Critical

Showing all detectors for the Java language with critical severity.

HTTP response splitting

Passing data from an untrusted source into a cookie or web response might expose the user to HTTP response splitting attacks.

Hardcoded credentials

Hardcoded credentials can be intercepted by malicious actors.

Unsanitized input is run as code

Scripts generated from unsanitized inputs can lead to malicious behavior and inadvertently running code remotely.

Session fixation

Session fixation might allow an attacker to steal authenticated session IDs.

Insecure cryptography

Weak, broken, or misconfigured cryptography can lead to security vulnerabilities.