Help Center
News
Indusface
Help Center
News
Indusface
AppTrana
OverviewOnboarding to AppTranaComparison between Old Portal and New PortalSAML Integration with Entra ID for Single Sign-On - AppTrana WAF
Dashboard
AppTrana Dashboard
Applications & Groups
Protection StatusDiscover AssetsDNS ManagementManage Groups
API Security
API Protection API Scanning API Discovery
Manage Assets
Application DetailsOrigin Server AddressOrigin Health Check MechanismSSL Details
WAAP Policies
Behavioral DDoS ProtectionAttack ShieldBOT PoliciesCustomize Application Behavior with BOT Confidence ScoreWAF StatusMalware Scanning for File UploadsGlobal Traffic Access SettingsASN Based IP WhitelistingBrowser ProtectionCore and Custom Rules
Vulnerabilities
Manage VulnerabilitiesSwyftComply for Auto Scan & Manual PentestSwyftComply for API ScanWhitelist Vulnerabilities
Attacks
Manage Attacks
Bandwidth
FAQs on CDNManage Bandwidth
Actions
Actions
Logs & Reports
Access LogsAttack LogsFalse Positive Analysis Report
License & Utilizatiion
Licenses & Utilization
Settings
Manage ProfileRole-Based Access Control (RBAC)Enable SIEM IntegrationSIEM Integration through API Configure Custom Error & Maintenance PageCI/CD IntegrationAppTrana and Jira Integration
Profile
Password ManagementManage Email Alerts
Others
WAF Automated Bypass and Unbypass
AI Shield
AI Shield
Indusface WAS
Onboard into Indusface WASSAML Integration with Entra ID for Single Sign-On - Indusface WAS
Summary
SummaryWAS Consulting License
Dashboard
Dashboard
Malware Monitoring
WAS Defacement ChecksMalware Monitoring
Application Audit
Application Audit
Vulnerability Assessment
Vulnerability Assessment
API Security Audit
API Security Audit
Asset Monitoring
Asset Monitoring
EASM
External Attack Surface Management (EASM)
Reports
Reports
Vulnerabilities
Vulnerabilities Web App Secrets API AcuRisQ – Risk Management with Advanced Risk Scoring
Settings
SettingsAPI Key Based - Scan Log ExportSIEM Integration with Sumo LogicJenkins Security ScanAutomate Issue Reporting: JIRA & WAS Integration
Indusface WAS MSSP
Indusface WAS MSSP
Summary
Summary
Dashboard
Dashboard
Application Scan
Application Scan
API Security Audit
API Security Audit
Reports
Reports
Settings
SettingsWebsite UsersGroups Report Protection Email Notification Company Service Mapping
WAS MSSP Consultant
WAS MSSP Consultant
Administrators
Administrators
WAS MSSP Consultant Admin
WAS MSSP Consultant Admin Consultancy Service Listing Manual Scan API Service List Vulnerability Add Vulnerability
Additional Resources
AppTrana Protection WAF Rules CoverageIndusface WAS Scanned VulnerabilitiesAppTrana API Protection - OWASP Top 10 of 2019API Scan Coverage for OWASP Top 10OWASP API Security Top 10 2023 – AppTrana API ProtectionInput Form Field Values Used by Indusface WAS Scanner During Crawling
Zero-Day Vulnerability Reports
Zero-Day Reports
Vulnerabilities Identified in 2021
Vulnerability Report of January 2021Vulnerability Report of February 2021Vulnerability Report of March 2021Vulnerability Report of April 2021Vulnerability Report of May 2021Vulnerability Report of June 2021Vulnerability Report of July 2021Vulnerability Report of August 2021Vulnerability Report of September 2021Vulnerability Report of October 2021Vulnerability Report of November 2021Vulnerability Report of December 2021
Vulnerabilities Identified in 2022
Vulnerability Report of January 2022Vulnerability Report of February 2022Vulnerability Report of March 2022Vulnerability Report of April 2022Vulnerability Report of May 2022Vulnerability Report of June 2022Vulnerability Report of July 2022Vulnerability Report of August 2022Vulnerability Report of September 2022Vulnerability Report of October 2022Vulnerability Report of November 2022Vulnerability Report of December 2022
Vulnerabilities Identified in 2023
Vulnerability Report of January 2023Vulnerability Report of February 2023Vulnerability Report of March 2023Vulnerability Report of April 2023Vulnerability Report of May 2023Vulnerability Report of June 2023Vulnerability Report of July 2023Vulnerability Report of August 2023Vulnerability Report of September 2023Vulnerability Report of October 2023Vulnerability Report of November 2023Vulnerability Report of December 2023
Vulnerabilities Identified in 2024
Vulnerability Report of January 2024Vulnerability Report of February 2024Vulnerability Report of March 2024Vulnerability Report of April 2024Vulnerability Report of May 2024Vulnerability Report of June 2024Vulnerability Report of July 2024Vulnerability Report of August 2024Vulnerability Report of September 2024Vulnerability Report of October 2024Vulnerability Report of November 2024Vulnerability Report of December 2024
Vulnerabilities Identified in 2025
Vulnerability Report of January 2025Vulnerability Report of February 2025Vulnerability Report of March 2025Vulnerability Report of April 2025 Vulnerability Report of May 2025Vulnerability Report of June 2025 Vulnerability Report of July 2025 Vulnerability Report of August 2025 Vulnerability Report of September 2025 Vulnerability Report of October 2025 Vulnerability Report of November 2025 Vulnerability Report of December 2025
Vulnerabilities Identified in 2026
Vulnerability Report of January 2026Vulnerability Report of February 2026 Vulnerability Report of March 2026 Vulnerability Report of April 2026
Security Bulletins
Latest Threats & AppTrana Coverage
Vulnerabilities 2024
Hotjar's OAuth+XSS Flaw Exposes Millions at Risk of Account TakeoverCritical Apache OFBiz Zero-day AuthBiz (CVE-2023-49070 and CVE-2023-51467)CVE-2024-4879 & CVE-2024-5217 Exposed - The Risks of RCE in ServiceNowScreenConnect Authentication Bypass (CVE-2024-1709 & CVE-2024-1708)CVE-2024-4577 – A PHP CGI Argument Injection Vulnerability in Windows ServersCVE-2024-8517 – Unauthenticated Remote Code Execution in SPIPCVE-2024-1071 – Critical Vulnerability in Ultimate Member WordPress PluginCryptocurrency Mining Attack Exploiting PHP Vulnerabilities: An Emerging Threat
Vulnerabilities 2025
Credential Coercion Vulnerabilities in Ivanti Endpoint Manager CVE-2024-4577 - PHP-CGI RCE Exploitation in Windows ServersCVE-2025-24813 - Apache Tomcat Vulnerability Under Active Exploitation CVE-2017-12637: Exploitation of SAP NetWeaver Directory Traversal Vulnerability SAP Zero-Day CVE-2025-31324: Unauthenticated RCE in NetWeaver VCFRAMEWORK CVE-2025-31650: Tomcat HTTP/2 Flaw Leads to DoS ExposureCVE-2025-4123: The Grafana Ghost Vulnerability that Enables Account TakeoverCVE-2025-53770: SharePoint Zero-Day Under Active ExploitationCVE-2025-54253: Critical Zero-Day Vulnerability in Adobe Experience Manager FormsCl0p Exploits Critical Oracle E-Business Suite Zero-Day (CVE-2025-61882)Multiple XSS Vulnerabilities in Liferay Portal & DXP: Analysis, Impact, and PreventionCVE-2025-59287: Critical WSUS Vulnerability Exploited in the WildSessionReaper (CVE-2025-54236): Impact, Detection, and MitigationDjango Vulnerabilities Expose Apps to SQL Injection and DoS AttacksCVE-2025-55752: Apache Tomcat Path Traversal VulnerabilityCVE-CVE-2025-64446: Critical FortiWeb Path Traversal Vulnerability Under Active ExploitationCVE-2025-54057: Stored XSS Vulnerability in Apache SkyWalking Exposes Monitoring Dashboards to AttackersReact2Shell(CVE-2025-55182): Critical RCE Vulnerability in React Server Components and Next.jsCVE-2025-66516: Critical XXE Vulnerability Exposes Apache Tika DeploymentsCVE-2025-10573: Critical Unauthenticated Stored XSS in Ivanti Endpoint ManagerCVE-2025-66675: Apache Struts DoS Vulnerability Leads to Disk ExhaustionReact After React2Shell: New RSC Vulnerabilities Expose DoS and Source Code RisksApache Commons Text Code Injection Vulnerability (CVE-2025-46295)CVE-2025-68613: Critical n8n RCE Vulnerability Enables Full Server CompromiseCritical Node.js Vulnerabilities Expose Uninitialized Memory (CVE-2025-55131)CVE-2025-3248: Critical Langflow Unauthenticated Remote Code Execution Vulnerability
Vulnerabilities 2026
CVE-2026-21858 (Ni8mare): Unauthenticated Remote Code Execution in Self-Hosted n8nCVE-2026-22610: Angular Template Compiler XSS Vulnerability Enabling Client-Side Script ExecutionCVE-2025-11953 – Metro4Shell RCE in React Native Metro ServerCVE-2026-1281 & CVE-2026-1340: Actively Exploited Pre-Authentication RCE in Ivanti EPMMCVE-2026-1357: WordPress Plugin RCE Exposes Sites to Full TakeoverCVE-2026-27739: Angular SSR Request Vulnerability CVE-2026-32201: SharePoint Spoofing Vulnerability Enabling Unauthenticated ImpersonationCVE-2026-34197: Apache ActiveMQ Jolokia RCE VulnerabilityCVE-2026-41940: WebPros cPanel & WHM and WP2 (WordPress Squared) Missing Authentication for Critical Function VulnerabilityCVE-2026-23918: Apache HTTP/2 Double-Free Vulnerability with Possible RCEBleeding Llama (CVE-2026-7482): Critical Unauthenticated Memory Leak in Ollama
Other Vulnerabilities
Apache Struts 2 Vulnerability CVE-2023-50164 ExposedCVE-2024-8190 – OS Command Injection in Ivanti CSACVE-2024-9264 - Grafana’s SQL Expressions VulnerabilityHTTP/2 Rapid Reset Attack VulnerabilityOracle WebLogic Server DeserializationApache Struts Remote Code Execution Vulnerability (CVE-2018-11776) Unpacking the Zimbra Cross-Site Scripting Vulnerability(CVE-2023-37580)Adobe ColdFusion Vulnerabilities Exploited in the WildRemote Unauthenticated API Access Vulnerabilities in IvantiMultiple Moveit Transfer VulnerabilitiesApache log4j RCE vulnerability
AppTrana API Integration
AppTrana API Access via Token-Based Authentication API Request to Purge CDN DataUpdate Origin Server Address through API CallAPI Request to Blacklist IPs
Release Notes
Release Notes
Indusface WAS
Indusface WAS 1.1.0

API Scan Coverage for OWASP Top 10

Go through the following report for API Scan Coverage for OWASP Top 10 - 2023.

API Scan Coverage for OWASP Top 10.pdf

Was this helpful?

Powered by Product Fruits