Skip to main content

Vendor archive

tenable CVEs

Beta · best-effort

151 CVEs tagged to vendor tenable12 Critical, 57 High, 73 Medium, 9 Low, 0 Unrated.

CVE-2026-57588

Published Jun 25, 2026

A SQL injection vulnerability in Nessus allows an attacker to craft a malicious scan result file that, when imported by a privileged user, injects malicious SQL into the scan resu…

CVSS 1.8 · Low
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-57587

Published Jun 25, 2026

A SQL injection vulnerability in Nessus allows a remote, unauthenticated attacker who controls reverse DNS records for a scanned host to inject malicious SQL into the scan results…

CVSS 2.9 · Low
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-47358

Published May 19, 2026

Terrascan v1.18.3 and prior are vulnerable to Server-Side Request Forgery (SSRF) via external URL resolution in uploaded IaC templates when running in server mode. When Terrascan…

CVSS 9.2 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-47357

Published May 19, 2026

Terrascan v1.18.3 and prior are vulnerable to Server-Side Request Forgery (SSRF) via the remote_url parameter in the remote directory scan endpoint (POST /v1/{iac}/{iacVersion}/{c…

CVSS 9.2 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-47356

Published May 19, 2026

Terrascan v1.18.3 and prior are vulnerable to Server-Side Request Forgery (SSRF) via the webhook_url parameter in the file scan endpoint (POST /v1/{iac}/{iacVersion}/{cloud}/local…

CVSS 8.7 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-2698

Published Feb 23, 2026

An improper access control vulnerability exists where an authenticated user could access areas outside of their authorized scope.

CVSS 5.7 · Medium
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2026-2697

Published Feb 23, 2026

An Indirect Object Reference (IDOR) in Security Center allows an authenticated remote attacker to escalate privileges via the 'owner' parameter.

CVSS 2.1 · Low
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-2026

Published Feb 13, 2026

A vulnerability has been identified where weak file permissions in the Nessus Agent directory on Windows hosts could allow unauthorized access, potentially permitting Denial of Se…

CVSS 5.4 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-36630

Published Jul 2, 2025

In Tenable Nessus versions prior to 10.8.5 on a Windows host, it was found that a non-administrative user could overwrite arbitrary local system files with log content at SYSTEM p…

CVSS 8.4 · High
Vendor/product tagsBeta · best-effort

CVE-2025-36632

Published Jun 16, 2025

In Tenable Agent versions prior to 10.8.5 on a Windows host, it was found that a non-administrative user could execute code with SYSTEM privilege.

CVSS 7.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-36633

Published Jun 13, 2025

In Tenable Agent versions prior to 10.8.5 on a Windows host, it was found that a non-administrative user could arbitrarily delete local system files with SYSTEM privilege, potenti…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-36631

Published Jun 13, 2025

In Tenable Agent versions prior to 10.8.5 on a Windows host, it was found that a non-administrative user could overwrite arbitrary local system files with log content at SYSTEM pr…

CVSS 8.4 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-24917

Published May 23, 2025

In Tenable Network Monitor versions prior to 6.5.1 on a Windows host, it was found that a non-administrative user could stage files in a local directory to run arbitrary code with…

CVSS 7.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-24916

Published May 23, 2025

When installing Tenable Network Monitor to a non-default location on a Windows host, Tenable Network Monitor versions prior to 6.5.1 did not enforce secure permissions for sub-dir…

CVSS 7.0 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-9158

Published Sep 30, 2024

A stored cross site scripting vulnerability exists in Nessus Network Monitor where an authenticated, privileged local attacker could inject arbitrary code into the NNM UI via the…

CVSS 8.4 · High
Vendor/product tagsBeta · best-effort

CVE-2024-3232

Published Jul 16, 2024

A formula injection vulnerability exists in Tenable Identity Exposure where an authenticated remote attacker with administrative privileges could manipulate application form field…

CVSS 7.6 · High
Vendor/product tagsBeta · best-effort

CVE-2024-5759

Published Jun 12, 2024

An improper privilege management vulnerability exists in Tenable Security Center where an authenticated, remote attacker could view unauthorized objects and launch scans without h…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-1891

Published Jun 12, 2024

A stored cross site scripting vulnerability exists in Tenable Security Center where an authenticated, remote attacker could inject HTML code into a web application scan result pag…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2024-1683

Published Feb 23, 2024

A DLL injection vulnerability exists where an authenticated, low-privileged local attacker could modify application files on the TIE Secure Relay host, which could allow for overr…

CVSS 7.3 · High
Vendor/product tagsBeta · best-effort

CVE-2024-1471

Published Feb 14, 2024

An HTML injection vulnerability exists where an authenticated, remote attacker with administrator privileges on the Security Center application could modify Repository parameters,…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-1367

Published Feb 14, 2024

A command injection vulnerability exists where an authenticated, remote attacker with administrator privileges on the Security Center application could modify Logging parameters,…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2024-0971

Published Feb 7, 2024

A SQL injection vulnerability exists where an authenticated, low-privileged remote attacker could potentially alter scan DB content.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-0955

Published Feb 7, 2024

A stored XSS vulnerability exists where an authenticated, remote attacker with administrator privileges on the Nessus application could alter Nessus proxy settings, which could le…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-6178

Published Nov 20, 2023

An arbitrary file write vulnerability exists where an authenticated attacker with privileges on the managing application could alter Nessus Rules variables to overwrite arbitrary…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-6062

Published Nov 20, 2023

An arbitrary file write vulnerability exists where an authenticated, remote attacker with administrator privileges on the Nessus application could alter Nessus Rules variables to…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-25 of 151 CVEsPage 1 of 7