Nessus 的 Web Servers 系列

ID名称严重性
298967SAP NetWeaver AS ABAP 缺少授权检查 (3674774)
critical
298966SAP NetWeaver AS ABAP XML 签名封装 (3697567)
high
298965SAP NetWeaver AS Java CRLF 注入 (3673213)
low
298964SAP NetWeaver AS ABAP 和 S/4HANA 缺少授权检查 (3672622)
medium
298596IBM WebSphere Application Server 8.5.x < 8.5.5.30 / 9.x < 9.0.5.27 (7260217)
medium
297279IBM WebSphere Application Server Liberty 17.0.0.3 < 26.0.0.2 RCE (7258224)
high
297229Oracle APEX 示例应用程序 (Brookstrut) (CVE-2026-21931)
medium
297228Oracle Application Express (Apex) Web 检测
info
297198Grafana Labs 3.0.0 < 11.6.9+security-01 / 12.0.0 < 12.0.8+security-01 / 12.1.0 < 12.1.5+security-01 / 12.2.0 < 12.2.3+security-01 / 12.3.0 < 12.3.1+security-01 DoS (CVE-2026-21720)
high
297197Grafana Labs 10.2.0 < 11.6.9+security-01 / 12.0.0 < 12.0.8+security-01 / 12.1.0 < 12.1.5+security-01 / 12.2.0 < 12.2.3+security-01 / 12.3.0 < 12.3.1+security- 01 权限升级CVE-2026-21721
high
296784OpenSSL 3.3.0 < 3.3.6 多种漏洞
high
296770OpenSSL 3.6.0 < 3.6.1 多个漏洞
high
296769OpenSSL 1.1.1 < 1.1.1ze 多个漏洞
high
296768OpenSSL 3.5.0 < 3.5.5 多个漏洞
high
296767OpenSSL 1.0.2 < 1.0.2zn 多个漏洞
high
296766OpenSSL 3.4.0 < 3.4.4 多个漏洞
high
296765OpenSSL 3.0.0 < 3.0.19 多个漏洞
high
296604Oracle HTTP Server2026 年 1 月 CPU
medium
296603Oracle HTTP Server2026 年 1 月 CPU
medium
288282SAP NetWeaver 命令注入2026 年 1 月
high
288281SAP NetWeaver AS ABAP 缺少授权检查 (3688703)
high
288280SAP NetWeaver AS Java 敏感信息漏洞2026 年 1 月
low
281759Nginx 站点枚举
info
281618IBM WebSphere eXtreme Scale 8.6.1.0 < 8.6.1.6 (7256003)
high
278309SAP NetWeaver AS Java DoS2025 年 12 月
high
278308SAP NetWeaver AS 缺少身份验证2025 年 12 月
medium
277790IBM WebSphere Application Server 8.5.x < 8.5.5.29 / 9.x < 9.0.5.27 / Liberty 17.0.0.3 < 26.0.0.1 XSS (7254078)
medium
276746Grafana Enterprise SCIM 配置权限提升(CVE-2025-41115)
critical
275454SAP NetWeaver AS ABAP 缺少授权检查 (3643337)
medium
275453SAP NetWeaver AS Java 信息泄露 (3643603)
medium
275445Omnissa Workspace ONE UEM 24.2.x < 24.2.0.36 / 24.6.x < 24.6.0.44 / 24.10.x < 24.10.0.25 (OMSA-2025-0005)
medium
274087IBM WebSphere Application Server 8.5.x < 8.5.5.29 / 9.x < 9.0.5.27 / Liberty 17.0.0.3 < 25.0.0.12 (7250200)
medium
272099IBM WebSphere eXtreme Scale 8.6.1.0 < 8.6.1.6 (7249244)
medium
272043Arcgis Server HTTP 检测
info
271806Apache Tomcat 9.0.40 < 9.0.109 多个漏洞
high
271696Apache Tomcat 11.0.0.M1 < 11.0.12
high
271695Apache Tomcat 10.1.0.M1 < 10.1.47
high
271694Apache Tomcat 9.0.0.M1 < 9.0.110
high
271693Apache Tomcat 11.0.0.M1 < 11.0.11 多个漏洞
high
271692Apache Tomcat 10.1.0.M1 < 10.1.45 多个漏洞
high
271691Apache Tomcat 9.0.0、M11 < 9.0.109 多个漏洞
high
270697SAP NetWeaver AS ABAP 多个漏洞2025 年 10 月
medium
270696SAP NetWeaver AS Java 不安全反序列化2025 年 10 月
critical
270347IBM WebSphere eXtreme Scale 8.6.1.0 < 8.6.1.6 (7247893)
high
266319OpenSSL 3.2.0 < 3.2.6 多个漏洞
medium
266318OpenSSL 1.0.2 < 1.0.2zm 漏洞
high
266298OpenSSL 3.5.0 < 3.5.4 多个漏洞
medium
266297OpenSSL 3.0.0 < 3.0.18 多种漏洞
high
266295OpenSSL 3.4.0 < 3.4.3 多个漏洞
medium
266294OpenSSL 1.1.1 < 1.1.1zd 漏洞
high