← Back

Nessus

nessus

Vendor: Tenable • 67 CVEs

CVEs (67)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Tenable
2Appliance
Nessus
May 13, 2026
Mar 8, 2017
N/A· v4
7.3 HIGH· v3
6.0 MEDIUM· v2
Tenable Nessus before 6.10.2 (as used alone or in Tenable Appliance before 4.5.0) was found to contain a flaw that allowed a remote, authenticated attacker to upload a crafted file that could be written to anywhere on th...Show more
Tenable Nessus before 6.10.2 (as used alone or in Tenable Appliance before 4.5.0) was found to contain a flaw that allowed a remote, authenticated attacker to upload a crafted file that could be written to anywhere on the system. This could be used to subsequently gain elevated privileges on the system (e.g., after a reboot). This issue only affects installations on Windows.Show less
1Tenable
1Nessus
May 13, 2026
Feb 28, 2017
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Cross-site scripting (XSS) vulnerability in Tenable Nessus before 6.9.1 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
1Tenable
1Nessus
May 13, 2026
Jan 31, 2017
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Cross-site scripting (XSS) vulnerability in Tenable Nessus before 6.9 allows remote authenticated users to inject arbitrary web script or HTML via vectors related to handling of .nessus files.
3Momentjs
OracleTenable
3Moment
NessusPrimavera Unifier
May 13, 2026
Jan 23, 2017
N/A· v4
6.5 MEDIUM· v3
7.8 HIGH· v2
The duration function in the moment package before 2.11.2 for Node.js allows remote attackers to cause a denial of service (CPU consumption) via a long string, aka a "regular expression Denial of Service (ReDoS)."
1Tenable
1Nessus
May 6, 2026
Jan 5, 2017
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Cross-site scripting (XSS) vulnerability in Tenable Nessus before 6.9.3 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
1Tenable
2Nessus
Web Ui
May 6, 2026
Jul 23, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The /server/properties resource in Tenable Web UI before 2.3.5 for Nessus 5.2.3 through 5.2.7 allows remote attackers to obtain sensitive information via the token parameter.
1Tenable
2Nessus
Plugin Set
May 6, 2026
Apr 11, 2014
N/A· v4
N/A· v3
6.9 MEDIUM· v2
A race condition in the wmi_malware_scan.nbin plugin before 201402262215 for Nessus 5.2.1 allows local users to gain privileges by replacing the dissolvable agent executable in the Windows temp directory with a Trojan ho...Show more
A race condition in the wmi_malware_scan.nbin plugin before 201402262215 for Nessus 5.2.1 allows local users to gain privileges by replacing the dissolvable agent executable in the Windows temp directory with a Trojan horse program.Show less