Nessus 的 CGI abuses 系列

ID名稱嚴重性
170061GitLab 13.7 < 15.4.6 / 15.5 < 15.5.5 / 15.6 < 15.6.1 (CVE-2022-4255)
medium
170060GitLab 1.0 <12.9.8/15.5 < 15.5.5/15.6 < 15.6.1 (CVE-2022-4205)
high
170059GitLab 12.9 < 15.4.6 / 15.5 < 15.5.5 / 15.6 < 15.6.1 (CVE-2022-3740)
medium
170058GitLab 12.8 < 15.4.6 / 15.5 < 15.5.5 / 15.6 < 15.6.1 (CVE-2022-3478)
medium
169976PHP 8.2.x < 8.2.1
high
169975GitLab 15.4 < 15.4.6 / 15.5 < 15.5.5 / 15.6 < 15.6.1 (CVE-2022-3820)
medium
169907HTMLawed < 1.2.9 命令插入 (CVE-2022-35914)
critical
169906Zyxel 命令插入 (CVE-2022-30525) (直接檢查)
critical
169673EMC RSA Archer 6.0 < 6.9 SP3 P4 / 6.10 < 6.10 P2 遠端程式碼執行
high
169631PHP 8.1.x < 8.1.14
high
169630PHP 8.0.x < 8.0.27
critical
169605ManageEngine PAM360 < 5.8 Build 5801 SQLi
critical
169582IBM Cognos Analytics 多個弱點 (6841801)
critical
169572ManageEngine Access Manager Plus < 4.3 Build 4309 SQLi
critical
169571ManageEngine Password Manager Pro < 12.2 Build 12210 SQLi
critical
169507Symantec Messaging Gateway < 10.8 XSS (21115)
medium
169457SolarWinds Web Help Desk <= 12.7.6 任意程式碼執行
medium
169427GitLab < 15.3.5 (CVE-2022-3265)
medium
169277SolarWinds Platform 2022.4.1
medium
168915Trend Micro Mobile Security for Enterprise 檔案刪除 (CVE-2022-40980)
critical
168914Trend Micro Mobile Security for Enterprise Web 主控台偵測
info
168876VMware Workspace One Access / VMware Identity Manager 多個弱點 (VMSA-2022-0032)
high
168664TYPO3 9.0.0 < 9.5.38 ELTS / 10.0.0 < 10.4.33 / 11.0.0 < 11.5.20 / 12.0.0 < 12.1.1 (TYPO3-CORE-SA-2022-016)
medium
168663TYPO3 9.0.0 < 9.5.38 ELTS / 10.0.0 < 10.4.33 / 11.0.0 < 11.5.20 (TYPO3-CORE-SA-2022-012)
high
168662TYPO3 8.0.0 < 8.7.49 ELTS / 9.0.0 < 9.5.38 ELTS / 10.0.0 < 10.4.33 / 11.0.0 < 11.5.20 / 12.0.0 < 12.1.1 (TYPO3-CORE-SA-2022-013)
medium
168661TYPO3 8.0.0 < 8.7.49 ELTS / 9.0.0 < 9.5.38 ELTS / 10.0.0 < 10.4.33 / 11.0.0 < 11.5.20 / 12.0.0 < 12.1.1 XSS (TYPO3-CORE-SA-2022-017)
medium
168660TYPO3 8.0.0 < 8.7.49 ELTS / 9.0.0 < 9.5.38 ELTS / 10.0.0 < 10.4.33 / 11.0.0 < 11.5.20 / 12.0.0 < 12.1.1 (TYPO3-CORE-SA-2022-015)
high
168659TYPO3 10.0.0 < 10.4.33 / 11.0.0 < 11.5.20 / 12.0.0 < 12.1.1 (TYPO3-CORE-SA-2022-014)
medium
168654Citrix ADC 和 Citrix Gateway RCE (CTX474995)
critical
168545WordPress 外掛程式「AdRotate Banner Manager」 < 5.9.1 XSRF
high
168500PHP 8.2.x < 8.2.0 多個弱點
critical
168496Apache Solr 7.4.0 <= 7.7.3 / 8.0.0 <= 8.11.0 RCE
critical
168495Apache Solr < 8.11.1 資訊洩漏弱點
critical
168478PrimeTek PrimeFaces 遠端程式碼執行 (CVE-2017-1000486)
critical
168361ManageEngine ServiceDesk Plus < 14.0 Build 14001 多個弱點
medium
168360ManageEngine AssetExplorer < 6.9 Build 6981 權限提升
medium
168359ManageEngine ServiceDesk Plus < 13.0 Build 13011 RCE
high
168358ManageEngine SupportCenter Plus < 11.0 Build 11026 多個弱點
high
168357ManageEngine AssetExplorer 6.9 Build 6980 XXE
medium
168356ManageEngine ServiceDesk Plus MSP < 10.6 Build 10609 權限提升
medium
168355ManageEngine ServiceDesk Plus MSP < 13.0 Build 13000 RCE
high
168354ManageEngine SupportCenter Plus < 11.0 Build 11025 權限提升
medium
168353ManageEngine ServiceDesk Plus MSP < 13.0 Build 13001 XXE
medium
168352Mattermost Server < 7.4.0 DoS (MMSA-2022-00124)
medium
168351Mattermost Server < 7.1.4 / 7.2.x < 7.2.1 / 7.3.x < 7.3.1 DoS (MMSA-2022-00120)
medium
168350Mattermost Server < 7.1.4 / 7.2.x < 7.2.1 / 7.3.x < 7.3.1 DoS (MMSA-2022-00118)
medium
168325Atlassian Crowd 3.x / 4.x < 4.4.4 / 5.x < 5.0.3 安全性繞過 (CWD-5888)
critical
168269Zimbra Collaboration Server 8.8.x < 8.8.15 修補程式 35 / 9.0.0 < 9.0.0 修補程式 28 多個弱點
high
168019GitLab < 15.3.5 (CVE-2022-3818)
medium
167867WordPress 外掛程式「Advanced Custom Fields」< 5.12.4、6.x < 6.0.3 自訂欄位值暴露
high