Web Servers Family for Nessus

IDNameSeverity
211636Draytek VigorConnect Unauthenticated LFI (CVE-2021-20124)
high
211633Grafana Labs Privilege Escalation (CVE-2024-9476)
medium
211576Grafana Labs SQL expressions allowing for RCE (CVE-2024-9264)
high
211519Apache Tomcat 11.0.0 < 11.0.1
medium
211518Apache Tomcat 9.0.96 < 9.0.97
medium
211517Apache Tomcat 10.1.31 < 10.1.33
medium
211506Apache Tomcat 11.0.0.M23 < 11.0.0 multiple vulnerabilities
critical
211504Apache Tomcat 10.1.27 < 10.1.31 multiple vulnerabilities
critical
211503Apache Tomcat 9.0.92 < 9.0.96 multiple vulnerabilities
critical
211465Rejetto HTTP File Server 2.x <= 2.3m RCE (CVE-2024-23692) (direct check)
critical
210957SAP NetWeaver AS ABAP NULL Pointer Dereference (3504390)
medium
210956SAP NetWeaver AS ABAP Information Disclosure (3508947)
medium
210955Security Updates for Azure CycleCloud (November 2024)
critical
210953Apache RocketMQ < 4.9.6 / 5.0.x < 5.1.1 RCE
critical
210932IBM WebSphere Application Server 8.5.x < 8.5.5.27 / 9.x < 9.0.5.22 (7174745)
medium
210931IBM WebSphere Application Server 8.5.x < 8.5.5.27 / 9.x < 9.0.5.22 XSS (7175393)
medium
210930IBM WebSphere eXtreme Scale 8.6.1.0 < 8.6.1.6 (7175229)
high
210894SAP NetWeaver AS Java Multiple Vulnerabilities (November 2024)
medium
210450Apache 2.4.x < 2.4.62 Multiple Vulnerabilities (Windows)
high
209278Oracle HTTP Server (October 2024 CPU)
high
209154OpenSSL 3.1.0 < 3.1.8 Vulnerability
medium
209153OpenSSL 3.2.0 < 3.2.4 Vulnerability
medium
209152OpenSSL 1.0.2 < 1.0.2zl Vulnerability
medium
209151OpenSSL 3.3.0 < 3.3.3 Vulnerability
medium
209150OpenSSL 3.0.0 < 3.0.16 Vulnerability
medium
209149OpenSSL 1.1.1 < 1.1.1zb Vulnerability
medium
208028IBM WebSphere Application Server 8.5.x < 8.5.5.27 / 9.x < 9.0.5.22 XSS (7171755)
medium
208027Grafana Labs Incorrect Permission (cve-2024-8118)
medium
207242SAP NetWeaver AS Java XSS (3505503)
medium
207241SAP NetWeaver AS ABAP Multiple Vulnerabilities (3488039)
medium
207240SAP NetWeaver AS ABAP Missing Authorization (3496410)
low
207239SAP NetWeaver AS ABAP Information Disclosure (3507252)
low
207229Security Updates for Azure CycleCloud (September 2024)
high
206652Rejetto HTTP File Server 2.x <= 2.3m RCE (CVE-2024-23692)
critical
206334IBM WebSphere eXtreme Scale 8.6.1.0 < 8.6.1.6 (7166876)
low
205886Apache OFBiz Path Traversal (CVE-2024-32113)
critical
205644IBM WebSphere Application Server 8.5.x < 8.5.5.27 / 9.x < 9.0.5.21 Information Disclosure (7165511)
medium
205643IBM WebSphere Application Server Liberty 17.0.0.3 < 24.0.0.9 Information Disclosure (7165502)
high
205614SAP NetWeaver AS ABAP Missing Authorization (3494349)
medium
205613SAP NetWeaver AS ABAP Improper Access Control (3468102)
medium
205612SAP NetWeaver AS Java Missing Authorization (3438085)
medium
205459Security Updates for Azure CycleCloud (August 2024)
high
205388Apache RocketMQ < 5.3.0 Information Disclosure (CVE-2024-23321)
high
205310Apache Traffic Server 8.x < 8.1.11 / 9.x < 9.2.5 Multiple Vulnerabilities
high
204917DLink DIR Information Disclosure (PT-2011-30)
high
204695TeamCity Server < 2024.7 Multiple Vulnerabilities
critical
202723Oracle HTTP Server (July 2024 CPU)
critical
202577Apache 2.4.60 < 2.4.62 Multiple Vulnerabilities
medium
202264SAP NetWeaver AS ABAP Protection Mechanism Failure (3456952)
medium
202263SAP NetWeaver AS ABAP Information Disclosure (3454858)
medium