πŸ›‘οΈ Security Knowledge Base

Cybersecurity FAQ
and Vulnerability Guide

A professional reference covering 13 vulnerability categories across Web, Cloud, Microsoft 365, Email, Infrastructure and more. Based on frameworks used by penetration testers and cloud security engineers.

13
Vulnerability Categories
100+
Common Vulnerabilities
14
Security Frameworks
6
Security Domains
πŸ”
🌐
Web App
10 categories Β· OWASP Top 10
☁️
Cloud Platform
6 categories Β· Azure AWS GCP
πŸͺŸ
Microsoft 365
7 categories Β· M365 Security
πŸ“§
Email Security
SPF DKIM DMARC BEC
🌍
DNS & Network
Subdomain takeover TLS
πŸ“‹
Frameworks
OWASP NIST MITRE CIS
❓
Is Any Environment Completely Secure?
The most common question in cybersecurity
FAQ #1
No environment is completely free of vulnerabilities. The vulnerabilities differ depending on whether you are assessing a web application, cloud infrastructure, SaaS platform (such as Microsoft 365 or Google Workspace), identity systems, or APIs.

Below is a professional classification similar to what is used by penetration testers, cloud security engineers, and security architects worldwide. Scan365.ai automates the detection of many of these vulnerabilities for your organisation.
🌐
Scan365 Free
Scans Web App and Email Security vulnerabilities automatically
☁️
Scan365 Pro
Adds Microsoft 365, ACSC Essential Eight, Cloud and Infrastructure scanning
πŸš€
Coming Soon
Google Workspace, AWS, GCP, Mobile App, and Container scanning
1
🌐
Web Application Vulnerabilities
OWASP Top 10 + Common Issues Β· Scanned automatically in Free plan
FREE SCAN
Scan365.ai automatically detects many of these vulnerabilities during your Website and Domain scan. Results include SSL, headers, outdated software, and configuration issues.
πŸ’‰Injection9β–Ό
  • SQL Injection (SQLi)Free
  • NoSQL Injection
  • LDAP Injection
  • XPath Injection
  • OS Command Injection
  • Server-Side Template Injection (SSTI)
  • XML Injection
  • CRLF Injection
  • Email Header Injection
πŸ“Cross-Site Scripting (XSS)4β–Ό
  • Stored XSSFree
  • Reflected XSS
  • DOM-based XSS
  • Mutation XSS
πŸ”Authentication8β–Ό
  • Weak passwordsFree
  • Credential stuffing
  • Password spraying
  • Brute-force attacks
  • Session fixation
  • Session hijacking
  • Broken MFA implementation
  • Weak password reset processFree
🚫Authorization6β–Ό
  • Broken Access Control
  • IDOR (Insecure Direct Object References)
  • Privilege escalation
  • Horizontal privilege escalation
  • Vertical privilege escalation
  • Forced browsing
πŸͺSession Management6β–Ό
  • Predictable session IDs
  • Session timeout issues
  • Missing Secure cookieFree
  • Missing HttpOnly
  • Missing SameSite
  • Token leakage
πŸ”’Cryptography7β–Ό
  • Weak encryption
  • Hardcoded secrets
  • Weak TLSFree
  • Deprecated SSLFree
  • Missing HSTSFree
  • Poor key management
  • Weak hashing (MD5, SHA-1)
πŸ“ŽFile Upload5β–Ό
  • Arbitrary file upload
  • Malicious image upload
  • Double extension upload
  • ZIP Slip
  • Path traversal via uploads
πŸ”ŒAPI Security7β–Ό
  • Broken Object Level Authorization (BOLA)
  • Broken Function Level Authorization
  • Excessive Data Exposure
  • Mass Assignment
  • Rate limiting bypassFree
  • API key exposure
  • JWT vulnerabilities
βš™οΈServer-Side7β–Ό
  • SSRF
  • XXE
  • Deserialization
  • Buffer Overflow
  • Race Conditions
  • HTTP Request Smuggling
  • HTTP Response Splitting
πŸ’ΌBusiness Logic5β–Ό
  • Coupon abuse
  • Price manipulation
  • Workflow bypass
  • Account takeover
  • Payment bypass
2
☁️
Cloud Platform Vulnerabilities
Azure Β· AWS Β· Google Cloud Β· Oracle Cloud Β· Alibaba Cloud
PRO SCAN
Applicable to Azure, AWS, Google Cloud Platform, Oracle Cloud, and Alibaba Cloud. Scan365 Pro scans your Microsoft Azure configuration for these vulnerabilities.
πŸ‘€Identity6β–Ό
  • Excessive IAM permissionsPro
  • Privilege escalation
  • Inactive accountsPro
  • Shared administrator accounts
  • Missing MFAPro
  • Stale credentials
πŸ’ΎStorage5β–Ό
  • Public storage bucketsPro
  • Public blobs
  • Exposed snapshots
  • Unencrypted storage
  • Backup exposure
🌐Network7β–Ό
  • Open security groups
  • Open firewall rules
  • Exposed RDP (3389)
  • Exposed SSH (22)
  • Open databases
  • Misconfigured VPN
  • DNS exposure
⚑Compute5β–Ό
  • Unpatched virtual machinesPro
  • Container escape
  • Weak Kubernetes RBAC
  • Docker daemon exposure
  • Insecure images
πŸ”‘Secrets5β–Ό
  • Secrets in GitHub
  • Secrets in source code
  • Exposed API keys
  • Exposed service principals
  • Hardcoded passwords
πŸ‘οΈMonitoring5β–Ό
  • Missing loggingPro
  • Disabled audit logsPro
  • Disabled Defender
  • No SIEM integration
  • Missing alerting
3
πŸͺŸ
Microsoft 365 Security Vulnerabilities
Identity Β· Exchange Β· SharePoint Β· Teams Β· Entra ID Β· Defender
PRO SCAN
Scan365 Pro performs a Microsoft 365 and Cloud audit checking these common attack vectors including identity, collaboration tools, and Defender configuration.
πŸ‘€Identity8β–Ό
  • No MFAPro
  • Weak Conditional AccessPro
  • Legacy Authentication enabledPro
  • Password Hash Sync attacks
  • Pass-the-Cookie
  • OAuth abuse
  • Token theft
  • Guest account abusePro
πŸ“¬Exchange Online5β–Ό
  • Mailbox forwardingPro
  • Malicious inbox rules
  • Auto-forwarding to external usersPro
  • SMTP relay abuse
  • Shared mailbox abuse
πŸ“SharePoint Online5β–Ό
  • Anonymous sharingPro
  • Public links
  • Oversharing
  • External sharingPro
  • Sensitive document exposure
πŸ’¬Microsoft Teams4β–Ό
  • Guest abuse
  • Phishing
  • External federation abuse
  • Malicious apps
πŸ†”Entra ID (Azure AD)6β–Ό
  • Weak Conditional AccessPro
  • Insecure app registrations
  • Service Principal abuse
  • PIM not enabledPro
  • Excessive Global AdministratorsPro
  • Consent phishing
πŸ›‘οΈMicrosoft Defender4β–Ό
  • Safe Links disabledPro
  • Safe Attachments disabledPro
  • Anti-phishing disabled
  • Missing Attack Simulation Training
4
πŸ”΅
Google Workspace Vulnerabilities
Gmail Β· Drive Β· Cloud Identity Β· Google APIs
COMING SOON
Google Workspace scanning is on the Scan365 roadmap. Currently you can manually review these vulnerabilities against your Google Workspace environment.
πŸ‘€Identity5β–Ό
  • No MFASoon
  • Weak password policy
  • Third-party OAuth abuse
  • Inactive users
  • Admin privilege abuse
πŸ“§Gmail6β–Ό
  • Email spoofingFree
  • SPF misconfigurationFree
  • DKIM missingFree
  • DMARC missingFree
  • Malicious forwarding rules
  • Phishing
πŸ“Google Drive5β–Ό
  • Public sharing
  • External sharing
  • Sensitive files
  • Link sharing
  • Data leakage
πŸ”ŒGoogle APIs3β–Ό
  • Exposed API Keys
  • Service Account misuse
  • OAuth abuse
5
πŸ”·
Azure-Specific Vulnerabilities
Storage Β· RBAC Β· Key Vault Β· AKS Β· Logic Apps Β· Conditional Access
PRO SCAN
πŸ”·Azure Vulnerabilities15β–Ό
  • Public Blob StoragePro
  • Overprivileged RBACPro
  • Azure Key Vault misconfiguration
  • Managed Identity abuse
  • Azure Automation abuse
  • VM Managed Identity abuse
  • Open NSGsPro
  • Open Load Balancers
  • Azure Functions exposure
  • Logic App exposure
  • Weak Conditional AccessPro
  • PIM not enabledPro
  • Azure Arc misconfiguration
  • AKS misconfiguration
  • Storage Account SAS token exposure
6
🟠
AWS & Google Cloud Vulnerabilities
S3 Β· IAM Β· Lambda Β· EC2 Β· Cloud Storage Β· Service Accounts
COMING SOON
🟠AWS Vulnerabilities10β–Ό
  • Public S3 bucketsSoon
  • IAM privilege escalation
  • Lambda privilege escalation
  • EC2 metadata attacks
  • EKS misconfiguration
  • Security Group exposure
  • Open RDS
  • Open Redis
  • CloudTrail disabled
  • Secrets Manager misconfiguration
πŸ”΄Google Cloud Vulnerabilities8β–Ό
  • Public Cloud Storage bucketsSoon
  • Excessive IAM permissions
  • Cloud Run exposure
  • Kubernetes RBAC issues
  • Service Account abuse
  • Metadata Server abuse
  • Open Firewall Rules
  • Secret Manager exposure
8
πŸ“¦
Container and Kubernetes Vulnerabilities
Docker Β· Kubernetes Β· AKS Β· EKS Β· GKE
PRO SCAN
πŸ“¦Container and K8s Issues11β–Ό
  • Container escape
  • Privileged containersPro
  • Host networking
  • Root containers
  • Insecure imagesPro
  • Secrets in images
  • Kubernetes Dashboard exposure
  • etcd exposure
  • Weak RBACPro
  • Admission controller disabled
  • Pod Security Standards not enforced
9
🌍
DNS and Network Vulnerabilities
Takeover Β· TLS Β· Certificates Β· Zone Transfer
FREE SCAN
Scan365 Free plan automatically checks your domain for DNS takeover risk, TLS configuration, HSTS and certificate issues.
🌍DNS and Network Issues9β–Ό
  • DNS takeoverFree
  • Subdomain takeoverFree
  • Open DNS resolver
  • Zone transfer
  • DNS cache poisoning
  • Weak TLS configurationFree
  • Missing HSTSFree
  • Weak ciphersFree
  • Certificate issuesFree
10
πŸ“§
Email Security Vulnerabilities
SPF Β· DKIM Β· DMARC Β· BEC Β· Phishing
FREE SCAN
Scan365 Phishing Risk Score module (Free plan) checks all email authentication records including SPF, DKIM, DMARC and identifies email spoofing vulnerabilities.
πŸ“§Email Security Issues8β–Ό
  • SPF missingFree
  • DKIM missingFree
  • DMARC missingFree
  • Open relay
  • Email spoofingFree
  • Business Email Compromise (BEC)
  • Mailbox forwarding abuse
  • QR-code phishing (Quishing)
11
πŸ“±
Mobile Application Vulnerabilities
iOS Β· Android Β· OWASP Mobile Top 10
COMING SOON
πŸ“±Mobile App Issues8β–Ό
  • Insecure storageSoon
  • Root detection bypass
  • Certificate pinning bypass
  • Weak encryption
  • API exposure
  • Hardcoded credentials
  • Reverse engineering
  • Insecure local database
12
πŸ–₯️
Infrastructure Vulnerabilities
Patching Β· RDP Β· SSH Β· SMB Β· Default credentials
PRO SCAN
πŸ–₯️Infrastructure Issues10β–Ό
  • Missing security patchesPro
  • Unsupported operating systemsPro
  • Weak administrator passwords
  • SMB vulnerabilities
  • RDP exposurePro
  • SSH misconfiguration
  • Default credentials
  • SNMP exposure
  • FTP/Telnet enabled
  • NFS exposure
13
πŸ“‹
Common Vulnerability Frameworks
OWASP Β· MITRE Β· NIST Β· CIS Β· Microsoft Β· AWS Β· Google
REFERENCE
Security professionals assess against these globally recognised frameworks. Scan365 Pro reports reference OWASP, ACSC Essential Eight, NIST and CIS benchmarks in every scan.
🌐
OWASP Top 10
Web Application security risks
πŸ”Œ
OWASP API Security Top 10
API-specific vulnerabilities
πŸ“±
OWASP Mobile Top 10
Mobile application risks
βš”οΈ
MITRE ATT&CK
Adversary tactics and techniques
πŸ—ΊοΈ
MITRE CAPEC
Common attack pattern enumeration
πŸ“
MITRE CWE
Common weakness enumeration
πŸ”
CVE
Common Vulnerabilities and Exposures
πŸ“
CIS Benchmarks
Security configuration standards
πŸ›οΈ
NIST CSF
Cybersecurity Framework
πŸ“–
NIST SP 800-53
Security and privacy controls
🚨
NIST SP 800-61
Incident Response
🟦
Microsoft Security Benchmark
Azure security baseline
🟠
AWS Well-Architected
Security Pillar framework
πŸ”΄
Google Cloud Security
Security Foundations framework
🎯
Six Security Domain Methodology
Enterprise security assessment framework for Microsoft Azure, M365, AWS and Google Cloud
For organisations with Microsoft infrastructure, Azure, Microsoft 365 and cloud engineering, a practical approach is to organise assessments into six security domains. Scan365.ai maps its scan results to these domains.
DomainExamplesScan365 Coverage
πŸ”Identity and AccessMFA, Conditional Access, RBAC, Privileged Identity Management, OAuth, service accountsPro
🌐NetworkFirewalls, NSGs, VPNs, WAFs, segmentation, DDoS protectionsFree Pro
πŸ”’Data ProtectionEncryption, Key Vault, DLP, information protection, backup securityPro
⚑Compute and ApplicationsVirtual machines, containers, Kubernetes, serverless functions, web applications, APIsFree Pro
πŸ‘οΈMonitoring and DetectionSIEM, audit logging, Microsoft Defender, Google Security Center, CloudTrail, alertingPro
πŸ“‹Governance and ComplianceCIS Benchmarks, NIST, ISO 27001, policy enforcement, vulnerability managementPro

Ready to Scan Your Organisation?

Scan365.ai automatically checks your website and Microsoft 365 environment against these vulnerabilities in 60 seconds. No technical knowledge required.

βœ“ No credit card required βœ“ Results in 60 seconds βœ“ Free PDF report βœ“ ITSL backed