Vulnerability Intelligence Database
Browse our comprehensive library of security vulnerabilities, misconfigurations, and compliance failures. Find threat details, CWE definitions, and code-level remediation rules.
Server & Directory Exposures
Injection & Client-Side Attacks
SQL Injection (SQLi)
Execution of malicious database queries.
Stored Cross-Site Scripting (Stored XSS)
Malicious scripts stored on target databases.
Reflected Cross-Site Scripting (Reflected XSS)
Direct reflection of script variables.
DOM-based Cross-Site Scripting (DOM XSS)
Client-side javascript source/sink execution.
Cross-Site Request Forgery (CSRF)
Unauthorized session command hijackings.
Clickjacking (UI Redress Attack)
Overlaying transparent frame interfaces.
Open Redirect Vulnerability
Routing users to untrusted destinations.
HTTP Security Headers
Missing Content Security Policy (CSP)
No restrictions on script execution paths.
Missing HTTP Strict Transport Security (HSTS)
No SSL stripping protection policies.
Missing X-Frame-Options Header
No clickjacking frame restrictions.
Missing X-Content-Type-Options Header
No protection against browser MIME-sniffing.