Skip to main content

Pentrova is launching soon. Join the waitlist for early access.Join the waitlist

Resources

Vulnerability database

Pentrova organises the web, API, and infrastructure flaws we detect into five taxonomic classes: Injection, Access Control, Cryptography, Infrastructure, and Application Security. The classes are deliberately broader than CWE so one class can map cleanly to the coverage that hunts it, and narrower than OWASP Top 10 so each entry points at a concrete detection and exploitation technique.

Every entry below describes the class, the signal our agents look for, and the shape of the deterministic proof the platform ships when a finding is confirmed. Specific catalog sizes and coverage inventories are available to evaluators under NDA via the product console and Trust Center.

The database is curated, not exhaustive. A full CWE cross-walk lives inside the product where it can stay accurate as the catalog changes. The entries here are the ones we expect a security engineer to recognise at a glance while evaluating Pentrova on a first read.

Every detection ends at the same artifact: a replayable PoC bundle that an engineer, an auditor, or an incident responder can verify without calling us. That discipline is what makes the taxonomy useful — each class is a bet on producing deterministic evidence, not probabilistic severity.

See also

Browse every security term

Full definitions for SSRF, XSS, JWT bypass, OAuth 2.0, mTLS, and the rest of the vocabulary used on this page.

Open the glossary →

Injection

Unsafe composition of attacker-controlled input into commands, queries, templates, or markup.

Access Control

Missing or inconsistent authorisation checks that let one principal act on another principal’s resources.

Cryptography

Cryptographic primitives used incorrectly: weak algorithms, predictable randomness, or misconfigured TLS.

Infrastructure

Server-side requests, file reads, and remote code execution exposed through infrastructure primitives.

Application Security

Business-logic and application-layer flaws that are specific to how the service composes its own features.

See the catalog inside the product

Every class above is backed by dedicated coverage. Book a demo and we will walk the catalog end-to-end against a target of your choice.

Site search

↑↓ navigateEnter openEsc close