Nessus 的 CGI abuses 系列

ID名称严重性
301998EcoStruxure IT Data Center Expert <= 9.0 硬编码凭据的使用 (SEVD-2026-069-05)
high
301912GitLab 8.14 < 18.7.6 / 18.8 < 18.8.6 / 18.9 < 18.9.2 (CVE-2026-1182)
medium
301879GitLab 14.4 < 18.7.6 / 18.8 < 18.8.6 / 18.9 < 18.9.2 (CVE-2026-1663)
medium
301878GitLab 10.6 < 18.7.6 / 18.8 < 18.8.6 / 18.9 < 18.9.2 (CVE-2026-1090)
medium
301877GitLab 8.11 < 18.7.6 / 18.8 < 18.8.6 / 18.9 < 18.9.2 (CVE-2026-3848)
medium
301876GitLab 12.6 < 18.7.6 / 18.8 < 18.8.6 / 18.9 < 18.9.2 (CVE-2026-1732)
medium
301874Splunk Enterprise 9.3.0 < 9.3.10、9.4.0 < 9.4.9、10.0.0 < 10.0.4 (SVD-2026-0302)
high
301873Splunk Enterprise 9.3.0 < 9.3.10、9.4.0 < 9.4.9、10.0.0 < 10.0.3 (SVD-2026-0303)
medium
301872Splunk Enterprise 9.3.0 < 9.3.10、9.4.0 < 9.4.9、10.0.0 < 10.0.4、10.2.0 < 10.2.1 (SVD-2026-0304)
medium
301871Splunk Enterprise 10.0.0 < 10.0.4、10.2.0 < 10.2.1 (SVD-2026-0305)
medium
301864Splunk Enterprise 9.3.0 < 9.3.9、9.4.0 < 9.4.9、10.0.0 < 10.0.3 (SVD-2026-0301)
medium
301863GitLab 1.0 < 18.7.6 / 18.8 < 18.8.6 / 18.9 < 18.9.2 (CVE-2026-1230)
medium
301862GitLab 18.9 < 18.9.2 (CVE-2026-1069)
high
301861GitLab 15.6 < 18.7.6 / 18.8 < 18.8.6 / 18.9 < 18.9.2 (CVE-2026-0602)
medium
301859Zabbix 6.0.x < 6.0.41 / 7.0.x < 7.0.18 / 7.4.x < 7.4.2 未经授权的对象创建 (ZBX-27567)
medium
301728WordPress 6.0 < 6.9.2
high
300913Apache ActiveMQ < 5.19.2 / 6.0.x < 6.1.9 / 6.2.0 MQTT 控制数据包验证漏洞 (CVE-2025-66168)
high
300912Kibana 8.x < 8.19.12 / 9.2.x < 9.2.6 / 9.3.x < 9.3.1 (ESA_2026_13)
high
300426GitLab 14.4 < 18.7.5 / 18.8 < 18.8.5 / 18.9 < 18.9.1 (CVE-2026-1662)
high
300425GitLab 11.2 < 18.7.5 / 18.8 < 18.8.5 / 18.9 < 18.9.1 (CVE-2026-2845)
medium
300404GitLab 16.2 < 18.7.5 / 18.8 < 18.8.5 / 18.9 < 18.9.1 (CVE-2026-0752)
medium
300301GitLab 17.11 < 18.7.5 / 18.8 < 18.8.5 / 18.9 < 18.9.1 (CVE-2026-1747)
medium
300235VMWare Aria Operations 8.x < 8.18.6 多个漏洞 (VMSA-2026-0001)
critical
300170GitLab 18.9 < 18.9.1 (CVE-2026-1725)
high
300125GitLab 9.2 < 18.7.5 / 18.8 < 18.8.5 / 18.9 < 18.9.1 (CVE-2026-1388)
high
299881Metabase < 0.57.13 / 0.58.x < 0.58.7 / 1.x < 1.57.13 / 1.58.x < 1.58.7 信息泄露
medium
299759Atlassian Confluence 7.19.x < 9.2.13 / 9.3.1 < 10.2.2 (CONFSERVER-102184)
high
299692Atlassian Confluence 7.19.x < 9.2.7 / 9.3.1 < 9.5.3 / 10.0.2 / 10.1.0 / 10.2.0 (CONFSERVER-102193)
high
299675Aruba ClearPass Policy Manager 6.11.x < 6.11.13 / 6.12.x < 6.12.7 本地权限升级 (CVE-2026-23599)
high
299661Atlassian Confluence 9.0.0 < 9.2.14 / 9.2.15 / 9.3.1 < 10.2.3 / 10.2.6 (CONFSERVER-102186)
high
299660Atlassian Confluence 8.5.x < 9.2.1 / 9.3.x < 9.4.0 / 9.5.x < 9.5.1 / 10.0.x < 10.2.3 / 10.2.6 (CONFSERVER-102185)
high
299659Atlassian Confluence 7.19.x < 9.2.14 / 9.2.15 / 9.3.x < 10.2.3 / 10.2.6 (CONFSERVER-102132)
high
299658Atlassian Confluence 7.19.x < 8.5.10 / 8.6.x < 9.2.5 / 9.3.x < 9.3.1 / 9.4.x < 9.5.1 / 10.0.2 / 10.1.0 / 10.2.0 (CONFSERVER-101930)
high
299605Splunk Enterprise 9.3.0 < 9.3.9、9.4.0 < 9.4.8、10.0.0 < 10.0.3 (SVD-2026-0208)
high
299604Splunk Enterprise 9.2.0 < 9.2.12、9.3.0 < 9.3.9、9.4.0 < 9.4.8、10.0.0 < 10.0.3 (SVD-2026-0205)
high
299413Splunk Enterprise 9.2.0 < 9.2.9、9.3.0 < 9.3.7、9.4.0 < 9.4.5、10.0.0 < 10.0.3 (SVD-2026-0202)
medium
299412Splunk Enterprise 9.3.0 < 9.3.9、9.4.0 < 9.4.8、10.0.0 < 10.0.3 (SVD-2026-0206)
medium
299411Splunk Enterprise 9.2.0 < 9.2.12、9.3.0 < 9.3.9、9.4.0 < 9.4.8、10.0.0 < 10.0.2 (SVD-2026-0204)
medium
299408Splunk Enterprise 9.2.0 < 9.2.11、9.3.0 < 9.3.8、9.4.0 < 9.4.7、10.0.0 < 10.0.2 (SVD-2026-0209)
medium
299407Splunk Enterprise 9.2.0 < 9.2.11、9.3.0 < 9.3.9、9.4.0 < 9.4.7、10.0.0 < 10.0.2 (SVD-2026-0203)
medium
299406Jenkins LTS < 2.541.2 / Jenkins weekly < 2.551 多个漏洞
high
299405Splunk Enterprise 9.2.0 < 9.2.11、9.3.0 < 9.3.9、9.4.0 < 9.4.7、10.0.0 < 10.0.2 (SVD-2026-0207)
medium
299404Splunk Universal Forwarders 9.2.0 < 9.2.12、9.3.0 < 9.3.9、9.4.0 < 9.4.8、10.0.0 < 10.0.3 (SVD-2026-0210)
high
299400Arcgis < 11.3 多个漏洞 (2025 Update 1)
high
299396Nagios XI < 2026R1.0.1 多个漏洞
high
299395Mattermost Server 10.11.x <= 10.11.9 / 11.1.x <= 11.1.2 / 11.2.x <= 11.2.1 不当访问控制 (MMSA-2025-00550)
medium
299394Mattermost Server 10.11.x <= 10.11.9 / 11.0.x <= 11.2.x 访问控制不当 (MMSA-2025-00549)
low
299390SmarterMail < 100.0.9526 XSS (CVE-2026-26930)
high
299364WordPress 插件“LA Studio Element Kit for Elementor”< 1.6.0 通过后门程序造成未经身份验证的特权提升
critical
298972Neo4j < 5.26.21 信息泄露漏洞 (CVE-2026-1622)
medium