Web Servers Family for Nessus

IDNameSeverity
303225Pac4J JWT < 4.5.9 / 5.x < 5.7.9 / 6.x < 6.3.3 Authentication Bypass (CVE-2026-29000) (Direct Check)
critical
302501OpenSSL 3.6.0 < 3.6.2 Vulnerability
high
302500OpenSSL 3.5.0 < 3.5.6 Vulnerability
high
302165SAP NetWeaver AS ABAP Missing Authorization Check (3703856)
medium
302164SAP NetWeaver AS ABAP SSRF (3689080)
medium
302163SAP NetWeaver AS ABAP Missing Authorization Check (3704740)
medium
302162SAP NetWeaver AS ABAP Missing Authorization Check (3694383)
low
302113SAP NetWeaver AS Java Multiple Vulnerabilities (3700960)
high
301975SAP Netweaver Visual Composer Unrestricted File Upload (3084487)
high
300293IBM WebSphere Application Server Liberty 17.0.0.3 < 26.0.0.3 (7261761)
critical
300110IBM WebSphere Application Server 8.5.5.3 < 8.5.5.30 / 9.x < 9.0.5.27 / Liberty 21.0.0.3 < 26.0.0.3 DoS (7261794)
high
299410Apache Tomcat 10.1.0.M7 < 10.1.52
high
299403Apache Tomcat 11.0.0.M1 < 11.0.15 multiple vulnerabilities
critical
299402Apache Tomcat 9.0.83 < 9.0.115
high
299401Apache Tomcat 10.1.0.M1 < 10.1.50 multiple vulnerabilities
critical
299398Apache Tomcat 11.0.0.M1 < 11.0.18
high
299397Apache Tomcat 9.0.0.M1 < 9.0.113 multiple vulnerabilities
critical
298967SAP NetWeaver AS ABAP Missing Authorization Check (3674774)
critical
298966SAP NetWeaver AS ABAP XML Signature Wrapping (3697567)
high
298965SAP NetWeaver AS Java CRLF Injection (3673213)
low
298964SAP NetWeaver AS ABAP and S/4HANA Missing Authorization Check (3672622)
medium
298596IBM WebSphere Application Server 8.5.5.28 < 8.5.5.30 / 9.0.5.24 < 9.0.5.27 (7260217)
medium
297279IBM WebSphere Application Server Liberty 17.0.0.3 < 26.0.0.2 RCE (7258224)
high
297229Oracle APEX Sample Applications (Brookstrut) (CVE-2026-21931)
medium
297228Oracle Application Express (Apex) Web Detection
info
297198Grafana Labs 3.0.0 < 11.6.9+security-01 / 12.0.0 < 12.0.8+security-01 / 12.1.0 < 12.1.5+security-01 / 12.2.0 < 12.2.3+security-01 / 12.3.0 < 12.3.1+security-01 DoS (CVE-2026-21720)
high
297197Grafana Labs 10.2.0 < 11.6.9+security-01 / 12.0.0 < 12.0.8+security-01 / 12.1.0 < 12.1.5+security-01 / 12.2.0 < 12.2.3+security-01 / 12.3.0 < 12.3.1+security-01 Privilege Escalation (CVE-2026-21721)
high
296784OpenSSL 3.3.0 < 3.3.6 Multiple Vulnerabilities
high
296770OpenSSL 3.6.0 < 3.6.1 Multiple Vulnerabilities
high
296769OpenSSL 1.1.1 < 1.1.1ze Multiple Vulnerabilities
high
296768OpenSSL 3.5.0 < 3.5.5 Multiple Vulnerabilities
high
296767OpenSSL 1.0.2 < 1.0.2zn Multiple Vulnerabilities
high
296766OpenSSL 3.4.0 < 3.4.4 Multiple Vulnerabilities
high
296765OpenSSL 3.0.0 < 3.0.19 Multiple Vulnerabilities
high
296604Oracle HTTP Server (January 2026 CPU)
medium
296603Oracle HTTP Server (January 2026 CPU)
medium
288282SAP NetWeaver Command Injection (January 2026)
high
288281SAP NetWeaver AS ABAP Missing Authorization Check (3688703)
high
288280SAP NetWeaver AS Java Sensitive Information Vulnerability (January 2026)
low
281759Nginx Sites Enumeration
info
281618IBM WebSphere eXtreme Scale 8.6.1.0 < 8.6.1.6 (7256003)
high
278309SAP NetWeaver AS Java DoS (December 2025)
high
278308SAP NetWeaver AS Missing Authentication (December 2025)
medium
277790IBM WebSphere Application Server 8.5.x < 8.5.5.29 / 9.x < 9.0.5.27 / Liberty 17.0.0.3 < 26.0.0.1 XSS (7254078)
medium
276746Grafana Enterprise SCIM Provisioning Privilege Escalation (CVE-2025-41115)
critical
275454SAP NetWeaver AS ABAP Missing Authorization Check (3643337)
medium
275453SAP NetWeaver AS Java Information Disclosure (3643603)
medium
275445Omnissa Workspace ONE UEM 24.2.x < 24.2.0.36 / 24.6.x < 24.6.0.44 / 24.10.x < 24.10.0.25 (OMSA-2025-0005)
medium
274087IBM WebSphere Application Server 8.5.x < 8.5.5.29 / 9.x < 9.0.5.27 / Liberty 17.0.0.3 < 25.0.0.12 (7250200)
medium
272099IBM WebSphere eXtreme Scale 8.6.1.0 < 8.6.1.6 (7249244)
medium