← Back

Tenable

tenable

180 CVEs • 17 products

Products (17)

Click to collapse
Toggle

CVEs (180)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Tenable
1Security Center
Aug 19, 2026
Aug 14, 2026
9.4 CRITICAL· v4
9.9 CRITICAL· v3
N/A· v2
A command injection vulnerability exists in Security Center where a remote, unauthenticated attacker could exploit this issue to execute arbitrary commands on the underlying operating system with the privileges of the se...Show more
A command injection vulnerability exists in Security Center where a remote, unauthenticated attacker could exploit this issue to execute arbitrary commands on the underlying operating system with the privileges of the service account.Show less
1Tenable
1Security Center
Aug 19, 2026
Aug 14, 2026
9.4 CRITICAL· v4
9.9 CRITICAL· v3
N/A· v2
An authenticated command injection vulnerability exists in Security Center related to file upload processing. An attacker could exploit this issue by uploading a specially crafted file, potentially resulting in arbitrary...Show more
An authenticated command injection vulnerability exists in Security Center related to file upload processing. An attacker could exploit this issue by uploading a specially crafted file, potentially resulting in arbitrary command execution on the underlying operating system.Show less
1Tenable
1Security Center
Aug 19, 2026
Aug 14, 2026
7.1 HIGH· v4
7.1 HIGH· v3
N/A· v2
A SQL injection vulnerability exists in Security Center that could allow an attacker to access unauthorized data from the application's database.
1Tenable
1Security Center
Aug 19, 2026
Aug 14, 2026
8.7 HIGH· v4
8.8 HIGH· v3
N/A· v2
An input validation vulnerability exists in Security Center's file upload handling, where insufficient sanitization of uploaded filenames could contribute to a downstream command injection issue.
1Tenable
1Security Center
Aug 19, 2026
Aug 14, 2026
5.3 MEDIUM· v4
4.3 MEDIUM· v3
N/A· v2
An improper access control vulnerability exists where an authenticated non-administrative application user could potentially view settings outside of their assigned scope.
1Tenable
1Security Center
Aug 19, 2026
Aug 14, 2026
6.0 MEDIUM· v4
5.3 MEDIUM· v3
N/A· v2
An issue was identified in which CSRF tokens were generated using a predictable method, potentially reducing their effectiveness as a security control. This has been addressed by improving the randomness and entropy of t...Show more
An issue was identified in which CSRF tokens were generated using a predictable method, potentially reducing their effectiveness as a security control. This has been addressed by improving the randomness and entropy of token generation.Show less
1Tenable
1Security Center
Aug 19, 2026
Aug 14, 2026
8.5 HIGH· v4
8.8 HIGH· v3
N/A· v2
A local privilege escalation vulnerability exists in Security Center. An attacker with write access to a specific configuration file could achieve arbitrary code execution with elevated privileges, without requiring furt...Show more
A local privilege escalation vulnerability exists in Security Center. An attacker with write access to a specific configuration file could achieve arbitrary code execution with elevated privileges, without requiring further user or victim interaction.Show less
1Tenable
1Security Center
Aug 19, 2026
Aug 14, 2026
6.9 MEDIUM· v4
4.9 MEDIUM· v3
N/A· v2
A SQL injection vulnerability exists in Security Center that could allow an authenticated administrator to execute arbitrary SQL queries, potentially resulting in unauthorized access to sensitive data, including credenti...Show more
A SQL injection vulnerability exists in Security Center that could allow an authenticated administrator to execute arbitrary SQL queries, potentially resulting in unauthorized access to sensitive data, including credentials.Show less
1Tenable
1Security Center
Aug 19, 2026
Aug 14, 2026
8.6 HIGH· v4
8.1 HIGH· v3
N/A· v2
A privilege escalation vulnerability exists in Tenable Security Center that allows a user with "Security Manager" role and "manage user" permission on a single group to modify users belonging to other groups. This bypass...Show more
A privilege escalation vulnerability exists in Tenable Security Center that allows a user with "Security Manager" role and "manage user" permission on a single group to modify users belonging to other groups. This bypasses the intended access control restrictions and enables unauthorized cross-group user management.Show less
1Tenable
1Security Center
Aug 19, 2026
Aug 14, 2026
8.6 HIGH· v4
7.2 HIGH· v3
N/A· v2
A command injection vulnerability exists in Tenable Security Center. An authenticated administrator could modify application configuration values to achieve arbitrary command execution on the underlying operating system...Show more
A command injection vulnerability exists in Tenable Security Center. An authenticated administrator could modify application configuration values to achieve arbitrary command execution on the underlying operating system when specific backend operations are triggered.Show less
1Tenable
1Security Center
Aug 19, 2026
Aug 14, 2026
9.4 CRITICAL· v4
9.9 CRITICAL· v3
N/A· v2
A remote code execution vulnerability exists in Tenable Security Center's report generation functionality. An authenticated, non-administrative user could exploit this issue by supplying specially crafted input that is l...Show more
A remote code execution vulnerability exists in Tenable Security Center's report generation functionality. An authenticated, non-administrative user could exploit this issue by supplying specially crafted input that is later processed unsafely during server-side report rendering, resulting in arbitrary code execution with the privileges of the service account.Show less
1Tenable
1Security Center
Aug 18, 2026
Jul 21, 2026
8.7 HIGH· v4
8.8 HIGH· v3
N/A· v2
The audit file upload handler does not sanitize filenames, allowing shell metacharacters to flow into system command execution. This input validation failure enables command injection when chained with a related vulnerab...Show more
The audit file upload handler does not sanitize filenames, allowing shell metacharacters to flow into system command execution. This input validation failure enables command injection when chained with a related vulnerability.Show less
1Tenable
1Security Center
Aug 18, 2026
Jul 21, 2026
7.1 HIGH· v4
7.1 HIGH· v3
N/A· v2
Unsanitized user-supplied input in report filtering parameters is concatenated directly into SQL queries without proper escaping or parameterized queries, enabling blind SQL injection and unauthorized database read acces...Show more
Unsanitized user-supplied input in report filtering parameters is concatenated directly into SQL queries without proper escaping or parameterized queries, enabling blind SQL injection and unauthorized database read access.Show less
1Tenable
1Security Center
Aug 18, 2026
Jul 21, 2026
9.4 CRITICAL· v4
9.9 CRITICAL· v3
N/A· v2
A filename supplied during file upload is not properly sanitized before being used in system command execution, allowing an attacker to inject shell metacharacters and achieve command injection via the audit file upload...Show more
A filename supplied during file upload is not properly sanitized before being used in system command execution, allowing an attacker to inject shell metacharacters and achieve command injection via the audit file upload functionality.Show less
1Tenable
1Security Center
Aug 18, 2026
Jul 21, 2026
9.4 CRITICAL· v4
9.9 CRITICAL· v3
N/A· v2
Unvalidated input in asset filter parameters allows shell metacharacters to escape command argument handling, resulting in remote code execution as a low-privileged OS user via the Analysis REST endpoint.
1Tenable
1Security Center
Aug 18, 2026
Jul 21, 2026
9.4 CRITICAL· v4
8.4 HIGH· v3
N/A· v2
An authenticated non-admin user can exploit a SQL injection flaw in the ticketing REST API to access sensitive data stored in the appliance database.
1Tenable
1Nessus Agent
Aug 25, 2026
Jul 14, 2026
9.4 CRITICAL· v4
9.1 CRITICAL· v3
N/A· v2
A path traversal vulnerability in Tenable Agent 11.2.0 and 11.1.3 and lower allows a privileged attacker to write arbitrary files outside the intended plugin directory, potentially leading to remote code execution.
1Tenable
1Nessus
Jun 26, 2026
Jun 25, 2026
1.8 LOW· v4
3.3 LOW· v3
N/A· v2
A SQL injection vulnerability in Nessus allows an attacker to craft a malicious scan result file that, when imported by a privileged user, injects malicious SQL into the scan results database, potentially enabling exfilt...Show more
A SQL injection vulnerability in Nessus allows an attacker to craft a malicious scan result file that, when imported by a privileged user, injects malicious SQL into the scan results database, potentially enabling exfiltration of scan-result data.Show less
1Tenable
1Nessus
Jun 26, 2026
Jun 25, 2026
2.9 LOW· v4
5.3 MEDIUM· v3
N/A· v2
A SQL injection vulnerability in Nessus allows a remote, unauthenticated attacker who controls reverse DNS records for a scanned host to inject malicious SQL into the scan results database, potentially enabling exfiltrat...Show more
A SQL injection vulnerability in Nessus allows a remote, unauthenticated attacker who controls reverse DNS records for a scanned host to inject malicious SQL into the scan results database, potentially enabling exfiltration of scan-result data.Show less
1Tenable
1Identity Exposure
Aug 19, 2026
Jun 23, 2026
8.7 HIGH· v4
7.5 HIGH· v3
N/A· v2
Tenable Identity Exposure contains multiple unauthenticated API endpoints under /w/api/* that expose sensitive application configuration data including cleartext LDAP credentials, SAML configuration, user accounts, and d...Show more
Tenable Identity Exposure contains multiple unauthenticated API endpoints under /w/api/* that expose sensitive application configuration data including cleartext LDAP credentials, SAML configuration, user accounts, and directory settings to unauthenticated remote attackers. Affected responses are served with Cache-Control: public headers and without Vary: Cookie, allowing reverse proxies and CDNs to cache and serve sensitive data to unauthenticated users even after authentication is applied.Show less