BETA O Shoulder está em beta — Os resultados às vezes podem estar incorretos. Seu feedback molda o que corrigimos a seguir. Compartilhar feedback
🟨
JavaScript Security
116 regras
67 CWEs 23 critical

Vulnerabilidades de Segurança JavaScript

Shoulder detecta 116 padrões de segurança específicos para aplicações JavaScript construídas com JavaScript.

Cobertura de Frameworks

Categorias de Vulnerabilidade

CWE-20 7 regras
Improper Input Validation
CWE-200 5 regras
Exposure of Sensitive Information to an Unauthorized Actor
2 critical
CWE-798 5 regras
Use of Hard-coded Credentials
2 critical
CWE-89 4 regras
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
4 critical
CWE-79 3 regras
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
1 critical
CWE-285 3 regras
Improper Authorization
3 critical
CWE-639 3 regras
Authorization Bypass Through User-Controlled Key
1 critical
CWE-22 2 regras
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
1 critical
CWE-94 2 regras
Improper Control of Generation of Code ('Code Injection')
1 critical
CWE-117 2 regras
Improper Output Neutralization for Logs
CWE-209 2 regras
Generation of Error Message Containing Sensitive Information
CWE-327 2 regras
Use of a Broken or Risky Cryptographic Algorithm
CWE-400 2 regras
Uncontrolled Resource Consumption
CWE-502 2 regras
Deserialization of Untrusted Data
1 critical
CWE-601 2 regras
URL Redirection to Untrusted Site ('Open Redirect')
CWE-770 2 regras
Allocation of Resources Without Limits or Throttling
CWE-915 2 regras
Improperly Controlled Modification of Dynamically-Determined Object Attributes
2 critical
CWE-918 2 regras
Server-Side Request Forgery (SSRF)
CWE-1104 2 regras
Use of Unmaintained Third Party Components
CWE-1321 2 regras
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
🟨

Escaneie seu projeto JavaScript

Execute o CLI Shoulder para encontrar vulnerabilidades específicas de JavaScript.