High

TitleLanguage
zypper clean' missingterraform
yum clean all' missingterraform
XML Injectionpython
WORKDIR should not be mounted on system dirsterraform
WORKDIR path not absoluteterraform
Web App uses latest TLS versionterraform
Verify that the RotateKubeletServerCertificate argument is set to trueterraform
Verify that the --read-only-port argument is set to 0terraform
Use of Weak Hashjava
Use of Weak Hashjava
Use of Weak Hashjava
Use of Weak Hashclojure
Use of RSA Algorithm without OAEPscala
Use of RSA Algorithm without OAEPcsharp
Use of Hard-coded Credentialsruby
Use of Hard-coded Credentialsruby
Use of Hard-coded Credentialspython
Use of Hard-coded Credentialsjavascript
Use of Hard-coded Credentialsjavascript
Use of Hard-coded Credentialsjavascript
Use of Hard-coded Credentialsjavascript
Use of Hard-coded Credentialsgo
Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)csharp
Use of a Broken or Risky Cryptographic Algorithmruby
Use of a Broken or Risky Cryptographic Algorithmpython
Use of a Broken or Risky Cryptographic Algorithmpython
Use of a Broken or Risky Cryptographic Algorithmpython
Use of a Broken or Risky Cryptographic Algorithmphp
Use of a Broken or Risky Cryptographic Algorithmjavascript
Use of a Broken or Risky Cryptographic Algorithmjavascript
Use of a Broken or Risky Cryptographic Algorithmjava
Use of a Broken or Risky Cryptographic Algorithmjava
Use of a Broken or Risky Cryptographic Algorithmjava
Use of a Broken or Risky Cryptographic Algorithmjava
Use of a Broken or Risky Cryptographic Algorithmjava
Use of a Broken or Risky Cryptographic Algorithmjava
Use of a Broken or Risky Cryptographic Algorithmjava
Use of a Broken or Risky Cryptographic Algorithmjava
Use of a Broken or Risky Cryptographic Algorithmjava
Use of a Broken or Risky Cryptographic Algorithmjava
Use of a Broken or Risky Cryptographic Algorithmgo
Use of a Broken or Risky Cryptographic Algorithmcsharp
Use of a Broken or Risky Cryptographic Algorithmcsharp
Use of a Broken or Risky Cryptographic Algorithmclojure
URL Redirection to Untrusted Site ('Open Redirect')javascript
URL Redirection to Untrusted Site ('Open Redirect')javascript
URL Redirection to Untrusted Site ('Open Redirect')go
Unencrypted SQS queue.terraform
Unencrypted SNS topic.terraform
Unencrypted S3 bucket.terraform
Unencrypted data lake storage.terraform
Trusting HTTP Permission Methods on the Server Sideruby
Trusted Microsoft Services should have bypass access to Storage accountsterraform
There is no encryption specified or encryption is disabled on the RDS Cluster.terraform
SYS_MODULE capability addedterraform
SYS_ADMIN capability addedterraform
Storage containers in blob storage mode should not have public accessterraform
Storage accounts should be configured to only accept transfers that are over secure connectionsterraform
SSL connections to a SQL database instance should be enforced.terraform
SSH Keys are the preferred way to connect to your droplet, no keys are suppliedterraform
SQS queue should be encrypted with a CMK.terraform
SNS topic not encrypted with CMK.terraform
Shielded GKE nodes not enabled.terraform
Service with External IPterraform
Service accounts should not have roles assigned with excessive privilegesterraform
Server-Side Request Forgery (SSRF)python
Server-Side Request Forgery (SSRF)python
Server-Side Request Forgery (SSRF)python
Server-Side Request Forgery (SSRF)javascript
Server-Side Request Forgery (SSRF)go
SAM Simple table must have server side encryption enabled.terraform
SAM API domain name uses outdated SSL/TLS protocols.terraform
S3 encryption should use Customer Managed Keysterraform
S3 Buckets not publicly accessible through ACL.terraform
S3 Access block should restrict public bucket to limit accessterraform
S3 Access Block should Ignore Public Aclterraform
S3 Access block should block public policyterraform
S3 Access block should block public ACLterraform
RUN <package-manager> update' instruction aloneterraform
Root file system is not read-onlyterraform
Root and user volumes on Workspaces should be encryptedterraform
Reusing a Nonce, Key Pair in Encryptionjava
Relative Path Traversaljava
Redshift clusters should use at rest encryptionterraform
Redshift cluster should be deployed into a specific VPCterraform
RDS Publicly Accessibleterraform
RDS encryption has not been enabled at a DB Instance level.terraform
Public ingress should not be allowed via network policiesterraform
Public egress should not be allowed via network policiesterraform
Privilegedterraform
Prevent binding to privileged portsterraform
Password authentication should be disabled on Azure virtual machinesterraform
Out-of-bounds Writesolidity
Node metadata value disables metadata concealment.terraform
No State Machine Policy Wildcardsterraform
No sensitive data stored in user_dataterraform
NET_RAW capability addedterraform
Neptune storage must be encrypted at restterraform
Neptune encryption should use Customer Managed Keysterraform
Multiple CMD instructions listedterraform
Missing Encryption of Sensitive Datahcl
Missing Authorizationdockerfile
Missing Authentication for Critical Functiontypescript
microdnf clean all' missingterraform
Master authorized networks should be configured on GKE clustersterraform
Manage Kubernetes networkingterraform
Load balancers should drop invalid headersterraform
Load balancer is exposed to the internet.terraform
Legacy metadata endpoints enabled.terraform
Legacy client authentication methods utilized.terraform
Legacy ABAC permissions are enabled.terraform
Launch configuration with unencrypted block device.terraform
Launch configuration should not have a public IP address.terraform
Kubernetes resource with disallowed volumes mountedterraform
KMS keys should be rotated at least every 90 daysterraform
Kinesis stream is unencrypted.terraform
Insufficiently Protected Credentialspython
Insufficiently Protected Credentialsscala
Insufficiently Protected Credentialsscala
Insufficient Verification of Data Authenticityjavascript
Insufficient Session Expirationcsharp
Instances should not have public IP addressesterraform
Instances should not have IP forwarding enabledterraform
Instances in a subnet should not receive a public IP address by default.terraform
Instance with unencrypted block device.terraform
Insertion of Sensitive Information into Externally-Accessible File or Directorygeneric
Inefficient Regular Expression Complexityruby
Incorrect Permission Assignment for Critical Resourcehcl
Incorrect Calculationsolidity
Incorrect Calculationsolidity
Inclusion of Sensitive Information in Source Codeapex
Inclusion of Sensitive Information in Source Codeapex
Inadequate Encryption Strengthruby
Inadequate Encryption Strengthjava
Inadequate Encryption Strengthjava
Inadequate Encryption Strengthjava
Inadequate Encryption Strengthjava
Inadequate Encryption Strengthjava
Inadequate Encryption Strengthkotlin
Inadequate Encryption Strengthgo
Inadequate Encryption Strengthgeneric
Inadequate Encryption Strengthterraform
Improper Restriction of XML External Entity Referencejavascript
Improper Restriction of XML External Entity Referencejava
Improper Restriction of XML External Entity Referencejava
Improper Restriction of XML External Entity Referencejava
Improper Restriction of XML External Entity Referencejava
Improper Restriction of XML External Entity Referencejava
Improper Restriction of XML External Entity Referencejava
Improper Restriction of XML External Entity Referencescala
Improper Restriction of XML External Entity Referenceclojure
Improper Privilege Managementyaml
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')ruby
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')ruby
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')ruby
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')ruby
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')ruby
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')ruby
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')ruby
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')python
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')python
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')python
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')python
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')python
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')python
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')python
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')python
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')python
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')python
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')python
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')php
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')php
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')php
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')php
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')javascript
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')javascript
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')javascript
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')javascript
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')javascript
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')javascript
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')java
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')java
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')java
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')java
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')java
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')scala
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')scala
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')scala
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')go
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')go
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')go
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')go
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')ruby
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')python
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')python
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')python
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')python
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')python
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')python
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')python
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')python
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')python
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')python
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')python
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')python
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')python
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')python
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')python
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')python
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')python
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')php
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')javascript
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')yaml
Improper Neutralization of Special Elements used in a Command ('Command Injection')terraform
Improper Neutralization of Special Elements in Data Query Logicjavascript
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')ruby
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')ruby
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')ruby
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')python
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')python
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')python
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')python
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')javascript
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')javascript
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')javascript
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')javascript
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')java
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')java
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')scala
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')go
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')generic
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')generic
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')generic
Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection')python
Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection')python
Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection')python
Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection')python
Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection')python
Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection')python
Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection')python
Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection')python
Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection')python
Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection')python
Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection')python
Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection')php
Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection')javascript
Improper Neutralization of Data within XPath Expressions ('XPath Injection')java
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')ruby
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')ruby
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')ruby
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')ruby
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')python
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')javascript
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')java
Improper Input Validationsolidity
Improper Input Validationsolidity
Improper Input Validationsolidity
Improper Enforcement of Behavioral Workflowsolidity
Improper Enforcement of Behavioral Workflowsolidity
Improper Enforcement of Behavioral Workflowsolidity
Improper Enforcement of Behavioral Workflowsolidity
Improper Enforcement of Behavioral Workflowsolidity
Improper Enforcement of Behavioral Workflowsolidity
Improper Enforcement of Behavioral Workflowsolidity
Improper Control of Generation of Code ('Code Injection')ruby
Improper Control of Generation of Code ('Code Injection')ruby
Improper Control of Generation of Code ('Code Injection')php
Improper Control of Generation of Code ('Code Injection')php
Improper Control of Generation of Code ('Code Injection')generic
Improper Certificate Validationruby
Improper Certificate Validationpython
Improper Authenticationjavascript
Improper Authenticationjavascript
Improper Authenticationyaml
Improper Access Controlsolidity
Improper Access Controlsolidity
Improper Access Controlsolidity
Improper Access Controlsolidity
Improper Access Controlsolidity
Improper Access Controlsolidity
Improper Access Controlsolidity
Improper Access Controlhcl
Improper Access Controlapex
Image user should not be 'rootterraform
If proxy kubeconfig file exists ensure permissions are set to 600 or more restrictiveterraform
if proxy kubeconfig file exists ensure ownership is set to root:rootterraform
IAM policy should avoid use of wildcards and instead apply the principle of least privilegeterraform
hostPath volume mounted with docker.sockterraform
GKE Control Plane should not be publicly accessibleterraform
GitHub repository has vulnerability alerts disabled.terraform
GitHub branch protection does not require signed commits.terraform
Generation of Weak Initialization Vector (IV)javascript
Generation of Predictable IV with CBC Modephp
Generation of Predictable IV with CBC Modejava
Function policies should avoid use of wildcards and instead apply the principle of least privilegeterraform
Function Call With Incorrect Variable or Reference as Argumentsolidity
External Control of File Name or Pathjavascript
Exposure of Sensitive Information to an Unauthorized Actorpython
Exposure of Sensitive Information to an Unauthorized Actorgeneric
Exposure of Sensitive Information to an Unauthorized Actorgeneric
Exposure of Sensitive Information to an Unauthorized Actoryaml
Exposure of Sensitive Information to an Unauthorized Actoryaml
Exposure of Resource to Wrong Spherepython
Exposure of Information Through Directory Listingjavascript
Execution with Unnecessary Privilegesjson
Execution with Unnecessary Privilegesyaml
Exec into Podsterraform
Ensure that the scheduler pod specification file permissions are set to 600 or more restrictiveterraform
Ensure that the scheduler pod specification file ownership is set to root:rootterraform
Ensure that the scheduler config file permissions are set to 600 or more restrictiveterraform
Ensure that the scheduler config file ownership is set to root:rootterraform
Ensure that the Kubernetes PKI certificate file permission is set to 600terraform
Ensure that the kubelet service file permissions are set to 600 or more restrictiveterraform
Ensure that the etcd pod specification file permissions are set to 600 or more restrictiveterraform
Ensure that the etcd pod specification file ownership is set to root:rootterraform
Ensure that the controller-manager config file permissions are set to 600 or more restrictiveterraform
Ensure that the controller-manager config file ownership is set to root:rootterraform
Ensure that the controller manager pod specification file ownership is set to root:rootterraform
Ensure that the container network interface file permissions are set to 600 or more restrictiveterraform
Ensure that the container network interface file ownership is set to root:rootterraform
Ensure that the API server pod specification file permissions are set to 600 or more restrictiveterraform
Ensure that the API server pod specification file ownership is set to root:rootterraform
Ensure that the --streaming-connection-idle-timeout argument is not set to 0terraform
Ensure that the --rotate-certificates argument is not set to falseterraform
Ensure that the --protect-kernel-defaults is set to trueterraform
Ensure that the --make-iptables-util-chains argument is set to trueterraform
Ensure that the --kubeconfig kubelet.conf file permissions are set to 600 or more restrictiveterraform
Ensure that the --kubeconfig kubelet.conf file ownership is set to root:rootterraform
Ensure that the --hostname-override argument is not setterraform
Ensure that the --event-qps argument is set to 0 or a level which ensures appropriate event captureterraform
Ensure that the --authorization-mode argument is not set to AlwaysAllowterraform
Ensure that Cloud Storage bucket is not anonymously or publicly accessible.terraform
Ensure that Cloud SQL Database Instances are not publicly exposedterraform
Ensure RBAC is enabled on AKS clustersterraform
Ensure plaintext value is not used for GitHub Action Environment Secret.terraform
Ensure MQ Broker is not publicly exposedterraform
Ensure Kubelet Config.Yaml Permissions 600 Or More Restrictive.terraform
Ensure Kubeconfig Kubelet Config.Yaml Ownership Set Root:Rootterraform
Ensure database firewalls do not permit public accessterraform
Ensure Controller Manager Pod Specification File Permissions Set 600 Or More Restrictiveterraform
Ensure all data stored in the launch configuration EBS is securely encryptedterraform
Ensure AKS cluster has Network Policy configuredterraform
Enable local-disk encryption for EMR clusters.terraform
Enable in-transit encryption for EMR clusters.terraform
Enable disk encryption on managed diskterraform
Enable at-rest encryption for EMR clusters.terraform
Enable At Rest Encryptionterraform
Elasticsearch domain uses plaintext traffic for node to node communication.terraform
Elasticsearch domain isn't encrypted at rest.terraform
Elasticsearch domain endpoint is using outdated TLS policy.terraform
Elasticache Replication Group uses unencrypted traffic.terraform
Elasticache Replication Group stores unencrypted data at-rest.terraform
EKS should have the encryption of secrets enabledterraform
EFS Encryption has not been enabledterraform
ECS Task Definitions with EFS volumes should use in-transit encryptionterraform
ECR repository policy must block public accessterraform
ECR repository has image scans disabled.terraform
ECR images tags shouldn't be mutable.terraform
EBS volumes must be encryptedterraform
DocumentDB storage must be encryptedterraform
Do not allow role to create ClusterRoleBindings and association with privileged roleterraform
Do not allow role binding creation and association with privileged role/clusterroleterraform
Do not allow privilege escalation from node proxyterraform
Do not allow attaching to shell on podsterraform
dnf clean all' missingterraform
Disable local_infile setting in MySQLterraform
Deserialization of Untrusted Dataruby
Deserialization of Untrusted Dataruby
Deserialization of Untrusted Datacsharp
Deprecated MAINTAINER usedterraform
Default security context configuredterraform
Default network should not be created at project levelterraform
DAX Cluster should always encrypt data at restterraform
Cryptographic Issuesjavascript
Cross-Site Request Forgery (CSRF)generic
Cross-Site Request Forgery (CSRF)apex
ConfigMap with secretsterraform
Config configuration aggregator should be using all regions for sourceterraform
CodeBuild Project artifacts encryption should not be disabledterraform
CloudTrail should use Customer managed keys to encrypt the logsterraform
Cloudtrail log validation should be enabled to prevent tampering of log dataterraform
CloudFront distribution uses outdated SSL/TLS protocols.terraform
CloudFront distribution does not have a WAF in front.terraform
Cleartext Transmission of Sensitive Informationjava
Cleartext Transmission of Sensitive Informationjava
Cleartext Transmission of Sensitive Informationjava
Cleartext Transmission of Sensitive Informationgo
Cleartext Transmission of Sensitive Informationgo
Cleartext Transmission of Sensitive Informationgo
aws_instance should activate session tokens for Instance Metadata Service.terraform
aws_instance should activate session tokens for Instance Metadata Service.terraform
AWS SQS policy document has wildcard action statement.terraform
AWS best practice to not use the default VPC for workflowsterraform
Authorization Bypass Through User-Controlled Keyruby
Athena workgroups should enforce configuration to prevent client disabling encryptionterraform
apt-get' missing '-y' to avoid manual inputterraform
apt-get' missing '--no-install-recommendsterraform
apt-get dist-upgrade' usedterraform
apk add' is missing '--no-cacheterraform
API Gateway domain name uses outdated SSL/TLS protocols.terraform
Active Debug Codepython
Access to host portsterraform
Access to host PIDterraform
Access to host networkterraform
Access to host IPC namespaceterraform
A MSK cluster allows unencrypted data in transit.terraform
A MSK cluster allows unencrypted data at rest.terraform
A configuration for an external workload identity pool provider should have conditions setterraform