Nessus 的 CGI abuses 系列

ID名称严重性
304265GitLab 14.3 < 18.8.7 / 18.9 < 18.9.3 / 18.10 < 18.10.1 (CVE-2026-2370)
high
303800NetScaler ADC 和 NetScaler 网关内存越界读取 (CTX696300 / CVE-2026-3055)
critical
303799NetScaler ADC 和 NetScaler 网关争用条件 (CTX696300 / CVE-2026-4368)
high
303627GitLab 17.10 < 18.8.7 / 18.9 < 18.9.3 / 18.10 < 18.10.1 (CVE-2026-3857)
high
303626GitLab 18.5 < 18.8.7 / 18.9 < 18.9.3 / 18.10 < 18.10.1 (CVE-2026-1724)
high
303625GitLab 11.10 < 18.8.7 / 18.9 < 18.9.3 / 18.10 < 18.10.1 (CVE-2026-2726)
medium
303624GitLab 15.4 < 18.8.7 / 18.9 < 18.9.3 / 18.10 < 18.10.1 (CVE-2026-2995)
medium
303623GitLab 7.11 < 18.8.7 / 18.9 < 18.9.3 / 18.10 < 18.10.1 (CVE-2026-2745)
high
303622GitLab 18.1 < 18.8.7 / 18.9 < 18.9.3 / 18.10 < 18.10.1 (CVE-2026-4363)
low
303621GitLab 18.5 < 18.8.7 / 18.9 < 18.9.3 / 18.10 < 18.10.1 (CVE-2026-3988)
high
303620GitLab 17.7 < 18.8.7 / 18.9 < 18.9.3 / 18.10 < 18.10.1 (CVE-2026-2973)
medium
303601Atlassian Bamboo 9.6.x < 9.6.24 / 10.x < 10.2.16 / 11.x / 12.x < 12.1.3 多个漏洞
high
303587Kibana 8.x < 8.19.12 / 9.x < 9.2.6 / 9.3.x < 9.3.1 缺少授权 (ESA-2026-19)
medium
303586Kibana 8.x < 8.19.13 / 9.x < 9.2.7 / 9.3.x < 9.3.2 DoS (ESA-2026-20)
medium
303451Unraid < 7.2.4 多种漏洞 (ZDI-26-171 / ZDI-26-172)
high
303449MantisBT < 2.28.1 SOAP API 身份验证绕过漏洞 (GHSA-phrq-pc6r-f6gh)
critical
303195Cockpit < 2.13.5 SQLi (GHSA-7x5c-vfhj-9628)
medium
303190Dell iDRAC9 < 7.00.00.174 / 7.10.90.00 信息泄露 (DSA-2026-113)
medium
302915Splunk Universal Forwarders 10.0.0 < 10.0.4、10.2 < 10.2.1 (SVD-2026-0314)
high
302903Jenkins 插件多个漏洞 (2026-03-18)
high
302902Jenkins LTS < 2.541.3 / Jenkins weekly < 2.555 多个漏洞
high
301998EcoStruxure IT Data Center Expert <= 9.0 硬编码凭据的使用 (SEVD-2026-069-05)
high
301912GitLab 8.14 < 18.7.6 / 18.8 < 18.8.6 / 18.9 < 18.9.2 (CVE-2026-1182)
medium
301879GitLab 14.4 < 18.7.6 / 18.8 < 18.8.6 / 18.9 < 18.9.2 (CVE-2026-1663)
medium
301878GitLab 10.6 < 18.7.6 / 18.8 < 18.8.6 / 18.9 < 18.9.2 (CVE-2026-1090)
medium
301877GitLab 8.11 < 18.7.6 / 18.8 < 18.8.6 / 18.9 < 18.9.2 (CVE-2026-3848)
medium
301876GitLab 12.6 < 18.7.6 / 18.8 < 18.8.6 / 18.9 < 18.9.2 (CVE-2026-1732)
medium
301874Splunk Enterprise 9.3.0 < 9.3.10、9.4.0 < 9.4.9、10.0.0 < 10.0.4 (SVD-2026-0302)
high
301873Splunk Enterprise 9.3.0 < 9.3.10、9.4.0 < 9.4.9、10.0.0 < 10.0.3 (SVD-2026-0303)
medium
301872Splunk Enterprise 9.3.0 < 9.3.10、9.4.0 < 9.4.9、10.0.0 < 10.0.4、10.2.0 < 10.2.1 (SVD-2026-0304)
medium
301871Splunk Enterprise 10.0.0 < 10.0.4、10.2.0 < 10.2.1 (SVD-2026-0305)
medium
301864Splunk Enterprise 9.3.0 < 9.3.9、9.4.0 < 9.4.9、10.0.0 < 10.0.3 (SVD-2026-0301)
medium
301863GitLab 1.0 < 18.7.6 / 18.8 < 18.8.6 / 18.9 < 18.9.2 (CVE-2026-1230)
medium
301862GitLab 18.9 < 18.9.2 (CVE-2026-1069)
high
301861GitLab 15.6 < 18.7.6 / 18.8 < 18.8.6 / 18.9 < 18.9.2 (CVE-2026-0602)
medium
301859Zabbix 6.0.x < 6.0.41 / 7.0.x < 7.0.18 / 7.4.x < 7.4.2 未经授权的对象创建 (ZBX-27567)
medium
301728WordPress 6.0 < 6.9.2
high
300913Apache ActiveMQ < 5.19.2 / 6.0.x < 6.1.9 / 6.2.0 MQTT 控制数据包验证漏洞 (CVE-2025-66168)
high
300912Kibana 8.x < 8.19.12 / 9.2.x < 9.2.6 / 9.3.x < 9.3.1 (ESA_2026_13)
high
300426GitLab 14.4 < 18.7.5 / 18.8 < 18.8.5 / 18.9 < 18.9.1 (CVE-2026-1662)
high
300425GitLab 11.2 < 18.7.5 / 18.8 < 18.8.5 / 18.9 < 18.9.1 (CVE-2026-2845)
medium
300404GitLab 16.2 < 18.7.5 / 18.8 < 18.8.5 / 18.9 < 18.9.1 (CVE-2026-0752)
medium
300301GitLab 17.11 < 18.7.5 / 18.8 < 18.8.5 / 18.9 < 18.9.1 (CVE-2026-1747)
medium
300235VMWare Aria Operations 8.x < 8.18.6 多个漏洞 (VMSA-2026-0001)
critical
300170GitLab 18.9 < 18.9.1 (CVE-2026-1725)
high
300125GitLab 9.2 < 18.7.5 / 18.8 < 18.8.5 / 18.9 < 18.9.1 (CVE-2026-1388)
high
299881Metabase < 0.57.13 / 0.58.x < 0.58.7 / 1.x < 1.57.13 / 1.58.x < 1.58.7 信息泄露
medium
299759Atlassian Confluence 7.19.x < 9.2.13 / 9.3.1 < 10.2.2 (CONFSERVER-102184)
high
299692Atlassian Confluence 7.19.x < 9.2.7 / 9.3.1 < 9.5.3 / 10.0.2 / 10.1.0 / 10.2.0 (CONFSERVER-102193)
high
299675Aruba ClearPass Policy Manager 6.11.x < 6.11.13 / 6.12.x < 6.12.7 本地权限升级 (CVE-2026-23599)
high