Nessus 的 Web Servers 系列

ID名称严重性
299410Apache Tomcat 10.1.0.M7 < 10.1.52
high
299403Apache Tomcat 11.0.0.M1 < 11.0.15 多个漏洞
critical
299402Apache Tomcat 9.0.83 < 9.0.115
high
299401Apache Tomcat 10.1.0.M1 < 10.1.50 多个漏洞
critical
299398Apache Tomcat 11.0.0.M1 < 11.0.18
high
299397Apache Tomcat 9.0.0.M1 < 9.0.113 多个漏洞
critical
298967SAP NetWeaver AS ABAP 缺少授权检查 (3674774)
critical
298966SAP NetWeaver AS ABAP XML 签名封装 (3697567)
high
298965SAP NetWeaver AS Java CRLF 注入 (3673213)
low
298964SAP NetWeaver AS ABAP 和 S/4HANA 缺少授权检查 (3672622)
medium
298596IBM WebSphere Application Server 8.5.x < 8.5.5.30 / 9.x < 9.0.5.27 (7260217)
medium
297279IBM WebSphere Application Server Liberty 17.0.0.3 < 26.0.0.2 RCE (7258224)
high
297229Oracle APEX 示例应用程序 (Brookstrut) (CVE-2026-21931)
medium
297228Oracle Application Express (Apex) Web 检测
info
297198Grafana Labs 3.0.0 < 11.6.9+security-01 / 12.0.0 < 12.0.8+security-01 / 12.1.0 < 12.1.5+security-01 / 12.2.0 < 12.2.3+security-01 / 12.3.0 < 12.3.1+security-01 DoS (CVE-2026-21720)
high
297197Grafana Labs 10.2.0 < 11.6.9+security-01 / 12.0.0 < 12.0.8+security-01 / 12.1.0 < 12.1.5+security-01 / 12.2.0 < 12.2.3+security-01 / 12.3.0 < 12.3.1+security- 01 权限升级CVE-2026-21721
high
296784OpenSSL 3.3.0 < 3.3.6 多种漏洞
high
296770OpenSSL 3.6.0 < 3.6.1 多个漏洞
high
296769OpenSSL 1.1.1 < 1.1.1ze 多个漏洞
high
296768OpenSSL 3.5.0 < 3.5.5 多个漏洞
high
296767OpenSSL 1.0.2 < 1.0.2zn 多个漏洞
high
296766OpenSSL 3.4.0 < 3.4.4 多个漏洞
high
296765OpenSSL 3.0.0 < 3.0.19 多个漏洞
high
296604Oracle HTTP Server2026 年 1 月 CPU
medium
296603Oracle HTTP Server2026 年 1 月 CPU
medium
288282SAP NetWeaver 命令注入2026 年 1 月
high
288281SAP NetWeaver AS ABAP 缺少授权检查 (3688703)
high
288280SAP NetWeaver AS Java 敏感信息漏洞2026 年 1 月
low
281759Nginx 站点枚举
info
281618IBM WebSphere eXtreme Scale 8.6.1.0 < 8.6.1.6 (7256003)
high
278309SAP NetWeaver AS Java DoS2025 年 12 月
high
278308SAP NetWeaver AS 缺少身份验证2025 年 12 月
medium
277790IBM WebSphere Application Server 8.5.x < 8.5.5.29 / 9.x < 9.0.5.27 / Liberty 17.0.0.3 < 26.0.0.1 XSS (7254078)
medium
276746Grafana Enterprise SCIM 配置权限提升(CVE-2025-41115)
critical
275454SAP NetWeaver AS ABAP 缺少授权检查 (3643337)
medium
275453SAP NetWeaver AS Java 信息泄露 (3643603)
medium
275445Omnissa Workspace ONE UEM 24.2.x < 24.2.0.36 / 24.6.x < 24.6.0.44 / 24.10.x < 24.10.0.25 (OMSA-2025-0005)
medium
274087IBM WebSphere Application Server 8.5.x < 8.5.5.29 / 9.x < 9.0.5.27 / Liberty 17.0.0.3 < 25.0.0.12 (7250200)
medium
272099IBM WebSphere eXtreme Scale 8.6.1.0 < 8.6.1.6 (7249244)
medium
272043Arcgis Server HTTP 检测
info
271806Apache Tomcat 9.0.40 < 9.0.109 多个漏洞
high
271696Apache Tomcat 11.0.0.M1 < 11.0.12
high
271695Apache Tomcat 10.1.0.M1 < 10.1.47
high
271694Apache Tomcat 9.0.0.M1 < 9.0.110
high
271693Apache Tomcat 11.0.0.M1 < 11.0.11 多个漏洞
high
271692Apache Tomcat 10.1.0.M1 < 10.1.45 多个漏洞
high
271691Apache Tomcat 9.0.0、M11 < 9.0.109 多个漏洞
high
270697SAP NetWeaver AS ABAP 多个漏洞2025 年 10 月
medium
270696SAP NetWeaver AS Java 不安全反序列化2025 年 10 月
critical
270347IBM WebSphere eXtreme Scale 8.6.1.0 < 8.6.1.6 (7247893)
high