组合风险、利用情报和受影响对象,快速定位需要优先处置的漏洞。
| 漏洞与影响对象 | 漏洞类型 | 风险等级 | CVSS | EPSS | PoC 状态 | 披露时间 | |
|---|---|---|---|---|---|---|---|
RCE FineReport v9 Arbitrary File Overwrite | 文件上传 | 严重 | — | — | PoC | ||
| Cisco Unified Call Manager Username Enumeration | 未授权访问 | 中危 | — | — | PoC | ||
RCE Apache Solr 9.1 - Remote Code Execution | 远程代码执行 | 严重 | — | — | PoC | ||
| Amazon EC2 - Server-side request forgery (SSRF) | 服务端请求伪造 | 严重 | 9.3 | — | PoC | ||
| Qibocms - Arbitrary File Download | 本地文件读取 | 高危 | — | — | PoC | ||
| Spring Eureka Exposure | 信息泄露 | 低危 | — | — | PoC | ||
| SAP Directory Listing | 目录列举 | 中危 | — | — | PoC | ||
| Exposed Prometheus | 安全配置错误 | 低危 | — | — | PoC | ||
| Unauthorized HP office pro printer | 未授权访问 | 高危 | — | — | PoC | ||
| Unauthorized HP Printer | 未授权访问 | 高危 | — | — | PoC | ||
| GitLab - User Information Disclosure Via Open API | 信息泄露 | 中危 | — | — | PoC | ||
| Flask Werkzeug Debugger Exposure | 信息泄露 | 低危 | — | — | PoC | ||
| Apache Storm Unauth | 未授权访问 | 中危 | — | — | PoC | ||
| Apache Hbase Unauth | 未授权访问 | 中危 | — | — | PoC | ||
RCE Unauthenticated Airflow Instance | 未授权访问 | 高危 | — | — | PoC | ||
| Airflow Debug Trace | 安全配置错误 | 低危 | — | — | PoC | ||
| AEM WCM Suggestions Servlet | 安全配置错误 | 低危 | — | — | PoC | ||
| Adobe AEM Security Users Exposure | 信息泄露 | 中危 | — | — | PoC | ||
| AEM QueryBuilder Internal Path Read | 文件包含 | 中危 | — | — | PoC | ||
| Adobe AEM Installed OSGI Bundles | 信息泄露 | 低危 | — | — | PoC |