Nessus 的 CGI abuses 系列

ID名称严重性
153807SonicWall Secure Mobile Access 任意文件删除 (SNWLID-2021-0021)
critical
153636ManageEngine Log360 < Build 5229 REST API 限制绕过 RCE
critical
153635ManageEngine Log360 检测
info
153612Nagios XI < 5.8.5 多个漏洞
critical
153490Liferay Portal 7.3.5 存储型 XSS
medium
153402Drupal 8.9.x < 8.9.19 / 9.1.x < 9.1.13 / 9.2.x < 9.2.6 多个漏洞 (drupal-2021-09-15)
critical
153176Citrix ADM 身份验证绕过 (CTX247738)
critical
153175Citrix ADM 身份验证绕过 (CTX261735)
high
153173WordPress 5.8 < 5.8.1 / 5.7 < 5.7.3 / 5.6 < 5.6.5 / 5.5 < 5.5.6 / 5.4 < 5.4.7 / 5.2 < 5.2.12
high
153158ManageEngine ADManager Plus 检测
info
153157ManageEngine ADManager Plus < 7111 RCE
critical
153147ManageEngine ADSelfService Plus < 版本 6114 REST API 认证绕过
critical
153087Atlassian Confluence Server Webwork OGNL 注入 (CVE-2021-26084)
critical
152984Joomla 4.0 < 4.0.1 访问控制不充分 (5846-joomla-4-0-1)
critical
152865Atlassian JIRA < 8.5.14 / 8.6.x < 8.13.6 / 8.14.x < 8.16.1 XSS (JRASERVER-72392)
medium
152864Atlassian Confluence < 6.13.23 / 6.14 < 7.4.11 / 7.5 < 7.11.6 / 7.12 < 7.12.5 Webwork OGNL 注入 (CONFSERVER-67940)
critical
152853PHP < 7.3.28 电子邮件标头注入
medium
152680ManageEngine ADSelfService Plus 6102 之前版本 RCE
critical
152534VMware Workspace One Access / VMware Identity Manager 多个漏洞 (VMSA-2021-0016)
critical
152533Drupal 8.9.x < 8.9.18 / 9.1.x < 9.1.12 / 9.2.x < 9.2.4 多个漏洞 (SA-CORE-2021-005)
medium
152487Adobe Connect <= 11.2.2 多个漏洞 (APSB21-66)
medium
152140Open Access Management 检测
info
152139OpenAM RCE (CVE-2021-35464)
critical
152137Atlassian Jira Data Center/Jira Service Management Data Center 缺失认证 (2021-07-21)
critical
151974Oracle Primavera Gateway(2021 年 7 月 CPU)
critical
151973Oracle Primavera Unifier(2021 年 7 月 CPU)
high
151932Drupal 7.x < 7.82 / 8.9.x < 8.9.17 / 9.1.x < 9.1.11 / 9.2.x < 9.2.2 Drupal 漏洞 (SA-CORE-2021-004)
high
151892Oracle Primavera P6 Enterprise Project Portfolio Management(2021 年 7 月 CPU)
medium
151620Liferay Portal 7.3.5 SQLi
high
151577Liferay Portal 7.3.4 < 7.3.6 XSS
medium
151576Liferay Portal 7.3.x < 7.3.6 信息泄露
medium
151575Liferay Portal 7.2.x < 7.3.6 XSS
medium
151489OpenTSDB yrange RCE(直接检查)
critical
151429Joomla 2.5.x < 3.9.28 多个漏洞 (5840-joomla-3-9-28)
high
151292Liferay Portal 7.x <= 7.2.1 / 7.3 < 7.3.6 多个漏洞
medium
151291ForgeRock Access Management 7.0 之前版本 RCE
critical
151288ForgeRock Access Management 检测
info
151286ManageEngine ServiceDesk Plus 11.2 11205 之前版本 RCE
high
151193Jenkins LTS < 2.289.2 / Jenkins weekly < 2.300 多个漏洞
high
151189Easy WP SMTP Plugin for WordPress 1.4.4 之前版本敏感信息泄露
high
151025WordPress“SRS Simple Hits Counter”插件信息泄露(直接检查)
high
151011Liferay Portal 不安全的反序列化 (CST-7213)
high
150866Citrix ADC 和 Citrix NetScaler Gateway 多个漏洞 (CTX297155)
medium
150865Citrix SD-WAN Center 测试版本网络 DoS (CTX297155)
medium
150720SonicWall Secure Remote Access (SRA) 认证前 SQLi 漏洞 (CVE-2019-7481)
high
150715SonicWall Secure Remote Access (SRA) 不受支持的版本
critical
150440Adobe Connect <11.2.2 权限升级 (APSB21-36)
medium
150245HPE Edgeline Infrastructure Manager 身份验证绕过 (HPESBGN04124)
critical
150057Nagios XI < 5.8 权限提升
critical
150056Nagios XI < 5.7 代码注入
high