved TODO/FIXME |
β Clean (expected)
|
todo_unresolved_clean.js |
Clean
|
Unresolved TODO/FIXME |
β Clean (expected)
|
todo_unresolved_clean.py |
Clean
|
Unresolved TODO/FIXME |
β Clean (expected)
|
trust_boundary_java_clean.java |
Clean
|
Trust Boundary Violation |
β Clean (expected)
|
trust_boundary_python_clean.py |
Clean
|
Trust boundary violation |
β Clean (expected)
|
type_confusion_parameter_clean.js |
Clean
|
type_confusion_parameter |
β Clean (expected)
|
type_juggling_php_clean.php |
Clean
|
Type juggling (PHP) |
β Clean (expected)
|
unbounded_query_clean.py |
Clean
|
Unbounded Query |
β Clean (expected)
|
unbounded_query_java_clean 2.java |
Clean
|
|
β Clean (expected)
|
unbounded_query_java_clean.java |
Clean
|
Unbounded query (Java) |
β Clean (expected)
|
unbounded_query_js_clean 2.js |
Clean
|
|
β Clean (expected)
|
unbounded_query_js_clean.js |
Clean
|
Unbounded query (JavaScript) |
β Clean (expected)
|
unbounded_query_php_clean 2.php |
Clean
|
|
β Clean (expected)
|
unbounded_query_php_clean.php |
Clean
|
Unbounded query (PHP) |
β Clean (expected)
|
uncontrolled_format_string_clean.cs |
Clean
|
uncontrolled_format_string |
β Clean (expected)
|
unencrypted_transfer_clean.py |
Clean
|
Unencrypted Data Transfer |
β Clean (expected)
|
unpinned_action_version_clean.yml |
Clean
|
Unpinned action version |
β Clean (expected)
|
unrestricted_file_upload_java_clean 2.java |
Clean
|
|
β False positive
|
unrestricted_file_upload_java_clean.java |
Clean
|
Unrestricted file upload (Java/Spring) |
β Clean (expected)
|
unrestricted_file_upload_js_clean 2.js |
Clean
|
|
β False positive
|
unrestricted_file_upload_js_clean.js |
Clean
|
Unrestricted file upload (Node.js/Multer) |
β Clean (expected)
|
unrestricted_file_upload_php_clean 2.php |
Clean
|
|
β False positive
|
unrestricted_file_upload_php_clean.php |
Clean
|
Unrestricted file upload (PHP) |
β Clean (expected)
|
unreviewed_vendor_code_clean.py |
Clean
|
Unreviewed Vendor Code |
β Clean (expected)
|
unsafe_code_construction_clean.js |
Clean
|
unsafe_code_construction |
β Clean (expected)
|
unsafe_deserialization_clean.py |
Clean
|
Unsafe deserialization |
β Clean (expected)
|
unsafe_deserialization_csharp_clean.cs |
Clean
|
Unsafe deserialization (C#) |
β Clean (expected)
|
unsafe_deserialization_delegate_clean.cs |
Clean
|
unsafe_deserialization_delegate |
β Clean (expected)
|
unsafe_deserialization_java_clean.java |
Clean
|
Unsafe deserialization (Java) |
β Clean (expected)
|
unsafe_deserialization_php_clean.php |
Clean
|
Unsafe deserialization (PHP) |
β Clean (expected)
|
unsafe_dynamic_method_access_clean.js |
Clean
|
unsafe_dynamic_method_access |
β Clean (expected)
|
unsafe_html_expansion_clean.js |
Clean
|
unsafe_html_expansion |
β Clean (expected)
|
unsafe_require_clean.js |
Clean
|
require() with dynamic variable |
β Clean (expected)
|
unsafe_shell_construction_clean.py |
Clean
|
unsafe_shell_construction |
β Clean (expected)
|
unvalidated_dynamic_method_call_clean.js |
Clean
|
unvalidated_dynamic_method_call |
β Clean (expected)
|
unvalidated_input_clean.py |
Clean
|
Unvalidated input (OS injection) |
β Clean (expected)
|
url_forward_injection_clean.java |
Clean
|
url_forward_injection |
β Clean (expected)
|
use_ssl_socket_clean.java |
Clean
|
use_ssl_socket |
β Clean (expected)
|
useless_regexp_escape_clean.js |
Clean
|
useless_regexp_escape |
β Clean (expected)
|
validated_input.py |
Clean
|
Unvalidated input (OS injection) |
β Clean (expected)
|
verbose_exception_clean.py |
Clean
|
Verbose exception |
β Clean (expected)
|
verbose_exception_csharp_clean.cs |
Clean
|
Verbose exception (C#) |
β Clean (expected)
|
verbose_exception_java_clean.java |
Clean
|
Verbose exception (Java) |
β Clean (expected)
|
verbose_exception_php_clean.php |
Clean
|
Verbose exception (PHP) |
β Clean (expected)
|
vue_v_html_clean.js |
Clean
|
Vue.js v-html β XSS risk |
β Clean (expected)
|
vulnerable_dependency_clean.py |
Clean
|
Vulnerable Dependency |
β Clean (expected)
|
weak_cipher_java_clean.java |
Clean
|
Weak Cipher (Java) |
β Clean (expected)
|
weak_crypto_clean.py |
Clean
|
Weak cryptographic algorithm |
β Clean (expected)
|
weak_crypto_csharp_clean.cs |
Clean
|
Weak cryptography (C#) |
β Clean (expected)
|
weak_crypto_java_clean.java |
Clean
|
Weak cryptography (Java) |
β Clean (expected)
|
weak_crypto_php_clean.php |
Clean
|
Weak cryptography (PHP) |
β Clean (expected)
|
weak_password_hash_clean.py |
Clean
|
Weak Password Hash |
β Clean (expected)
|
weak_password_hash_php_clean 2.php |
Clean
|
|
β Clean (expected)
|
weak_password_hash_php_clean.php |
Clean
|
Weak password hashing (PHP) |
β Clean (expected)
|
weak_password_policy_clean.py |
Clean
|
Weak Password Policy |
β Clean (expected)
|
weak_random_csharp_clean.cs |
Clean
|
Weak random (C#) |
β Clean (expected)
|
weak_random_java_clean.java |
Clean
|
Weak random (Java) |
β Clean (expected)
|
weak_random_java_util_clean.java |
Clean
|
Weak Random (Java) |
β Clean (expected)
|
weak_random_php_clean.php |
Clean
|
Weak random (PHP) |
β Clean (expected)
|
weak_random_python_clean.py |
Clean
|
Weak random number generator |
β Clean (expected)
|
websocket_no_tls_clean.js |
Clean
|
WebSocket Without TLS |
β Clean (expected)
|
websocket_no_tls_clean.py |
Clean
|
WebSocket Without TLS |
β Clean (expected)
|
websocket_no_validation_clean.js |
Clean
|
WebSocket No Validation |
β Clean (expected)
|
websocket_tls.js |
Clean
|
WebSocket Without TLS |
β Clean (expected)
|
websocket_tls_python.py |
Clean
|
WebSocket Without TLS |
β Clean (expected)
|
window_open_noopener_clean.js |
Clean
|
window.open without noopener |
β Clean (expected)
|
with_doctype.html |
Clean
|
Missing DOCTYPE declaration |
β Clean (expected)
|
with_skip_link.html |
Clean
|
Missing skip navigation link |
β Clean (expected)
|
workflow_not_in_codeowners_clean.yml |
Clean
|
Workflows missing from CODEOWNERS |
β Clean (expected)
|
world_writable_file_read_clean.java |
Clean
|
world_writable_file_read |
β Clean (expected)
|
xml_bomb_clean.js |
Clean
|
xml_bomb |
β Clean (expected)
|
xml_bomb_clean.py |
Clean
|
xml_bomb |
β Clean (expected)
|
xml_injection_csharp_clean.cs |
Clean
|
xml_injection_csharp |
β Clean (expected)
|
xpath_injection_clean.js |
Clean
|
xpath_injection |
β Clean (expected)
|
xpath_injection_csharp_clean.cs |
Clean
|
XPath Injection (C#) |
β Clean (expected)
|
xpath_injection_java_clean.java |
Clean
|
XPath Injection (Java) |
β Clean (expected)
|
xpath_injection_java_eval_clean.java |
Clean
|
XPath Injection (Java) |
β Clean (expected)
|
xpath_injection_php_clean.php |
Clean
|
XPath Injection (PHP) |
β Clean (expected)
|
xpath_injection_python_clean.py |
Clean
|
XPath Injection (Python) |
β Clean (expected)
|
xslt_injection_clean.java |
Clean
|
xslt_injection |
β Clean (expected)
|
xss_angular_bypass_clean.js |
Clean
|
XSS via Angular security bypass |
β Clean (expected)
|
xss_blade_unescaped_clean.php |
Clean
|
XSS via unescaped Blade output |
β Clean (expected)
|
xss_echo_php_clean.php |
Clean
|
XSS via echo (PHP) |
β Clean (expected)
|
xss_exception_exposure_clean.js |
Clean
|
xss_exception_exposure |
β Clean (expected)
|
xss_flask_reflected_clean.py |
Clean
|
Reflected XSS (Flask) |
β Clean (expected)
|
xss_innerhtml_clean.js |
Clean
|
XSS via innerHTML |
β Clean (expected)
|
xss_jquery_unsafe_plugin_clean.js |
Clean
|
xss_jquery_unsafe_plugin |
β Clean (expected)
|
xss_raw_html_clean.cs |
Clean
|
XSS via Html.Raw() |
β Clean (expected)
|
xss_raw_html_clean.py |
Clean
|
XSS via Html.Raw() |
β Clean (expected)
|
xss_react_dangerous_clean.js |
Clean
|
XSS via React dangerouslySetInnerHTML |
β Clean (expected)
|
xss_servlet_response_clean.java |
Clean
|
XSS Servlet Response |
β Clean (expected)
|
xss_svelte_html_clean.html |
Clean
|
XSS via Svelte {@html} tag |
β Clean (expected)
|
xss_through_dom_clean.js |
Clean
|
xss_through_dom |
β Clean (expected)
|
xss_unsafe_html_construction_clean.js |
Clean
|
xss_unsafe_html_construction |
β Clean (expected)
|
xss_vue_vhtml_clean.html |
Clean
|
XSS via Vue.js v-html directive |
β Clean (expected)
|
xxe_injection_clean.java |
Clean
|
XXE injection |
β Clean (expected)
|
xxe_injection_clean.js |
Clean
|
XXE injection |
β Clean (expected)
|
xxe_injection_csharp_clean.cs |
Clean
|
XXE injection (C#) |
β Clean (expected)
|
xxe_injection_php_clean.php |
Clean
|
XXE injection (PHP) |
β Clean (expected)
|
xxe_injection_python_clean.py |
Clean
|
XXE injection (Python) |
β Clean (expected)
|
xxe_xmldocument_clean.cs |
Clean
|
xxe_xmldocument |
β Clean (expected)
|
zip_bomb_clean.py |
Clean
|
Zip bomb vulnerability |
β Clean (expected)
|
zip_slip_clean.java |
Clean
|
zip_slip |
β Clean (expected)
|
zip_slip_csharp_clean.cs |
Clean
|
zip_slip_csharp |
β Clean (expected)
|
angularjs_insecure_url_whitelist.js |
Vulnerable
|
angularjs_insecure_url_whitelist |
β Detected (expected)
|
api_key_in_url.js |
Vulnerable
|
API Key in URL |
β Detected (expected)
|
api_key_in_url.py |
Vulnerable
|
API Key in URL |
β Detected (expected)
|
arithmetic_extreme_values.java |
Vulnerable
|
arithmetic_extreme_values |
β Detected (expected)
|
arithmetic_tainted.java |
Vulnerable
|
arithmetic_tainted |
β Detected (expected)
|
arithmetic_uncontrolled.java |
Vulnerable
|
arithmetic_uncontrolled |
β Detected (expected)
|
array_construction_tainted.java |
Vulnerable
|
array_construction_tainted |
β Detected (expected)
|
array_index_validation.java |
Vulnerable
|
array_index_validation |
β Detected (expected)
|
aspnet_debug_enabled.cs |
Vulnerable
|
aspnet_debug_enabled |
β Detected (expected)
|
aspnet_directory_listing.cs |
Vulnerable
|
aspnet_directory_listing |
β Detected (expected)
|
aspnet_max_request_length.cs |
Vulnerable
|
aspnet_max_request_length |
β Detected (expected)
|
assembly_path_injection.cs |
Vulnerable
|
assembly_path_injection |
β Detected (expected)
|
autoplay_media.html |
Vulnerable
|
Autoplaying media |
β Detected (expected)
|
bad_tag_filter.js |
Vulnerable
|
bad_tag_filter |
β Detected (expected)
|
bad_tag_filter.py |
Vulnerable
|
bad_tag_filter |
β Detected (expected)
|
base64_credentials.py |
Vulnerable
|
Base64 encoded credentials |
β Detected (expected)
|
base64_eval.js |
Vulnerable
|
Base64 obfuscated code execution |
β Detected (expected)
|
base64_eval.py |
Vulnerable
|
Base64 obfuscated code execution |
β Detected (expected)
|
base64_obfuscation.js |
Vulnerable
|
Suspicious base64 string decoded |
β Detected (expected)
|
broken_crypto_algorithm.js |
Vulnerable
|
broken_crypto_algorithm |
β Detected (expected)
|
build_artifact_leak.js |
Vulnerable
|
build_artifact_leak |
β Detected (expected)
|
button_no_aria.html |
Vulnerable
|
Button without aria-label |
β Detected (expected)
|
cache_poisoning.py |
Vulnerable
|
Cache Poisoning |
β Detected (expected)
|
case_sensitive_middleware_path.js |
Vulnerable
|
case_sensitive_middleware_path |
β Detected (expected)
|
catch_all_exception.py |
Vulnerable
|
Catch-all exception |
β Detected (expected)
|
catch_all_exception_csharp.cs |
Vulnerable
|
Generic catch (C#) |
β Detected (expected)
|
catch_all_exception_java.java |
Vulnerable
|
Generic catch (Java) |
β Detected (expected)
|
catch_all_exception_php.php |
Vulnerable
|
Generic catch (PHP) |
β Detected (expected)
|
ci_curl_pipe_bash.yml |
Vulnerable
|
Remote script piped to shell |
β Detected (expected)
|
ci_debug_trace_enabled.yml |
Vulnerable
|
CI/CD debug logging enabled |
β Detected (expected)
|
ci_docker_privileged.yml |
Vulnerable
|
Privileged Docker container in CI/CD |
β Detected (expected)
|
ci_insecure_download.yml |
Vulnerable
|
Insecure HTTP download in CI/CD |
β Detected (expected)
|
ci_netcat_reverse_shell.yml |
Vulnerable
|
Netcat reverse shell in CI/CD script |
β Detected (expected)
|
cleartext_cookie.js |
Vulnerable
|
cleartext_cookie |
β Detected (expected)
|
cleartext_logging.js |
Vulnerable
|
cleartext_logging |
β Detected (expected)
|
cleartext_storage_class.java |
Vulnerable
|
cleartext_storage_class |
β Detected (expected)
|
cleartext_storage_cookie.java |
Vulnerable
|
cleartext_storage_cookie |
β Detected (expected)
|
cleartext_storage_csharp.cs |
Vulnerable
|
cleartext_storage_csharp |
β Detected (expected)
|
cleartext_storage_properties.java |
Vulnerable
|
cleartext_storage_properties |
β Detected (expected)
|
cleartext_storage_sensitive.js |
Vulnerable
|
cleartext_storage_sensitive |
β Detected (expected)
|
cleartext_storage_sensitive.py |
Vulnerable
|
cleartext_storage_sensitive |
β Detected (expected)
|
client_side_auth.js |
Vulnerable
|
Client-side access control |
β Detected (expected)
|
client_side_ssrf.js |
Vulnerable
|
client_side_ssrf |
β Detected (expected)
|
command_injection_csharp.cs |
Vulnerable
|
Command injection (C#) |
β Detected (expected)
|
command_injection_java.java |
Vulnerable
|
Command injection (Java) |
β Detected (expected)
|
command_injection_java_broad.java |
Vulnerable
|
Command Injection (Java) |
β Detected (expected)
|
command_injection_php.php |
Vulnerable
|
Command injection (PHP) |
β Detected (expected)
|
comparison_wider_type.java |
Vulnerable
|
comparison_wider_type |
β Detected (expected)
|
conditional_bypass.js |
Vulnerable
|
conditional_bypass |
β Detected (expected)
|
conditional_bypass_csharp.cs |
Vulnerable
|
conditional_bypass_csharp |
β Detected (expected)
|
conditional_bypass_java.java |
Vulnerable
|
conditional_bypass_java |
β Detected (expected)
|
console_log.js |
Vulnerable
|
Residual console.log |
β Detected (expected)
|
console_log_residual.js |
Vulnerable
|
Residual console.log |
β Detected (expected)
|
console_write_csharp.cs |
Vulnerable
|
Console.Write in production (C#) |
β Detected (expected)
|
cookie_broad_domain.cs |
Vulnerable
|
cookie_broad_domain |
β Detected (expected)
|
cookie_broad_path.cs |
Vulnerable
|
cookie_broad_path |
β Detected (expected)
|
cookie_injection.py |
Vulnerable
|
cookie_injection |
β Detected (expected)
|
cors_credentials_wildcard.js |
Vulnerable
|
CORS wildcard with credentials |
β Detected (expected)
|
cors_permissive_csharp.cs |
Vulnerable
|
Permissive CORS (C#) |
β Detected (expected)
|
create_element.js |
Vulnerable
|
Manual createElement |
β Detected (expected)
|
crud_without_ownership.js |
Vulnerable
|
CRUD without ownership check |
β Detected (expected)
|
cs_deep_nesting 2.cs |
Vulnerable
|
|
β Detected (expected)
|
cs_deep_nesting.cs |
Vulnerable
|
Excessive nesting depth (C#, 6+ levels) |
β Detected (expected)
|
cs_empty_catch_block 2.cs |
Vulnerable
|
|
β Detected (expected)
|
cs_empty_catch_block.cs |
Vulnerable
|
Empty catch block (C#) |
β Detected (expected)
|
cs_high_coupling 2.cs |
Vulnerable
|
|
β Detected (expected)
|
cs_high_coupling.cs |
Vulnerable
|
High coupling β too many C# interfaces (SonarQube S1200) |
β Detected (expected)
|
cs_magic_number 2.cs |
Vulnerable
|
|
β Detected (expected)
|
cs_magic_number.cs |
Vulnerable
|
Magic number in comparison (C#) |
β Detected (expected)
|
cs_string_format_legacy 2.cs |
Vulnerable
|
|
β Detected (expected)
|
cs_string_format_legacy.cs |
Vulnerable
|
string.Format() instead of interpolation (C#) |
β Detected (expected)
|
cs_too_many_params 2.cs |
Vulnerable
|
|
β Detected (expected)
|
cs_too_many_params.cs |
Vulnerable
|
Too many C# method parameters (6+) |
β Detected (expected)
|
csrf_missing_flask 2.py |
Vulnerable
|
|
β Detected (expected)
|
csrf_missing_flask.py |
Vulnerable
|
Missing CSRF protection (Flask) |
β Detected (expected)
|
csv_injection.py |
Vulnerable
|
CSV Formula Injection |
β Detected (expected)
|
dangerous_eval.py |
Vulnerable
|
Dangerous Eval/Exec |
β Detected (expected)
|
dangerous_function_java.java |
Vulnerable
|
dangerous_function_java |
β Detected (expected)
|
data_uri_html.js |
Vulnerable
|
Data URI with HTML content |
β Detected (expected)
|
data_uri_html_tag.html |
Vulnerable
|
Data URI HTML in tag |
β Detected (expected)
|
db_connection_string_credentials 2.py |
Vulnerable
|
|
β Detected (expected)
|
db_connection_string_credentials.py |
Vulnerable
|
DB connection string with credentials (Python) |
β Detected (expected)
|
db_connection_string_credentials_js 2.js |
Vulnerable
|
|
β Detected (expected)
|
db_connection_string_credentials_js.js |
Vulnerable
|
DB connection string with credentials (JavaScript) |
β Detected (expected)
|
db_error_exposed_csharp 2.cs |
Vulnerable
|
|
β Detected (expected)
|
db_error_exposed_csharp.cs |
Vulnerable
|
DB error exposed in response (C#) |
β Detected (expected)
|
db_error_exposed_java 2.java |
Vulnerable
|
|
β Detected (expected)
|
db_error_exposed_java.java |
Vulnerable
|
DB error exposed in response (Java) |
β Detected (expected)
|
db_error_exposed_php 2.php |
Vulnerable
|
|
β Detected (expected)
|
db_error_exposed_php.php |
Vulnerable
|
DB error exposed in response (PHP) |
β Detected (expected)
|
db_error_exposed_python 2.py |
Vulnerable
|
|
β Detected (expected)
|
db_error_exposed_python.py |
Vulnerable
|
DB error exposed in response (Python) |
β Detected (expected)
|
db_logic_controller_csharp.cs |
Vulnerable
|
DB logic in controller (C#) |
β Detected (expected)
|
db_logic_controller_java.java |
Vulnerable
|
DB logic in controller (Java) |
β Detected (expected)
|
db_logic_controller_php.php |
Vulnerable
|
DB logic in controller (PHP) |
β Detected (expected)
|
db_superuser_connection_csharp 2.cs |
Vulnerable
|
|
β Detected (expected)
|
db_superuser_connection_csharp.cs |
Vulnerable
|
DB connection as superuser (C#) |
β Detected (expected)
|
db_superuser_connection_java 2.java |
Vulnerable
|
|
β Detected (expected)
|
db_superuser_connection_java.java |
Vulnerable
|
DB connection as superuser (Java) |
β Detected (expected)
|
db_superuser_connection_python 2.py |
Vulnerable
|
|
β Detected (expected)
|
db_superuser_connection_python.py |
Vulnerable
|
DB connection as superuser (Python) |
β Detected (expected)
|
db_tls_disabled_java 2.java |
Vulnerable
|
|
β Detected (expected)
|
db_tls_disabled_java.java |
Vulnerable
|
DB connection without TLS (Java) |
β Detected (expected)
|
db_tls_disabled_js 2.js |
Vulnerable
|
|
β Detected (expected)
|
db_tls_disabled_js.js |
Vulnerable
|
DB connection without TLS (JavaScript) |
β Detected (expected)
|
db_tls_disabled_python 2.py |
Vulnerable
|
|
β Detected (expected)
|
db_tls_disabled_python.py |
Vulnerable
|
DB connection without TLS (Python) |
β Detected (expected)
|
debug_mode.py |
Vulnerable
|
Debug mode enabled |
β Detected (expected)
|
default_credentials.py |
Vulnerable
|
Default Credentials |
β Detected (expected)
|
dependabot_insecure_exec.yml |
Vulnerable
|
Dependabot insecure external code execution |
β Detected (expected)
|
dependency_confusion.js |
Vulnerable
|
Dependency Confusion |
β Detected (expected)
|
dependency_confusion.py |
Vulnerable
|
Dependency Confusion |
β Detected (expected)
|
deprecated_api.py |
Vulnerable
|
Deprecated API |
β Detected (expected)
|
deprecated_api_csharp.cs |
Vulnerable
|
Deprecated API (C#) |
β Detected (expected)
|
deprecated_api_java.java |
Vulnerable
|
Deprecated API (Java) |
β Detected (expected)
|
deprecated_api_javascript.js |
Vulnerable
|
Deprecated API (JavaScript) |
β Detected (expected)
|
deprecated_api_php.php |
Vulnerable
|
Deprecated API (PHP) |
β Detected (expected)
|
destructive_without_backup.py |
Vulnerable
|
Destructive Operation Without Backup |
β Detected (expected)
|
different_kinds_comparison_bypass.js |
Vulnerable
|
different_kinds_comparison_bypass |
β Detected (expected)
|
disable_certificate_validation.js |
Vulnerable
|
disable_certificate_validation |
β Detected (expected)
|
django_csrf_exempt.py |
Vulnerable
|
@csrf_exempt decorator (Django) |
β Detected (expected)
|
django_debug_enabled.py |
Vulnerable
|
DEBUG = True (Django) |
β Detected (expected)
|
django_mark_safe_xss.py |
Vulnerable
|
Django mark_safe() β XSS risk |
β Detected (expected)
|
django_secret_key_weak.py |
Vulnerable
|
Hardcoded SECRET_KEY (Django) |
β Detected (expected)
|
django_vulnerable.py |
Vulnerable
|
@csrf_exempt decorator (Django) |
β Detected (expected)
|
docker_latest_tag.yml |
Vulnerable
|
Docker image with :latest tag |
β Detected (expected)
|
dockerfile_copy_all |
Vulnerable
|
COPY . . in Dockerfile |
β Detected (expected)
|
dockerfile_root_user |
Vulnerable
|
Dockerfile runs as root |
β Detected (expected)
|
dockerfile_unpinned_base |
Vulnerable
|
Unpinned base image |
β Detected (expected)
|
dom_clobbering.html |
Vulnerable
|
DOM Clobbering |
β Detected (expected)
|
dom_in_loop.js |
Vulnerable
|
DOM manipulation in loop |
β Detected (expected)
|
dom_manipulation_loop.js |
Vulnerable
|
DOM manipulation in loop |
β Detected (expected)
|
dom_pseudo_eval.js |
Vulnerable
|
dom_pseudo_eval |
β Detected (expected)
|
dont_install_root_cert.cs |
Vulnerable
|
dont_install_root_cert |
β Detected (expected)
|
double_escaping.js |
Vulnerable
|
double_escaping |
β Detected (expected)
|
dynamic_import.py |
Vulnerable
|
Dynamic import |
β Detected (expected)
|
ecb_cipher_mode.py |
Vulnerable
|
Insecure ECB cipher mode |
β Detected (expected)
|
ecb_mode_csharp.cs |
Vulnerable
|
ecb_mode_csharp |
β Detected (expected)
|
elasticsearch_query_injection 2.py |
Vulnerable
|
|
β Detected (expected)
|
elasticsearch_query_injection.py |
Vulnerable
|
Elasticsearch query injection (Python) |
β Detected (expected)
|
electron_insecure_content.js |
Vulnerable
|
electron_insecure_content |
β Detected (expected)
|
electron_node_integration.js |
Vulnerable
|
electron_node_integration |
β Detected (expected)
|
electron_web_security_disabled.js |
Vulnerable
|
electron_web_security_disabled |
β Detected (expected)
|
empty_password_config.js |
Vulnerable
|
empty_password_config |
β Detected (expected)
|
error_suppressor_php.php |
Vulnerable
|
Error suppressor (PHP @) |
β Detected (expected)
|
eval_injection_php.php |
Vulnerable
|
Code injection (PHP) |
β Detected (expected)
|
eval_template_literal.js |
Vulnerable
|
eval() with template literal |
β Detected (expected)
|
event_listeners_not_cleaned.js |
Vulnerable
|
Event listeners not cleaned |
β Detected (expected)
|
event_listeners_orphan.js |
Vulnerable
|
Event listeners not cleaned |
β Detected (expected)
|
exec_relative_path.java |
Vulnerable
|
exec_relative_path |
β Detected (expected)
|
exec_tainted_environment.java |
Vulnerable
|
exec_tainted_environment |
β Detected (expected)
|
exec_unescaped.java |
Vulnerable
|
exec_unescaped |
β Detected (expected)
|
exposed_test_endpoint.py |
Vulnerable
|
Exposed Test/Debug Endpoint |
β Detected (expected)
|
exposure_private_information.cs |
Vulnerable
|
exposure_private_information |
β Detected (expected)
|
exposure_transmitted_data.cs |
Vulnerable
|
exposure_transmitted_data |
β Detected (expected)
|
express_cors_wildcard.js |
Vulnerable
|
Permissive CORS configuration (Express) |
β Detected (expected)
|
express_no_csrf.js |
Vulnerable
|
Express without CSRF protection |
β Detected (expected)
|
express_no_helmet.js |
Vulnerable
|
Missing Helmet middleware (Express) |
β Detected (expected)
|
express_vulnerable.js |
Vulnerable
|
Missing Helmet middleware (Express) |
β Detected (expected)
|
extract_usage_php.php |
Vulnerable
|
Variable overwrite (PHP extract) |
β Detected (expected)
|
file_access_to_http.js |
Vulnerable
|
file_access_to_http |
β Detected (expected)
|
file_inclusion_php.php |
Vulnerable
|
File inclusion (PHP) |
β Detected (expected)
|
file_too_long.cs |
Vulnerable
|
File too long |
β Detected (expected)
|
file_too_long.java |
Vulnerable
|
File too long |
β Detected (expected)
|
file_too_long.php |
Vulnerable
|
File too long |
β Detected (expected)
|
file_too_long.py |
Vulnerable
|
File too long |
β Detected (expected)
|
file_upload_no_validation.py |
Vulnerable
|
File Upload Without Validation |
β Detected (expected)
|
filesystem_race_condition.js |
Vulnerable
|
filesystem_race_condition |
β Detected (expected)
|
fixme_comment.py |
Vulnerable
|
Unresolved TODO/FIXME |
β Detected (expected)
|
flask_debug_enabled.py |
Vulnerable
|
Debug mode enabled (Flask) |
β Detected (expected)
|
flask_secret_key_weak.py |
Vulnerable
|
Hardcoded secret_key (Flask) |
β Detected (expected)
|
flask_vulnerable.py |
Vulnerable
|
Debug mode enabled (Flask) |
β Detected (expected)
|
focus_outline_removed.js |
Vulnerable
|
Focus outline removed |
β Detected (expected)
|
format_string_vuln.java |
Vulnerable
|
Format String Vulnerability |
β Detected (expected)
|
format_string_vuln.py |
Vulnerable
|
Format String Vulnerability |
β Detected (expected)
|
fstring_in_logging.py |
Vulnerable
|
F-string in Logging |
β Detected (expected)
|
functionality_untrusted_domain.js |
Vulnerable
|
functionality_untrusted_domain |
β Detected (expected)
|
functionality_untrusted_source.js |
Vulnerable
|
functionality_untrusted_source |
β Detected (expected)
|
gha_actor_check_bypass.yml |
Vulnerable
|
Bypassable actor-based security gate |
β Detected (expected)
|
gha_artifact_poisoning.yml |
Vulnerable
|
Artifact poisoning via workflow_run |
β Detected (expected)
|
gha_cache_poisoning.yml |
Vulnerable
|
Cache poisoning risk in release workflow |
β Detected (expected)
|
gha_confused_deputy.yml |
Vulnerable
|
Confused deputy auto-merge bypass |
β Detected (expected)
|
gha_credentials_on_disk.yml |
Vulnerable
|
Git credentials persisted on disk |
β Detected (expected)
|
gha_dangerous_artefact.yml |
Vulnerable
|
Sensitive files uploaded as artifact |
β Detected (expected)
|
gha_deprecated_commands.yml |
Vulnerable
|
Deprecated workflow commands |
β Detected (expected)
|
gha_excessive_permissions.yml |
Vulnerable
|
Excessive workflow permissions |
β Detected (expected)
|
gha_expression_injection.yml |
Vulnerable
|
GitHub Actions expression injection |
β Detected (expected)
|
gha_github_app_no_revoke.yml |
Vulnerable
|
GitHub App token not revoked after job |
β Detected (expected)
|
gha_github_env_write.yml |
Vulnerable
|
Untrusted data written to GITHUB_ENV |
β Detected (expected)
|
gha_insecure_commands_env.yml |
Vulnerable
|
Insecure workflow commands enabled |
β Detected (expected)
|
gha_job_all_secrets.yml |
Vulnerable
|
All secrets serialized in workflow |
β Detected (expected)
|
gha_local_action.yml |
Vulnerable
|
Local action usage |
β Detected (expected)
|
gha_missing_permissions.yml |
Vulnerable
|
Missing permissions block |
β Detected (expected)
|
gha_secret_in_log.yml |
Vulnerable
|
Secret printed in workflow log |
β Detected (expected)
|
gha_secrets_bypass_redaction.yml |
Vulnerable
|
Secrets redaction bypass via JSON |
β Detected (expected)
|
gha_secrets_without_environment.yml |
Vulnerable
|
Secrets used without environment gate on risky trigger |
β Detected (expected)
|
gha_self_hosted_runner.yml |
Vulnerable
|
Self-hosted runner on public repository |
β Detected (expected)
|
gha_unguarded_comment_trigger.yml |
Vulnerable
|
Unguarded comment trigger |
β Detected (expected)
|
gha_unsound_condition.yml |
Vulnerable
|
Unsound if: condition with block scalar |
β Detected (expected)
|
gha_version_comment_missing.yml |
Vulnerable
|
Pinned action SHA without version comment |
β Detected (expected)
|
gha_workflow_dispatch_inputs.yml |
Vulnerable
|
workflow_dispatch with user inputs |
β Detected (expected)
|
gitlab_allow_failure_security.yml |
Vulnerable
|
Security job with allow_failure: true |
β Detected (expected)
|
gitlab_double_pipeline.yml |
Vulnerable
|
GitLab CI duplicate pipeline rules |
β Detected (expected)
|
gitlab_script_secrets_echo.yml |
Vulnerable
|
GitLab CI token printed to log |
β Detected (expected)
|
gitlab_unsafe_variables.yml |
Vulnerable
|
Unprotected GitLab CI variable |
β Detected (expected)
|
graphql_batching_attack.js |
Vulnerable
|
GraphQL Batching Attack |
β Detected (expected)
|
graphql_introspection.js |
Vulnerable
|
GraphQL Introspection Enabled |
β Detected (expected)
|
graphql_introspection_enabled.js |
Vulnerable
|
GraphQL Introspection Enabled |
β Detected (expected)
|
graphql_introspection_enabled.py |
Vulnerable
|
GraphQL Introspection Enabled |
β Detected (expected)
|
graphql_introspection_python.py |
Vulnerable
|
GraphQL Introspection Enabled |
β Detected (expected)
|
graphql_no_depth_limit.js |
Vulnerable
|
GraphQL Without Depth Limit |
β Detected (expected)
|
graphql_no_depth_limit.py |
Vulnerable
|
GraphQL Without Depth Limit |
β Detected (expected)
|
groovy_injection.java |
Vulnerable
|
groovy_injection |
β Detected (expected)
|
hack_comment.js |
Vulnerable
|
Unresolved TODO/FIXME |
β Detected (expected)
|
hardcoded_api_key.py |
Vulnerable
|
Hardcoded secret |
β Detected (expected)
|
hardcoded_aws_key.py |
Vulnerable
|
Hardcoded secret |
β Detected (expected)
|
hardcoded_connection_string.cs |
Vulnerable
|
hardcoded_connection_string |
β Detected (expected)
|
hardcoded_connection_string_java 2.java |
Vulnerable
|
|
β Detected (expected)
|
hardcoded_connection_string_java.java |
Vulnerable
|
Hardcoded DB credentials (Java) |
β Detected (expected)
|
hardcoded_connection_string_php 2.php |
Vulnerable
|
|
β Detected (expected)
|
hardcoded_connection_string_php.php |
Vulnerable
|
Hardcoded DB credentials (PHP) |
β Detected (expected)
|
hardcoded_data_as_code.js |
Vulnerable
|
hardcoded_data_as_code |
β Detected (expected)
|
hardcoded_encryption_key.cs |
Vulnerable
|
hardcoded_encryption_key |
β Detected (expected)
|
hardcoded_github_token.py |
Vulnerable
|
Hardcoded secret |
β Detected (expected)
|
hardcoded_internal_ip.py |
Vulnerable
|
Hardcoded Internal IP Address |
β Detected (expected)
|
hardcoded_iv_nonce.py |
Vulnerable
|
Hardcoded IV/Nonce |
β Detected (expected)
|
hardcoded_password.py |
Vulnerable
|
Hardcoded secret |
β Detected (expected)
|
hardcoded_pem_key.py |
Vulnerable
|
Hardcoded secret |
β Detected (expected)
|
hardcoded_secret.js |
Vulnerable
|
Hardcoded secret |
β Detected (expected)
|
hardcoded_secret.py |
Vulnerable
|
Hardcoded secret |
β Detected (expected)
|
hardcoded_secret_cicd.yml |
Vulnerable
|
Hardcoded secret in CI/CD configuration |
β Detected (expected)
|
hardcoded_slack_token.py |
Vulnerable
|
Hardcoded secret |
β Detected (expected)
|
hardcoded_stripe_key.js |
Vulnerable
|
Hardcoded secret |
β Detected (expected)
|
hardcoded_tmp_path.py |
Vulnerable
|
Hardcoded /tmp path |
β Detected (expected)
|
hardcoded_ui_string.js |
Vulnerable
|
Hardcoded UI string |
β Detected (expected)
|
header_injection.py |
Vulnerable
|
header_injection |
β Detected (expected)
|
heading_skip_level.html |
Vulnerable
|
Heading skip level |
β Detected (expected)
|
homebrew_auth.py |
Vulnerable
|
Homebrew authentication |
β Detected (expected)
|
host_header_poisoning.js |
Vulnerable
|
host_header_poisoning |
β Detected (expected)
|
html_aria_hidden_focusable.html |
Vulnerable
|
Focusable element hidden with aria-hidden |
β Detected (expected)
|
html_autocomplete_invalid.html |
Vulnerable
|
Non-standard autocomplete value |
β Detected (expected)
|
html_button_missing_type.html |
Vulnerable
|
HTML button without type attribute |
β Detected (expected)
|
html_deprecated_tag.html |
Vulnerable
|
Deprecated HTML tag |
β Detected (expected)
|
html_img_missing_dimensions.html |
Vulnerable
|
HTML image without dimensions (width/height) |
β Detected (expected)
|
html_inline_style.html |
Vulnerable
|
Inline CSS style (HTML) |
β Detected (expected)
|
html_input_button_empty.html |
Vulnerable
|
Button input without label (missing value) |
β Detected (expected)
|
html_invalid_aria_role.html |
Vulnerable
|
Empty ARIA role attribute |
β Detected (expected)
|
html_invalid_lang_value.html |
Vulnerable
|
Non-BCP-47 lang attribute value |
β Detected (expected)
|
html_missing_main_landmark.html |
Vulnerable
|
Missing <main> landmark |
β Detected (expected)
|
html_missing_meta_viewport.html |
Vulnerable
|
Missing viewport meta tag (HTML) |
β Detected (expected)
|
html_no_lang.html |
Vulnerable
|
HTML missing lang attribute |
β Detected (expected)
|
html_select_missing_label.html |
Vulnerable
|
Select without accessible label |
β Detected (expected)
|
html_target_blank_noreferrer.html |
Vulnerable
|
target="_blank" without rel="noopener noreferrer" |
β Detected (expected)
|
html_th_scope_missing.html |
Vulnerable
|
Table header without scope attribute |
β Detected (expected)
|
html_video_missing_captions.html |
Vulnerable
|
Video without caption track |
β Detected (expected)
|
html_viewport_zoom_disabled.html |
Vulnerable
|
User zoom disabled (viewport) |
β Detected (expected)
|
http_no_tls.py |
Vulnerable
|
HTTP without TLS |
β Detected (expected)
|
http_response_splitting.java |
Vulnerable
|
http_response_splitting |
β Detected (expected)
|
http_smuggling.py |
Vulnerable
|
HTTP request smuggling |
β Detected (expected)
|
http_to_file_access.js |
Vulnerable
|
http_to_file_access |
β Detected (expected)
|
http_without_tls.py |
Vulnerable
|
HTTP without TLS |
β Detected (expected)
|
idor_missing_ownership.cs |
Vulnerable
|
IDOR Missing Ownership |
β Detected (expected)
|
idor_missing_ownership.py |
Vulnerable
|
IDOR Missing Ownership |
β Detected (expected)
|
iframe_no_title.html |
Vulnerable
|
Iframe without title |
β Detected (expected)
|
img_decorative_no_role.html |
Vulnerable
|
Decorative image without role |
β Detected (expected)
|
img_no_alt.html |
Vulnerable
|
Image without alt text |
β Detected (expected)
|
improper_code_sanitization.js |
Vulnerable
|
improper_code_sanitization |
β Detected (expected)
|
inappropriate_encoding.cs |
Vulnerable
|
inappropriate_encoding |
β Detected (expected)
|
incomplete_hostname_regexp.js |
Vulnerable
|
incomplete_hostname_regexp |
β Detected (expected)
|
incomplete_hostname_regexp.py |
Vulnerable
|
incomplete_hostname_regexp |
β Detected (expected)
|
incomplete_html_attribute_sanitization.js |
Vulnerable
|
incomplete_html_attribute_sanitization |
β Detected (expected)
|
incomplete_multichar_sanitization.js |
Vulnerable
|
incomplete_multichar_sanitization |
β Detected (expected)
|
incomplete_sanitization.js |
Vulnerable
|
incomplete_sanitization |
β Detected (expected)
|
incomplete_url_sanitization.py |
Vulnerable
|
incomplete_url_sanitization |
β Detected (expected)
|
incomplete_url_scheme_check.js |
Vulnerable
|
incomplete_url_scheme_check |
β Detected (expected)
|
incomplete_url_substring_sanitization.js |
Vulnerable
|
incomplete_url_substring_sanitization |
β Detected (expected)
|
incorrect_suffix_check.js |
Vulnerable
|
incorrect_suffix_check |
β Detected (expected)
|
indirect_command_injection.js |
Vulnerable
|
indirect_command_injection |
β Detected (expected)
|
infinite_loop_user_input.java |
Vulnerable
|
infinite_loop_user_input |
β Detected (expected)
|
inline_event_handler.js |
Vulnerable
|
Inline event handler |
β Detected (expected)
|
inline_event_handler_html.html |
Vulnerable
|
Inline event handler in HTML |
β Detected (expected)
|
inline_style_js.js |
Vulnerable
|
Inline style in JS |
β Detected (expected)
|
input_no_label.html |
Vulnerable
|
Input without label |
β Detected (expected)
|
insecure_basic_auth.java |
Vulnerable
|
insecure_basic_auth |
β Detected (expected)
|
insecure_bean_validation.java |
Vulnerable
|
insecure_bean_validation |
β Detected (expected)
|
insecure_cipher.py |
Vulnerable
|
Insecure cipher algorithm |
β Detected (expected)
|
insecure_cloud_config.py |
Vulnerable
|
Insecure Cloud Configuration |
β Detected (expected)
|
insecure_cookie.cs |
Vulnerable
|
Insecure cookie (missing HttpOnly/Secure) |
β Detected (expected)
|
insecure_cookie.java |
Vulnerable
|
Insecure cookie (missing HttpOnly/Secure) |
β Detected (expected)
|
insecure_cookie.js |
Vulnerable
|
Insecure cookie (missing HttpOnly/Secure) |
β Detected (expected)
|
insecure_cookie.php |
Vulnerable
|
Insecure cookie (missing HttpOnly/Secure) |
β Detected (expected)
|
insecure_cookie.py |
Vulnerable
|
Insecure cookie (missing HttpOnly/Secure) |
β Detected (expected)
|
insecure_cookie_flag.java |
Vulnerable
|
Insecure Cookie Flag |
β Detected (expected)
|
insecure_cookie_js.js |
Vulnerable
|
insecure_cookie_js |
β Missed
|
insecure_cookie_no_secure.py |
Vulnerable
|
Cookie without Secure flag |
β Detected (expected)
|
insecure_db_deserialization_python 2.py |
Vulnerable
|
|
β Detected (expected)
|
insecure_db_deserialization_python.py |
Vulnerable
|
Insecure DB deserialization (Python) |
β Detected (expected)
|
insecure_dependency_http.js |
Vulnerable
|
insecure_dependency_http |
β Detected (expected)
|
insecure_deserialize_call.py |
Vulnerable
|
Insecure deserialization call |
β Detected (expected)
|
insecure_download.js |
Vulnerable
|
insecure_download |
β Detected (expected)
|
insecure_javamail.java |
Vulnerable
|
insecure_javamail |
β Detected (expected)
|
insecure_ldap_auth.java |
Vulnerable
|
insecure_ldap_auth |
β Detected (expected)
|
insecure_local_storage.js |
Vulnerable
|
Insecure Local Storage |
β Detected (expected)
|
insecure_maven_dependency.java |
Vulnerable
|
insecure_maven_dependency |
β Detected (expected)
|
insecure_random.js |
Vulnerable
|
Insecure RNG |
β Detected (expected)
|
insecure_sql_connection.cs |
Vulnerable
|
insecure_sql_connection |
β Detected (expected)
|
insecure_ssl_version.py |
Vulnerable
|
Insecure SSL/TLS version |
β Detected (expected)
|
insecure_temp_file.js |
Vulnerable
|
insecure_temp_file |
β Detected (expected)
|
insecure_temp_file.py |
Vulnerable
|
insecure_temp_file |
β Detected (expected)
|
insufficient_key_size.js |
Vulnerable
|
Insufficient Cryptographic Key Size |
β Detected (expected)
|
insufficient_key_size.py |
Vulnerable
|
Insufficient Cryptographic Key Size |
β Detected (expected)
|
insufficient_key_size_csharp.cs |
Vulnerable
|
insufficient_key_size_csharp |
β Detected (expected)
|
insufficient_key_size_java.java |
Vulnerable
|
insufficient_key_size_java |
β Detected (expected)
|
insufficient_password_hash.js |
Vulnerable
|
insufficient_password_hash |
β Detected (expected)
|
java_deep_nesting 2.java |
Vulnerable
|
|
β Detected (expected)
|
java_deep_nesting.java |
Vulnerable
|
Excessive nesting depth (Java, 6+ levels) |
β Detected (expected)
|
java_empty_catch_block 2.java |
Vulnerable
|
|
β Detected (expected)
|
java_empty_catch_block.java |
Vulnerable
|
Empty catch block (Java) |
β Detected (expected)
|
java_public_field 2.java |
Vulnerable
|
|
β Detected (expected)
|
java_public_field.java |
Vulnerable
|
Non-constant public field (Java) |
β Detected (expected)
|
java_string_concat_loop 2.java |
Vulnerable
|
|
β Detected (expected)
|
java_string_concat_loop.java |
Vulnerable
|
String concatenation in loop (Java) |
β Detected (expected)
|
java_too_many_params 2.java |
Vulnerable
|
|
β Detected (expected)
|
java_too_many_params.java |
Vulnerable
|
Too many Java method parameters (6+) |
β Detected (expected)
|
java_utility_class_constructor 2.java |
Vulnerable
|
|
β Detected (expected)
|
java_utility_class_constructor.java |
Vulnerable
|
Java utility class without private constructor |
β Detected (expected)
|
javascript_uri.js |
Vulnerable
|
javascript: URI β XSS |
β Detected (expected)
|
javascript_uri_html.html |
Vulnerable
|
javascript: URI in HTML attribute |
β Detected (expected)
|
jexl_injection.java |
Vulnerable
|
jexl_injection |
β Detected (expected)
|
jinja2_autoescape_false.py |
Vulnerable
|
jinja2_autoescape_false |
β Detected (expected)
|
jndi_injection_java.java |
Vulnerable
|
JNDI Injection (Log4Shell) |
β Detected (expected)
|
js_cognitive_complexity 2.js |
Vulnerable
|
|
β Detected (expected)
|
js_cognitive_complexity.js |
Vulnerable
|
High cognitive complexity (JavaScript) |
β Detected (expected)
|
js_debugger_statement 2.js |
Vulnerable
|
|
β Detected (expected)
|
js_debugger_statement.js |
Vulnerable
|
Debugger statement in production (JavaScript) |
β Detected (expected)
|
js_deep_nesting 2.js |
Vulnerable
|
|
β Detected (expected)
|
js_deep_nesting.js |
Vulnerable
|
Excessive nesting depth (JavaScript, 6+ levels) |
β Detected (expected)
|
js_empty_catch_block 2.js |
Vulnerable
|
|
β Detected (expected)
|
js_empty_catch_block.js |
Vulnerable
|
Empty catch block (JavaScript) |
β Detected (expected)
|
js_no_var 2.js |
Vulnerable
|
|
β Detected (expected)
|
js_no_var.js |
Vulnerable
|
Use of var keyword (JavaScript) |
β Detected (expected)
|
js_too_many_params 2.js |
Vulnerable
|
|
β Detected (expected)
|
js_too_many_params.js |
Vulnerable
|
Too many JavaScript function parameters (6+) |
β Detected (expected)
|
jsx_anchor_href_invalid.jsx |
Vulnerable
|
JSX link with invalid href (href="#" or javascript:) |
β Detected (expected)
|
jsx_img_missing_alt.jsx |
Vulnerable
|
JSX image without alt prop (WCAG 1.1.1) |
β Detected (expected)
|
jsx_label_missing_control.jsx |
Vulnerable
|
JSX label without associated control (missing htmlFor) |
β Detected (expected)
|
jsx_no_access_key.jsx |
Vulnerable
|
accessKey used (JSX) |
β Detected (expected)
|
jsx_no_autofocus.jsx |
Vulnerable
|
autoFocus used (JSX) |
β Detected (expected)
|
jsx_tabindex_positive.jsx |
Vulnerable
|
Positive tabIndex (JSX, WCAG 2.4.3) |
β Detected (expected)
|
jwt_hardcoded_secret.py |
Vulnerable
|
JWT Hardcoded Secret |
β Detected (expected)
|
jwt_missing_verification.js |
Vulnerable
|
jwt_missing_verification |
β Detected (expected)
|
jwt_none_algorithm.js |
Vulnerable
|
JWT None Algorithm |
β Detected (expected)
|
jwt_none_algorithm.py |
Vulnerable
|
JWT None Algorithm |
β Detected (expected)
|
jwt_weak_secret.js |
Vulnerable
|
JWT weak secret |
β Detected (expected)
|
ldap_injection_csharp.cs |
Vulnerable
|
LDAP injection (C#) |
β Detected (expected)
|
ldap_injection_java.java |
Vulnerable
|
LDAP injection (Java) |
β Detected (expected)
|
ldap_injection_java_broad.java |
Vulnerable
|
LDAP Injection (Java) |
β Detected (expected)
|
ldap_injection_python.py |
Vulnerable
|
LDAP injection (Python) |
β Detected (expected)
|
link_no_text.html |
Vulnerable
|
Link without text |
β Detected (expected)
|
llm_output_to_sink.py |
Vulnerable
|
LLM Output to Sink |
β Detected (expected)
|
local_time_usage.py |
Vulnerable
|
Local Time Without Timezone |
β Detected (expected)
|
local_unvalidated_arithmetic.cs |
Vulnerable
|
local_unvalidated_arithmetic |
β Detected (expected)
|
lock_order_inconsistency.java |
Vulnerable
|
lock_order_inconsistency |
β Detected (expected)
|
log4shell_jndi.java |
Vulnerable
|
Log4Shell (JNDI) |
β Detected (expected)
|
log_forging_csharp.cs |
Vulnerable
|
log_forging_csharp |
β Detected (expected)
|
log_injection.js |
Vulnerable
|
Log Injection |
β Detected (expected)
|
log_injection.py |
Vulnerable
|
Log Injection |
β Detected (expected)
|
loop_bound_injection.js |
Vulnerable
|
loop_bound_injection |
β Detected (expected)
|
manual_createelement.js |
Vulnerable
|
Manual createElement |
β Detected (expected)
|
mass_assignment_csharp 2.cs |
Vulnerable
|
|
β Detected (expected)
|
mass_assignment_csharp.cs |
Vulnerable
|
Mass assignment (C#) |
β Detected (expected)
|
mass_assignment_java 2.java |
Vulnerable
|
|
β Detected (expected)
|
mass_assignment_java.java |
Vulnerable
|
Mass assignment (Java) |
β Detected (expected)
|
mass_assignment_js 2.js |
Vulnerable
|
|
β Detected (expected)
|
mass_assignment_js.js |
Vulnerable
|
Mass assignment (JavaScript) |
β Detected (expected)
|
mass_assignment_laravel.php |
Vulnerable
|
Mass assignment (Laravel) |
β Detected (expected)
|
mass_assignment_python 2.py |
Vulnerable
|
|
β Detected (expected)
|
mass_assignment_python.py |
Vulnerable
|
Mass assignment (Python) |
β Detected (expected)
|
missing_auth_decorator.py |
Vulnerable
|
Missing Authentication Decorator |
β Detected (expected)
|
missing_authorize_attribute.cs |
Vulnerable
|
missing_authorize_attribute |
β Detected (expected)
|
missing_change_management.py |
Vulnerable
|
Missing Change Management |
β Detected (expected)
|
missing_csp_header.py |
Vulnerable
|
Missing Content-Security-Policy |
β Detected (expected)
|
missing_data_retention.py |
Vulnerable
|
Missing Data Retention |
β Detected (expected)
|
missing_doctype.html |
Vulnerable
|
Missing DOCTYPE declaration |
β Detected (expected)
|
missing_global_error_handler.cs |
Vulnerable
|
missing_global_error_handler |
β Detected (expected)
|
missing_health_check.py |
Vulnerable
|
Missing Health Check Endpoint |
β Detected (expected)
|
missing_hsts.py |
Vulnerable
|
Missing HSTS Header |
β Detected (expected)
|
missing_hsts_django.py |
Vulnerable
|
Missing HSTS Header |
β Detected (expected)
|
missing_jwt_signature_check.java |
Vulnerable
|
missing_jwt_signature_check |
β Detected (expected)
|
missing_mfa_csharp.cs |
Vulnerable
|
Missing MFA (C#) |
β Detected (expected)
|
missing_mfa_java.java |
Vulnerable
|
Missing MFA (Java) |
β Detected (expected)
|
missing_mfa_javascript.js |
Vulnerable
|
Missing MFA (JavaScript) |
β Detected (expected)
|
missing_mfa_php.php |
Vulnerable
|
Missing MFA (PHP) |
β Detected (expected)
|
missing_mfa_python.py |
Vulnerable
|
Missing MFA (Python) |
β Detected (expected)
|
missing_monitoring.py |
Vulnerable
|
Missing Monitoring/Logging |
β Detected (expected)
|
missing_pkce_oauth.js |
Vulnerable
|
Missing PKCE (OAuth) |
β Detected (expected)
|
missing_rate_limit.js |
Vulnerable
|
Missing rate limiting |
β Detected (expected)
|
missing_regexp_anchor.js |
Vulnerable
|
missing_regexp_anchor |
β Detected (expected)
|
missing_security_docs.py |
Vulnerable
|
Undocumented Security Function |
β Detected (expected)
|
missing_session_timeout.py |
Vulnerable
|
Missing Session Timeout |
β Detected (expected)
|
missing_skip_link.html |
Vulnerable
|
Missing skip navigation link |
β Detected (expected)
|
missing_sri.html |
Vulnerable
|
Missing Subresource Integrity |
β Detected (expected)
|
missing_timeout.py |
Vulnerable
|
Missing request timeout |
β Detected (expected)
|
missing_x_frame_options.js |
Vulnerable
|
missing_x_frame_options |
β Detected (expected)
|
missing_x_frame_options_csharp.cs |
Vulnerable
|
missing_x_frame_options_csharp |
β Detected (expected)
|
missing_xml_validation.cs |
Vulnerable
|
missing_xml_validation |
β Detected (expected)
|
mongo_operator_injection.js |
Vulnerable
|
MongoDB NoSQL injection |
β Detected (expected)
|
mvel_injection.java |
Vulnerable
|
mvel_injection |
β Detected (expected)
|
n1_query.py |
Vulnerable
|
Potential N+1 Query |
β Detected (expected)
|
n_plus_1_query.py |
Vulnerable
|
Potential N+1 Query |
β Detected (expected)
|
n_plus_1_query_java.java |
Vulnerable
|
N+1 query (Java) |
β Detected (expected)
|
n_plus_1_query_js 2.js |
Vulnerable
|
|
β Detected (expected)
|
n_plus_1_query_js.js |
Vulnerable
|
N+1 query (JavaScript) |
β Detected (expected)
|
n_plus_1_query_php 2.php |
Vulnerable
|
|
β Detected (expected)
|
n_plus_1_query_php.php |
Vulnerable
|
N+1 query (PHP) |
β Detected (expected)
|
netty_response_splitting.java |
Vulnerable
|
netty_response_splitting |
β Detected (expected)
|
nosql_document_parse_java 2.java |
Vulnerable
|
|
β Detected (expected)
|
nosql_document_parse_java.java |
Vulnerable
|
MongoDB Document.parse injection (Java) |
β Detected (expected)
|
nosql_injection.py |
Vulnerable
|
nosql_injection |
β Detected (expected)
|
nosql_injection_mongoose.js |
Vulnerable
|
NoSQL injection via Mongoose $where |
β Detected (expected)
|
nosql_operator_injection_python 2.py |
Vulnerable
|
|
β Detected (expected)
|
nosql_operator_injection_python.py |
Vulnerable
|
MongoDB operator injection (Python) |
β Detected (expected)
|
npm_lifecycle_script.js |
Vulnerable
|
Suspicious npm lifecycle script |
β Detected (expected)
|
numeric_cast_tainted.java |
Vulnerable
|
numeric_cast_tainted |
β Detected (expected)
|
oauth_open_redirect.py |
Vulnerable
|
OAuth Open Redirect |
β Detected (expected)
|
ognl_injection.java |
Vulnerable
|
ognl_injection |
β Detected (expected)
|
open_redirect.js |
Vulnerable
|
Open redirect |
β Detected (expected)
|
open_redirect_csharp.cs |
Vulnerable
|
Open redirect (C#) |
β Detected (expected)
|
open_redirect_java.java |
Vulnerable
|
Open redirect (Java) |
β Detected (expected)
|
open_redirect_php.php |
Vulnerable
|
Open redirect (PHP) |
β Detected (expected)
|
os_system_injection.py |
Vulnerable
|
Shell execution via os.system/popen |
β Detected (expected)
|
overly_large_regex_range.js |
Vulnerable
|
overly_large_regex_range |
β Detected (expected)
|
overly_large_regex_range.py |
Vulnerable
|
overly_large_regex_range |
β Detected (expected)
|
page_no_title.html |
Vulnerable
|
Page without title |
β Detected (expected)
|
pam_auth_bypass.py |
Vulnerable
|
pam_auth_bypass |
β Detected (expected)
|
paramiko_no_host_key.py |
Vulnerable
|
Paramiko no host key verification |
β Detected (expected)
|
parser_without_try.py |
Vulnerable
|
Parser without error handling |
β Detected (expected)
|
partial_path_traversal.java |
Vulnerable
|
partial_path_traversal |
β Detected (expected)
|
partial_ssrf.py |
Vulnerable
|
partial_ssrf |
β Detected (expected)
|
password_in_config_file.js |
Vulnerable
|
password_in_config_file |
β Detected (expected)
|
password_reversible_storage_java 2.java |
Vulnerable
|
|
β Detected (expected)
|
password_reversible_storage_java.java |
Vulnerable
|
Reversible password storage (Java) |
β Detected (expected)
|
password_reversible_storage_python 2.py |
Vulnerable
|
|
β Detected (expected)
|
password_reversible_storage_python.py |
Vulnerable
|
Reversible password storage (Python) |
β Detected (expected)
|
path_traversal_csharp.cs |
Vulnerable
|
Path traversal (C#) |
β Detected (expected)
|
path_traversal_fis.java |
Vulnerable
|
Path Traversal (FileInputStream) |
β Detected (expected)
|
path_traversal_java.java |
Vulnerable
|
Path traversal (Java) |
β Detected (expected)
|
path_traversal_javascript.js |
Vulnerable
|
Path traversal (JavaScript) |
β Detected (expected)
|
path_traversal_os_join.py |
Vulnerable
|
Path traversal via os.path.join |
β Detected (expected)
|
path_traversal_python.py |
Vulnerable
|
Path traversal (Python) |
β Detected (expected)
|
permissive_file_permissions.py |
Vulnerable
|
Permissive file permissions |
β Detected (expected)
|
persistent_cookie.cs |
Vulnerable
|
persistent_cookie |
β Detected (expected)
|
php_deep_nesting 2.php |
Vulnerable
|
|
β Detected (expected)
|
php_deep_nesting.php |
Vulnerable
|
Excessive nesting depth (PHP, 6+ levels) |
β Detected (expected)
|
php_empty_catch_block 2.php |
Vulnerable
|
|
β Detected (expected)
|
php_empty_catch_block.php |
Vulnerable
|
Empty catch block (PHP) |
β Detected (expected)
|
php_exit_die 2.php |
Vulnerable
|
|
β Detected (expected)
|
php_exit_die.php |
Vulnerable
|
Use of exit()/die() in PHP |
β Detected (expected)
|
php_public_property 2.php |
Vulnerable
|
|
β Detected (expected)
|
php_public_property.php |
Vulnerable
|
Non-constant public property (PHP) |
β Detected (expected)
|
php_string_concat_loop 2.php |
Vulnerable
|
|
β Detected (expected)
|
php_string_concat_loop.php |
Vulnerable
|
String concatenation in loop (PHP) |
β Detected (expected)
|
php_too_many_params 2.php |
Vulnerable
|
|
β Detected (expected)
|
php_too_many_params.php |
Vulnerable
|
Too many PHP function parameters (6+) |
β Detected (expected)
|
pii_in_tests.py |
Vulnerable
|
PII in Test Code |
β Detected (expected)
|
pii_in_url.py |
Vulnerable
|
PII in URL |
β Detected (expected)
|
pii_logged.py |
Vulnerable
|
PII Logged |
β Detected (expected)
|
polynomial_redos_java.java |
Vulnerable
|
polynomial_redos_java |
β Detected (expected)
|
positive_tabindex.html |
Vulnerable
|
Positive tabindex |
β Detected (expected)
|
postmessage_no_origin_check.js |
Vulnerable
|
postMessage Without Origin Check |
β Detected (expected)
|
predictable_seed.java |
Vulnerable
|
predictable_seed |
β Detected (expected)
|
predictable_session.py |
Vulnerable
|
Predictable token/session |
β Detected (expected)
|
private_file_exposure.js |
Vulnerable
|
private_file_exposure |
β Detected (expected)
|
privilege_escalation.py |
Vulnerable
|
Privilege Escalation |
β Detected (expected)
|
prompt_injection_llm.js |
Vulnerable
|
Prompt Injection (LLM) |
β Missed
|
prompt_injection_llm.py |
Vulnerable
|
Prompt Injection (LLM) |
β Detected (expected)
|
prototype_pollution.js |
Vulnerable
|
Prototype pollution |
β Detected (expected)
|
pull_request_target_checkout.yml |
Vulnerable
|
pull_request_target with fork checkout |
β Detected (expected)
|
py_bare_except 2.py |
Vulnerable
|
|
β Detected (expected)
|
py_bare_except.py |
Vulnerable
|
Bare except clause (no exception type) |
β Detected (expected)
|
py_commented_out_code 2.py |
Vulnerable
|
|
β Detected (expected)
|
py_commented_out_code.py |
Vulnerable
|
Commented-out code (dead code) |
β Detected (expected)
|
py_global_statement 2.py |
Vulnerable
|
|
β Detected (expected)
|
py_global_statement.py |
Vulnerable
|
Global statement inside function |
β Detected (expected)
|
py_magic_value_comparison 2.py |
Vulnerable
|
|
β Detected (expected)
|
py_magic_value_comparison.py |
Vulnerable
|
Magic number comparison |
β Detected (expected)
|
py_missing_class_docstring 2.py |
Vulnerable
|
|
β Detected (expected)
|
py_missing_class_docstring.py |
Vulnerable
|
py_missing_class_docstring |
β Detected (expected)
|
py_too_many_arguments 2.py |
Vulnerable
|
|
β Detected (expected)
|
py_too_many_arguments.py |
Vulnerable
|
Too many function arguments (6+) |
β Detected (expected)
|
py_too_many_nested_blocks 2.py |
Vulnerable
|
|
β Detected (expected)
|
py_too_many_nested_blocks.py |
Vulnerable
|
Excessive nesting depth (6+ levels) |
β Detected (expected)
|
race_condition.py |
Vulnerable
|
Race condition (TOCTOU) |
β Detected (expected)
|
race_condition_financial.py |
Vulnerable
|
Race Condition (Financial) |
β Detected (expected)
|
razor_html_raw.cs |
Vulnerable
|
XSS via Html.Raw() |
β Detected (expected)
|
redis_eval_injection_js 2.js |
Vulnerable
|
|
β Detected (expected)
|
redis_eval_injection_js.js |
Vulnerable
|
Redis EVAL injection (JavaScript) |
β Detected (expected)
|
redis_eval_injection_python 2.py |
Vulnerable
|
|
β Detected (expected)
|
redis_eval_injection_python.py |
Vulnerable
|
Redis EVAL injection (Python) |
β Detected (expected)
|
redos_nested_quantifier.py |
Vulnerable
|
ReDoS nested quantifier |
β Detected (expected)
|
redos_vulnerable.py |
Vulnerable
|
ReDoS Vulnerable Regex |
β Detected (expected)
|
regex_dos.js |
Vulnerable
|
ReDoS β unsafe regex |
β Detected (expected)
|
regex_injection.js |
Vulnerable
|
regex_injection |
β Detected (expected)
|
regex_injection_csharp.cs |
Vulnerable
|
regex_injection_csharp |
β Detected (expected)
|
regex_injection_java.java |
Vulnerable
|
regex_injection_java |
β Detected (expected)
|
regex_redos_js 2.js |
Vulnerable
|
|
β Detected (expected)
|
regex_redos_js.js |
Vulnerable
|
ReDoS via user-controlled RegExp (JavaScript) |
β Detected (expected)
|
remote_property_injection.js |
Vulnerable
|
remote_property_injection |
β Detected (expected)
|
request_validation_disabled.cs |
Vulnerable
|
Request validation disabled |
β Detected (expected)
|
request_validation_disabled.py |
Vulnerable
|
Request validation disabled |
β Detected (expected)
|
resource_exhaustion.js |
Vulnerable
|
resource_exhaustion |
β Detected (expected)
|
resource_injection_csharp.cs |
Vulnerable
|
resource_injection_csharp |
β Detected (expected)
|
rsa_without_oaep.java |
Vulnerable
|
rsa_without_oaep |
β Detected (expected)
|
rsa_without_oaep_csharp.cs |
Vulnerable
|
rsa_without_oaep_csharp |
β Detected (expected)
|
runtime_checks_bypass.cs |
Vulnerable
|
runtime_checks_bypass |
β Detected (expected)
|
samesite_none_cookie.js |
Vulnerable
|
samesite_none_cookie |
β Detected (expected)
|
samesite_none_cookie.py |
Vulnerable
|
samesite_none_cookie |
β Detected (expected)
|
sample_cicd_vulnerable.yml |
Vulnerable
|
pull_request_target with fork checkout |
β Detected (expected)
|
sample_csharp.cs |
Vulnerable
|
SQL injection (C# concatenation) |
β Detected (expected)
|
sample_data_retention.py |
Vulnerable
|
Missing Data Retention |
β Detected (expected)
|
sample_deprecated_csharp.cs |
Vulnerable
|
Deprecated API (C#) |
β Detected (expected)
|
sample_deprecated_java.java |
Vulnerable
|
Deprecated API (Java) |
β Detected (expected)
|
sample_deprecated_js.js |
Vulnerable
|
Deprecated API (JavaScript) |
β Detected (expected)
|
sample_deprecated_php.php |
Vulnerable
|
Deprecated API (PHP) |
β Detected (expected)
|
sample_dockerfile |
Vulnerable
|
Dockerfile runs as root |
β Detected (expected)
|
sample_frontend_xss.jsx |
Vulnerable
|
XSS via React dangerouslySetInnerHTML |
β Detected (expected)
|
sample_gitlab_vulnerable.yml |
Vulnerable
|
Unprotected GitLab CI variable |
β Detected (expected)
|
sample_hardcoded_ui_html.html |
Vulnerable
|
Hardcoded UI string |
β Detected (expected)
|
sample_hardcoded_ui_string.js |
Vulnerable
|
Hardcoded UI string |
β Detected (expected)
|
sample_java.java |
Vulnerable
|
SQL injection (Java concatenation) |
β Detected (expected)
|
sample_mfa_csharp.cs |
Vulnerable
|
Missing MFA (C#) |
β Detected (expected)
|
sample_mfa_java.java |
Vulnerable
|
Missing MFA (Java) |
β Detected (expected)
|
sample_mfa_js.js |
Vulnerable
|
Missing MFA (JavaScript) |
β Detected (expected)
|
sample_mfa_php.php |
Vulnerable
|
Missing MFA (PHP) |
β Detected (expected)
|
sample_mfa_python.py |
Vulnerable
|
Missing MFA (Python) |
β Detected (expected)
|
sample_orm_js.js |
Vulnerable
|
SQL injection via Sequelize raw query |
β Detected (expected)
|
sample_orm_python.py |
Vulnerable
|
SQL injection via Django raw SQL |
β Detected (expected)
|
sample_php.php |
Vulnerable
|
SQL injection (PHP concatenation) |
β Detected (expected)
|
sample_pii_logged.py |
Vulnerable
|
PII Logged |
β Detected (expected)
|
sample_svelte_xss.svelte |
Vulnerable
|
XSS via Svelte {@html} tag |
β Detected (expected)
|
sample_vue_xss.vue |
Vulnerable
|
XSS via Vue.js v-html directive |
β Detected (expected)
|
second_order_command_injection.js |
Vulnerable
|
second_order_command_injection |
β Detected (expected)
|
secret_logged.py |
Vulnerable
|
Secret logged (f-string) |
β Detected (expected)
|
secret_logged_arg.py |
Vulnerable
|
Secret logged (argument) |
β Detected (expected)
|
secret_logged_csharp.cs |
Vulnerable
|
Secret logged (C#) |
β Detected (expected)
|
secret_logged_fstring.py |
Vulnerable
|
Secret logged (f-string) |
β Detected (expected)
|
secret_logged_java.java |
Vulnerable
|
Secret logged (Java) |
β Detected (expected)
|
secret_logged_php.php |
Vulnerable
|
Secret logged (PHP) |
β Detected (expected)
|
security_questions.py |
Vulnerable
|
Security Questions Usage |
β Detected (expected)
|
sensitive_get_query.js |
Vulnerable
|
sensitive_get_query |
β Detected (expected)
|
server_crash_unhandled.js |
Vulnerable
|
server_crash_unhandled |
β Detected (expected)
|
service_worker_hijack.js |
Vulnerable
|
Service Worker Hijack |
β Detected (expected)
|
session_fixation.js |
Vulnerable
|
session_fixation |
β Detected (expected)
|
session_not_abandoned.cs |
Vulnerable
|
session_not_abandoned |
β Detected (expected)
|
shell_injection_from_env.js |
Vulnerable
|
shell_injection_from_env |
β Detected (expected)
|
smtp_injection_php.php |
Vulnerable
|
SMTP Header Injection (PHP) |
β Detected (expected)
|
smtp_injection_python.py |
Vulnerable
|
SMTP Header Injection (Python) |
β Detected (expected)
|
socket_auth_race.java |
Vulnerable
|
socket_auth_race |
β Detected (expected)
|
spel_injection.java |
Vulnerable
|
SpEL injection |
β Detected (expected)
|
spring_actuator_exposed.java |
Vulnerable
|
Spring Actuator Exposed |
β Detected (expected)
|
spring_cors_permissive.java |
Vulnerable
|
Permissive CORS configuration |
β Detected (expected)
|
spring_csrf_disabled.java |
Vulnerable
|
Spring CSRF disabled |
β Detected (expected)
|
sql_injection_concat.py |
Vulnerable
|
SQL Injection (concat) |
β Detected (expected)
|
sql_injection_concat_csharp.cs |
Vulnerable
|
SQL injection (C# concatenation) |
β Detected (expected)
|
sql_injection_concat_java.java |
Vulnerable
|
SQL injection (Java concatenation) |
β Detected (expected)
|
sql_injection_concat_php.php |
Vulnerable
|
SQL injection (PHP concatenation) |
β Detected (expected)
|
sql_injection_dapper.cs |
Vulnerable
|
SQL injection via Dapper raw query |
β Detected (expected)
|
sql_injection_dapper.py |
Vulnerable
|
SQL injection via Dapper raw query |
β Detected (expected)
|
sql_injection_django_raw.py |
Vulnerable
|
SQL injection via Django raw SQL |
β Detected (expected)
|
sql_injection_doctrine.php |
Vulnerable
|
SQL injection via Doctrine DQL |
β Detected (expected)
|
sql_injection_format_java.java |
Vulnerable
|
SQL injection (Java String.format) |
β Detected (expected)
|
sql_injection_format_string_python 2.py |
Vulnerable
|
|
β Detected (expected)
|
sql_injection_format_string_python.py |
Vulnerable
|
SQL injection via % format string (Python) |
β Detected (expected)
|
sql_injection_fstring.py |
Vulnerable
|
SQL Injection (f-string) |
β Detected (expected)
|
sql_injection_java_broad.java |
Vulnerable
|
SQL Injection (Java) |
β Detected (expected)
|
sql_injection_jpa_native.java |
Vulnerable
|
SQL injection via JPA/Hibernate native query |
β Detected (expected)
|
sql_injection_mybatis.java |
Vulnerable
|
SQL injection via MyBatis ${} interpolation |
β Detected (expected)
|
sql_injection_prisma.js |
Vulnerable
|
SQL injection via Prisma $queryRaw |
β Detected (expected)
|
sql_injection_raw_js 2.js |
Vulnerable
|
|
β Detected (expected)
|
sql_injection_raw_js.js |
Vulnerable
|
SQL injection in raw query (JavaScript) |
β Detected (expected)
|
sql_injection_sequelize.js |
Vulnerable
|
SQL injection via Sequelize raw query |
β Detected (expected)
|
sql_injection_sqlalchemy_text.py |
Vulnerable
|
SQL injection via SQLAlchemy text() |
β Detected (expected)
|
sql_injection_string_format_csharp 2.cs |
Vulnerable
|
|
β Detected (expected)
|
sql_injection_string_format_csharp.cs |
Vulnerable
|
SQL injection via string.Format (C#) |
β Detected (expected)
|
sql_injection_typeorm.js |
Vulnerable
|
SQL injection via TypeORM raw query |
β Detected (expected)
|
sql_injection_whereraw_php.php |
Vulnerable
|
SQL injection via Laravel whereRaw/havingRaw |
β Detected (expected)
|
sql_injection_wpdb.php |
Vulnerable
|
SQL injection via WordPress $wpdb |
β Detected (expected)
|
sql_order_by_injection_python 2.py |
Vulnerable
|
|
β Detected (expected)
|
sql_order_by_injection_python.py |
Vulnerable
|
ORDER BY injection (Python) |
β Detected (expected)
|
ssl_bypass_csharp.cs |
Vulnerable
|
SSL/TLS bypass (C#) |
β Detected (expected)
|
ssl_bypass_java.java |
Vulnerable
|
SSL/TLS bypass (Java) |
β Detected (expected)
|
ssl_no_cert_validation.py |
Vulnerable
|
SSL cert validation disabled |
β Detected (expected)
|
ssrf_csharp.cs |
Vulnerable
|
Server-Side Request Forgery (C#) |
β Detected (expected)
|
ssrf_java.java |
Vulnerable
|
Server-Side Request Forgery (Java) |
β Detected (expected)
|
ssrf_javascript.js |
Vulnerable
|
Server-Side Request Forgery (JavaScript) |
β Detected (expected)
|
ssrf_pdf_generation.py |
Vulnerable
|
SSRF via PDF Generation |
β Detected (expected)
|
ssrf_php.php |
Vulnerable
|
Server-Side Request Forgery (PHP) |
β Detected (expected)
|
ssrf_python.py |
Vulnerable
|
Server-Side Request Forgery (Python) |
β Detected (expected)
|
ssti_javascript.js |
Vulnerable
|
Server-Side Template Injection (JavaScript) |
β Detected (expected)
|
ssti_python.py |
Vulnerable
|
Server-Side Template Injection (Python) |
β Detected (expected)
|
static_initialization_vector.java |
Vulnerable
|
static_initialization_vector |
β Detected (expected)
|
stored_procedure_dynamic_csharp 2.cs |
Vulnerable
|
|
β Detected (expected)
|
stored_procedure_dynamic_csharp.cs |
Vulnerable
|
Dynamic stored procedure (C#) |
β Detected (expected)
|
stored_procedure_dynamic_java 2.java |
Vulnerable
|
|
β Detected (expected)
|
stored_procedure_dynamic_java.java |
Vulnerable
|
Dynamic stored procedure (Java) |
β Detected (expected)
|
stored_procedure_dynamic_php 2.php |
Vulnerable
|
|
β Detected (expected)
|
stored_procedure_dynamic_php.php |
Vulnerable
|
Dynamic stored procedure (PHP) |
β Detected (expected)
|
stored_xss.js |
Vulnerable
|
stored_xss |
β Detected (expected)
|
style_inline.js |
Vulnerable
|
Inline style in JS |
β Detected (expected)
|
svelte_at_html.js |
Vulnerable
|
Svelte {@html} β XSS risk |
β Detected (expected)
|
svg_inline.html |
Vulnerable
|
Inline SVG in HTML |
β Detected (expected)
|
svg_scriptable_content.html |
Vulnerable
|
SVG With Scriptable Content |
β Detected (expected)
|
system_out_java.java |
Vulnerable
|
System.out in production (Java) |
β Detected (expected)
|
taint_codeinj.cs |
Vulnerable
|
Taint Code Injection |
β Detected (expected)
|
taint_codeinj.java |
Vulnerable
|
Taint Code Injection |
β Missed
|
taint_codeinj.js |
Vulnerable
|
Taint Code Injection |
β Missed
|
taint_codeinj.php |
Vulnerable
|
Taint Code Injection |
β Detected (expected)
|
taint_codeinj.py |
Vulnerable
|
Taint Code Injection |
β Detected (expected)
|
taint_cookie_injection.cs |
Vulnerable
|
taint_cookie_injection |
β Detected (expected)
|
taint_cookie_injection.java |
Vulnerable
|
taint_cookie_injection |
β Detected (expected)
|
taint_cookie_injection.js |
Vulnerable
|
taint_cookie_injection |
β Missed
|
taint_cookie_injection.php |
Vulnerable
|
taint_cookie_injection |
β Detected (expected)
|
taint_cookie_injection.py |
Vulnerable
|
taint_cookie_injection |
β Detected (expected)
|
taint_deserialization.cs |
Vulnerable
|
Taint Deserialization |
β Detected (expected)
|
taint_deserialization.java |
Vulnerable
|
Taint Deserialization |
β Detected (expected)
|
taint_deserialization.js |
Vulnerable
|
Taint Deserialization |
β Missed
|
taint_deserialization.php |
Vulnerable
|
Taint Deserialization |
β Detected (expected)
|
taint_deserialization.py |
Vulnerable
|
Taint Deserialization |
β Detected (expected)
|
taint_graphql_injection.cs |
Vulnerable
|
taint_graphql_injection |
β Detected (expected)
|
taint_graphql_injection.java |
Vulnerable
|
taint_graphql_injection |
β Detected (expected)
|
taint_graphql_injection.js |
Vulnerable
|
taint_graphql_injection |
β Missed
|
taint_graphql_injection.php |
Vulnerable
|
taint_graphql_injection |
β Detected (expected)
|
taint_graphql_injection.py |
Vulnerable
|
taint_graphql_injection |
β Detected (expected)
|
taint_header_injection.cs |
Vulnerable
|
taint_header_injection |
β Detected (expected)
|
taint_header_injection.java |
Vulnerable
|
taint_header_injection |
β Detected (expected)
|
taint_header_injection.js |
Vulnerable
|
taint_header_injection |
β Missed
|
taint_header_injection.php |
Vulnerable
|
taint_header_injection |
β Detected (expected)
|
taint_header_injection.py |
Vulnerable
|
taint_header_injection |
β Detected (expected)
|
taint_ldap.cs |
Vulnerable
|
Taint LDAP Injection |
β Detected (expected)
|
taint_ldap.java |
Vulnerable
|
Taint LDAP Injection |
β Detected (expected)
|
taint_ldap.js |
Vulnerable
|
Taint LDAP Injection |
β Missed
|
taint_ldap.php |
Vulnerable
|
Taint LDAP Injection |
β Detected (expected)
|
taint_ldap.py |
Vulnerable
|
Taint LDAP Injection |
β Detected (expected)
|
taint_log_injection.cs |
Vulnerable
|
Taint Log Injection |
β Detected (expected)
|
taint_log_injection.java |
Vulnerable
|
Taint Log Injection |
β Detected (expected)
|
taint_log_injection.js |
Vulnerable
|
Taint Log Injection |
β Missed
|
taint_log_injection.php |
Vulnerable
|
Taint Log Injection |
β Detected (expected)
|
taint_log_injection.py |
Vulnerable
|
Taint Log Injection |
β Detected (expected)
|
taint_nosql.cs |
Vulnerable
|
taint_nosql |
β Detected (expected)
|
taint_nosql.java |
Vulnerable
|
taint_nosql |
β Detected (expected)
|
taint_nosql.js |
Vulnerable
|
taint_nosql |
β Missed
|
taint_nosql.php |
Vulnerable
|
taint_nosql |
β Detected (expected)
|
taint_nosql.py |
Vulnerable
|
taint_nosql |
β Detected (expected)
|
taint_open_redirect.cs |
Vulnerable
|
Taint Open Redirect |
β Detected (expected)
|
taint_open_redirect.java |
Vulnerable
|
Taint Open Redirect |
β Detected (expected)
|
taint_open_redirect.js |
Vulnerable
|
Taint Open Redirect |
β Missed
|
taint_open_redirect.php |
Vulnerable
|
Taint Open Redirect |
β Detected (expected)
|
taint_open_redirect.py |
Vulnerable
|
Taint Open Redirect |
β Detected (expected)
|
taint_path_traversal.cs |
Vulnerable
|
Taint Path Traversal |
β Detected (expected)
|
taint_path_traversal.java |
Vulnerable
|
Taint Path Traversal |
β Detected (expected)
|
taint_path_traversal.js |
Vulnerable
|
Taint Path Traversal |
β Missed
|
taint_path_traversal.php |
Vulnerable
|
Taint Path Traversal |
β Detected (expected)
|
taint_path_traversal.py |
Vulnerable
|
Taint Path Traversal |
β Detected (expected)
|
taint_rce.cs |
Vulnerable
|
Taint RCE |
β Detected (expected)
|
taint_rce.java |
Vulnerable
|
Taint RCE |
β Detected (expected)
|
taint_rce.js |
Vulnerable
|
Taint RCE |
β Missed
|
taint_rce.php |
Vulnerable
|
Taint RCE |
β Detected (expected)
|
taint_rce.py |
Vulnerable
|
Taint RCE |
β Detected (expected)
|
taint_smtp_injection.cs |
Vulnerable
|
taint_smtp_injection |
β Detected (expected)
|
taint_smtp_injection.java |
Vulnerable
|
taint_smtp_injection |
β Missed
|
taint_smtp_injection.js |
Vulnerable
|
taint_smtp_injection |
β Missed
|
taint_smtp_injection.php |
Vulnerable
|
taint_smtp_injection |
β Detected (expected)
|
taint_smtp_injection.py |
Vulnerable
|
taint_smtp_injection |
β Detected (expected)
|
taint_sqli.cs |
Vulnerable
|
Taint SQL Injection |
β Detected (expected)
|
taint_sqli.java |
Vulnerable
|
Taint SQL Injection |
β Detected (expected)
|
taint_sqli.js |
Vulnerable
|
Taint SQL Injection |
β Missed
|
taint_sqli.php |
Vulnerable
|
Taint SQL Injection |
β Detected (expected)
|
taint_sqli.py |
Vulnerable
|
Taint SQL Injection |
β Detected (expected)
|
taint_ssrf.cs |
Vulnerable
|
Taint SSRF |
β Detected (expected)
|
taint_ssrf.java |
Vulnerable
|
Taint SSRF |
β Detected (expected)
|
taint_ssrf.js |
Vulnerable
|
Taint SSRF |
β Missed
|
taint_ssrf.php |
Vulnerable
|
Taint SSRF |
β Detected (expected)
|
taint_ssrf.py |
Vulnerable
|
Taint SSRF |
β Detected (expected)
|
taint_ssti.cs |
Vulnerable
|
Taint SSTI |
β Detected (expected)
|
taint_ssti.java |
Vulnerable
|
Taint SSTI |
β Detected (expected)
|
taint_ssti.js |
Vulnerable
|
Taint SSTI |
β Missed
|
taint_ssti.php |
Vulnerable
|
Taint SSTI |
β Detected (expected)
|
taint_ssti.py |
Vulnerable
|
Taint SSTI |
β Detected (expected)
|
taint_xpathi.cs |
Vulnerable
|
Taint XPath Injection |
β Detected (expected)
|
taint_xpathi.java |
Vulnerable
|
Taint XPath Injection |
β Detected (expected)
|
taint_xpathi.js |
Vulnerable
|
Taint XPath Injection |
β Missed
|
taint_xpathi.php |
Vulnerable
|
Taint XPath Injection |
β Detected (expected)
|
taint_xpathi.py |
Vulnerable
|
Taint XPath Injection |
β Detected (expected)
|
taint_xss.cs |
Vulnerable
|
Taint XSS |
β Detected (expected)
|
taint_xss.java |
Vulnerable
|
Taint XSS |
β Detected (expected)
|
taint_xss.js |
Vulnerable
|
Taint XSS |
β Missed
|
taint_xss.php |
Vulnerable
|
Taint XSS |
β Detected (expected)
|
taint_xss.py |
Vulnerable
|
Taint XSS |
β Detected (expected)
|
taint_xxe.cs |
Vulnerable
|
Taint XXE |
β Detected (expected)
|
taint_xxe.java |
Vulnerable
|
Taint XXE |
β Detected (expected)
|
taint_xxe.js |
Vulnerable
|
Taint XXE |
β Missed
|
taint_xxe.php |
Vulnerable
|
Taint XXE |
β Detected (expected)
|
taint_xxe.py |
Vulnerable
|
Taint XXE |
β Detected (expected)
|
tainted_format_string.js |
Vulnerable
|
tainted_format_string |
β Detected (expected)
|
tainted_permissions_check.java |
Vulnerable
|
tainted_permissions_check |
β Detected (expected)
|
tarfile_unsafe_extract.py |
Vulnerable
|
Unsafe tar extraction |
β Detected (expected)
|
temp_dir_info_disclosure.java |
Vulnerable
|
temp_dir_info_disclosure |
β Detected (expected)
|
template_injection_java.java |
Vulnerable
|
template_injection_java |
β Detected (expected)
|
template_object_injection.js |
Vulnerable
|
template_object_injection |
β Detected (expected)
|
toctou_race_condition.java |
Vulnerable
|
toctou_race_condition |
β Detected (expected)
|
todo_comment.py |
Vulnerable
|
Unresolved TODO/FIXME |
β Detected (expected)
|
todo_unresolved.java |
Vulnerable
|
Unresolved TODO/FIXME |
β Detected (expected)
|
todo_unresolved.js |
Vulnerable
|
Unresolved TODO/FIXME |
β Detected (expected)
|
todo_unresolved.py |
Vulnerable
|
Unresolved TODO/FIXME |
β Detected (expected)
|
trust_boundary_java.java |
Vulnerable
|
Trust Boundary Violation |
β Detected (expected)
|
trust_boundary_python.py |
Vulnerable
|
Trust boundary violation |
β Detected (expected)
|
type_confusion_parameter.js |
Vulnerable
|
type_confusion_parameter |
β Detected (expected)
|
type_juggling_php.php |
Vulnerable
|
Type juggling (PHP) |
β Detected (expected)
|
unbounded_query.py |
Vulnerable
|
Unbounded Query |
β Detected (expected)
|
unbounded_query_java 2.java |
Vulnerable
|
|
β Detected (expected)
|
unbounded_query_java.java |
Vulnerable
|
Unbounded query (Java) |
β Detected (expected)
|
unbounded_query_js 2.js |
Vulnerable
|
|
β Detected (expected)
|
unbounded_query_js.js |
Vulnerable
|
Unbounded query (JavaScript) |
β Detected (expected)
|
unbounded_query_php 2.php |
Vulnerable
|
|
β Detected (expected)
|
unbounded_query_php.php |
Vulnerable
|
Unbounded query (PHP) |
β Detected (expected)
|
uncontrolled_format_string.cs |
Vulnerable
|
uncontrolled_format_string |
β Detected (expected)
|
unencrypted_transfer.py |
Vulnerable
|
Unencrypted Data Transfer |
β Detected (expected)
|
unpinned_action_version.yml |
Vulnerable
|
Unpinned action version |
β Detected (expected)
|
unpinned_composer.json |
Vulnerable
|
Unpinned Dependency |
β Detected (expected)
|
unpinned_csproj.xml |
Vulnerable
|
Unpinned Dependency |
β Detected (expected)
|
unpinned_package.json |
Vulnerable
|
Unpinned Dependency |
β Detected (expected)
|
unpinned_pom.xml |
Vulnerable
|
Unpinned Dependency |
β Detected (expected)
|
unpinned_requirements.txt |
Vulnerable
|
Unpinned Dependency |
β Detected (expected)
|
unrestricted_file_upload_java 2.java |
Vulnerable
|
|
β Detected (expected)
|
unrestricted_file_upload_java.java |
Vulnerable
|
Unrestricted file upload (Java/Spring) |
β Detected (expected)
|
unrestricted_file_upload_js 2.js |
Vulnerable
|
|
β Detected (expected)
|
unrestricted_file_upload_js.js |
Vulnerable
|
Unrestricted file upload (Node.js/Multer) |
β Detected (expected)
|
unrestricted_file_upload_php 2.php |
Vulnerable
|
|
β Detected (expected)
|
unrestricted_file_upload_php.php |
Vulnerable
|
Unrestricted file upload (PHP) |
β Detected (expected)
|
unreviewed_vendor_code.py |
Vulnerable
|
Unreviewed Vendor Code |
β Detected (expected)
|
unsafe_code_construction.js |
Vulnerable
|
unsafe_code_construction |
β Detected (expected)
|
unsafe_deserialization.py |
Vulnerable
|
Unsafe deserialization |
β Detected (expected)
|
unsafe_deserialization_csharp.cs |
Vulnerable
|
Unsafe deserialization (C#) |
β Detected (expected)
|
unsafe_deserialization_delegate.cs |
Vulnerable
|
unsafe_deserialization_delegate |
β Detected (expected)
|
unsafe_deserialization_java.java |
Vulnerable
|
Unsafe deserialization (Java) |
β Detected (expected)
|
unsafe_deserialization_php.php |
Vulnerable
|
Unsafe deserialization (PHP) |
β Detected (expected)
|
unsafe_dynamic_method_access.js |
Vulnerable
|
unsafe_dynamic_method_access |
β Detected (expected)
|
unsafe_html_expansion.js |
Vulnerable
|
unsafe_html_expansion |
β Detected (expected)
|
unsafe_require.js |
Vulnerable
|
require() with dynamic variable |
β Detected (expected)
|
unsafe_shell_construction.py |
Vulnerable
|
unsafe_shell_construction |
β Detected (expected)
|
unvalidated_dynamic_method_call.js |
Vulnerable
|
unvalidated_dynamic_method_call |
β Detected (expected)
|
unvalidated_input.py |
Vulnerable
|
Unvalidated input (OS injection) |
β Detected (expected)
|
url_forward_injection.java |
Vulnerable
|
url_forward_injection |
β Detected (expected)
|
use_ssl_socket.java |
Vulnerable
|
use_ssl_socket |
β Detected (expected)
|
useless_regexp_escape.js |
Vulnerable
|
useless_regexp_escape |
β Detected (expected)
|
verbose_exception.py |
Vulnerable
|
Verbose exception |
β Detected (expected)
|
verbose_exception_csharp.cs |
Vulnerable
|
Verbose exception (C#) |
β Detected (expected)
|
verbose_exception_java.java |
Vulnerable
|
Verbose exception (Java) |
β Detected (expected)
|
verbose_exception_php.php |
Vulnerable
|
Verbose exception (PHP) |
β Detected (expected)
|
vue_v_html.js |
Vulnerable
|
Vue.js v-html β XSS risk |
β Detected (expected)
|
vulnerable_package.json |
Vulnerable
|
Vulnerable Dependency |
β Detected (expected)
|
vulnerable_pyproject.toml |
Vulnerable
|
Vulnerable Dependency |
β Detected (expected)
|
vulnerable_requirements.txt |
Vulnerable
|
Vulnerable Dependency |
β Detected (expected)
|
weak_cipher_java.java |
Vulnerable
|
Weak Cipher (Java) |
β Detected (expected)
|
weak_crypto.py |
Vulnerable
|
Weak cryptographic algorithm |
β Detected (expected)
|
weak_crypto_csharp.cs |
Vulnerable
|
Weak cryptography (C#) |
β Detected (expected)
|
weak_crypto_java.java |
Vulnerable
|
Weak cryptography (Java) |
β Detected (expected)
|
weak_crypto_php.php |
Vulnerable
|
Weak cryptography (PHP) |
β Detected (expected)
|
weak_password_hash.py |
Vulnerable
|
Weak Password Hash |
β Detected (expected)
|
weak_password_hash_php 2.php |
Vulnerable
|
|
β Detected (expected)
|
weak_password_hash_php.php |
Vulnerable
|
Weak password hashing (PHP) |
β Detected (expected)
|
weak_password_policy.py |
Vulnerable
|
Weak Password Policy |
β Detected (expected)
|
weak_random_csharp.cs |
Vulnerable
|
Weak random (C#) |
β Detected (expected)
|
weak_random_java.java |
Vulnerable
|
Weak random (Java) |
β Detected (expected)
|
weak_random_java_util.java |
Vulnerable
|
Weak Random (Java) |
β Detected (expected)
|
weak_random_php.php |
Vulnerable
|
Weak random (PHP) |
β Detected (expected)
|
weak_random_python.py |
Vulnerable
|
Weak random number generator |
β Detected (expected)
|
websocket_no_tls.js |
Vulnerable
|
WebSocket Without TLS |
β Detected (expected)
|
websocket_no_tls.py |
Vulnerable
|
WebSocket Without TLS |
β Detected (expected)
|
websocket_no_validation.js |
Vulnerable
|
WebSocket No Validation |
β Detected (expected)
|
window_open_noopener.js |
Vulnerable
|
window.open without noopener |
β Detected (expected)
|
workflow_not_in_codeowners.yml |
Vulnerable
|
Workflows missing from CODEOWNERS |
β Detected (expected)
|
world_writable_file_read.java |
Vulnerable
|
world_writable_file_read |
β Detected (expected)
|
xml_bomb.js |
Vulnerable
|
xml_bomb |
β Detected (expected)
|
xml_bomb.py |
Vulnerable
|
xml_bomb |
β Detected (expected)
|
xml_injection_csharp.cs |
Vulnerable
|
xml_injection_csharp |
β Detected (expected)
|
xpath_injection.js |
Vulnerable
|
xpath_injection |
β Detected (expected)
|
xpath_injection_csharp.cs |
Vulnerable
|
XPath Injection (C#) |
β Detected (expected)
|
xpath_injection_java.java |
Vulnerable
|
XPath Injection (Java) |
β Detected (expected)
|
xpath_injection_java_eval.java |
Vulnerable
|
XPath Injection (Java) |
β Detected (expected)
|
xpath_injection_php.php |
Vulnerable
|
XPath Injection (PHP) |
β Detected (expected)
|
xpath_injection_python.py |
Vulnerable
|
XPath Injection (Python) |
β Detected (expected)
|
xslt_injection.java |
Vulnerable
|
xslt_injection |
β Detected (expected)
|
xss_angular_bypass.js |
Vulnerable
|
XSS via Angular security bypass |
β Detected (expected)
|
xss_blade_unescaped.php |
Vulnerable
|
XSS via unescaped Blade output |
β Detected (expected)
|
xss_echo_php.php |
Vulnerable
|
XSS via echo (PHP) |
β Detected (expected)
|
xss_exception_exposure.js |
Vulnerable
|
xss_exception_exposure |
β Detected (expected)
|
xss_flask_reflected.py |
Vulnerable
|
Reflected XSS (Flask) |
β Detected (expected)
|
xss_innerhtml.js |
Vulnerable
|
XSS via innerHTML |
β Detected (expected)
|
xss_jquery_unsafe_plugin.js |
Vulnerable
|
xss_jquery_unsafe_plugin |
β Detected (expected)
|
xss_raw_html.cs |
Vulnerable
|
XSS via Html.Raw() |
β Detected (expected)
|
xss_raw_html.py |
Vulnerable
|
XSS via Html.Raw() |
β Detected (expected)
|
xss_react_dangerous.js |
Vulnerable
|
XSS via React dangerouslySetInnerHTML |
β Detected (expected)
|
xss_servlet_response.java |
Vulnerable
|
XSS Servlet Response |
β Detected (expected)
|
xss_through_dom.js |
Vulnerable
|
xss_through_dom |
β Detected (expected)
|
xss_unsafe_html_construction.js |
Vulnerable
|
xss_unsafe_html_construction |
β Detected (expected)
|
xxe_injection.java |
Vulnerable
|
XXE injection |
β Detected (expected)
|
xxe_injection.js |
Vulnerable
|
XXE injection |
β Detected (expected)
|
xxe_injection_csharp.cs |
Vulnerable
|
XXE injection (C#) |
β Detected (expected)
|
xxe_injection_php.php |
Vulnerable
|
XXE injection (PHP) |
β Detected (expected)
|
xxe_injection_python.py |
Vulnerable
|
XXE injection (Python) |
β Detected (expected)
|
xxe_xmldocument.cs |
Vulnerable
|
xxe_xmldocument |
β Detected (expected)
|
zip_bomb.py |
Vulnerable
|
Zip bomb vulnerability |
β Detected (expected)
|
zip_slip.java |
Vulnerable
|
zip_slip |
β Detected (expected)
|
zip_slip_csharp.cs |
Vulnerable
|
zip_slip_csharp |
β Detected (expected)
|