← Back

Tenable

tenable

160 CVEs • 16 products

Products (16)

Click to collapse
Toggle
Nessus
nessus
Tenable.sc
tenable.sc
Nessus Agent
nessus_agent
Appliance
appliance
Terrascan
terrascan
Web Ui
web_ui
Tenable.io
tenable.io
Plugin Set
plugin-set
Jira Cloud
jira_cloud
Plugin Feed
plugin_feed

CVEs (160)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Tenable
1Nessus
Jun 26, 2026
Jun 25, 2026
1.8 LOW· v4
3.3 LOW· v3
N/A· v2
A SQL injection vulnerability in Nessus allows an attacker to craft a malicious scan result file that, when imported by a privileged user, injects malicious SQL into the scan results database, potentially enabling exfilt...Show more
A SQL injection vulnerability in Nessus allows an attacker to craft a malicious scan result file that, when imported by a privileged user, injects malicious SQL into the scan results database, potentially enabling exfiltration of scan-result data.Show less
1Tenable
1Nessus
Jun 26, 2026
Jun 25, 2026
2.9 LOW· v4
5.3 MEDIUM· v3
N/A· v2
A SQL injection vulnerability in Nessus allows a remote, unauthenticated attacker who controls reverse DNS records for a scanned host to inject malicious SQL into the scan results database, potentially enabling exfiltrat...Show more
A SQL injection vulnerability in Nessus allows a remote, unauthenticated attacker who controls reverse DNS records for a scanned host to inject malicious SQL into the scan results database, potentially enabling exfiltration of scan-result data.Show less
1Tenable
1Terrascan
Jul 24, 2026
May 19, 2026
9.2 CRITICAL· v4
8.6 HIGH· v3
N/A· v2
Terrascan v1.18.3 and prior are vulnerable to Server-Side Request Forgery (SSRF) via external URL resolution in uploaded IaC templates when running in server mode. When Terrascan parses uploaded ARM templates or CloudFor...Show more
Terrascan v1.18.3 and prior are vulnerable to Server-Side Request Forgery (SSRF) via external URL resolution in uploaded IaC templates when running in server mode. When Terrascan parses uploaded ARM templates or CloudFormation templates, it resolves external URLs referenced within those templates via hashicorp/go-getter with all default detectors enabled, including FileDetector. An unauthenticated remote attacker can upload an ARM template containing a templateLink.uri or parametersLink.uri field, or a CloudFormation template containing an AWS::CloudFormation::Stack TemplateURL field, pointing to an attacker-controlled URL. Terrascan will fetch the attacker-controlled URL server-side. Unlike SSRF via the remote scan endpoint, file:// URLs are directly usable without requiring an X-Terraform-Get redirect, enabling local file read. This affects deployments running terrascan in server mode (terrascan server), which binds to 0.0.0.0 with no authentication. Note: Terrascan was archived in August 2023 and no patch will be released.Show less
1Tenable
1Terrascan
Jul 24, 2026
May 19, 2026
9.2 CRITICAL· v4
8.6 HIGH· v3
N/A· v2
Terrascan v1.18.3 and prior are vulnerable to Server-Side Request Forgery (SSRF) via the remote_url parameter in the remote directory scan endpoint (POST /v1/{iac}/{iacVersion}/{cloud}/remote/dir/scan) when running in se...Show more
Terrascan v1.18.3 and prior are vulnerable to Server-Side Request Forgery (SSRF) via the remote_url parameter in the remote directory scan endpoint (POST /v1/{iac}/{iacVersion}/{cloud}/remote/dir/scan) when running in server mode. An unauthenticated remote attacker can supply an attacker-controlled HTTP URL as remote_url with remote_type set to "http". The URL is passed directly to hashicorp/go-getter (v1.7.5) without validation. Go-getter's HttpGetter supports the X-Terraform-Get response header, allowing the attacker's server to redirect the download to a file:// URL, enabling local file read. Additionally, HttpGetter has Netrc set to true, causing it to read ~/.netrc and send stored credentials to attacker-controlled hostnames. This affects deployments running terrascan in server mode (terrascan server), which binds to 0.0.0.0 with no authentication. Note: Terrascan was archived in August 2023 and no patch will be released.Show less
1Tenable
1Terrascan
Jul 24, 2026
May 19, 2026
8.7 HIGH· v4
8.6 HIGH· v3
N/A· v2
Terrascan v1.18.3 and prior are vulnerable to Server-Side Request Forgery (SSRF) via the webhook_url parameter in the file scan endpoint (POST /v1/{iac}/{iacVersion}/{cloud}/local/file/scan) when running in server mode....Show more
Terrascan v1.18.3 and prior are vulnerable to Server-Side Request Forgery (SSRF) via the webhook_url parameter in the file scan endpoint (POST /v1/{iac}/{iacVersion}/{cloud}/local/file/scan) when running in server mode. An unauthenticated remote attacker can supply an arbitrary URL as the webhook_url multipart form parameter. After scanning the uploaded file, Terrascan sends an HTTP POST request to the attacker-controlled URL containing the full scan results as a JSON body, with the attacker-supplied webhook_token forwarded as a Bearer token in the Authorization header. The retryable HTTP client retries up to 10 times on failure. This affects deployments running terrascan in server mode (terrascan server), which binds to 0.0.0.0 with no authentication. Note: Terrascan was archived in August 2023 and no patch will be released.Show less
1Tenable
1Security Center
Jun 17, 2026
Feb 23, 2026
5.7 MEDIUM· v4
6.5 MEDIUM· v3
N/A· v2
An improper access control vulnerability exists where an authenticated user could access areas outside of their authorized scope.
1Tenable
1Security Center
Jun 17, 2026
Feb 23, 2026
2.1 LOW· v4
8.8 HIGH· v3
N/A· v2
An Indirect Object Reference (IDOR) in Security Center allows an authenticated remote attacker to escalate privileges via the 'owner' parameter.
1Tenable
1Nessus Agent
Jun 17, 2026
Feb 13, 2026
5.4 MEDIUM· v4
6.1 MEDIUM· v3
N/A· v2
A vulnerability has been identified where weak file permissions in the Nessus Agent directory on Windows hosts could allow unauthorized access, potentially permitting Denial of Service (DoS) attacks.
1Tenable
1Nessus
Jun 17, 2026
Jul 2, 2025
N/A· v4
7.1 HIGH· v3
N/A· v2
In Tenable Nessus versions prior to 10.8.5 on a Windows host, it was found that a non-administrative user could overwrite arbitrary local system files with log content at SYSTEM privilege.
1Tenable
1Nessus Agent
Jun 17, 2026
Jun 16, 2025
N/A· v4
7.8 HIGH· v3
N/A· v2
In Tenable Agent versions prior to 10.8.5 on a Windows host, it was found that a non-administrative user could execute code with SYSTEM privilege.
1Tenable
1Nessus Agent
Jun 17, 2026
Jun 13, 2025
N/A· v4
7.8 HIGH· v3
N/A· v2
In Tenable Agent versions prior to 10.8.5 on a Windows host, it was found that a non-administrative user could arbitrarily delete local system files with SYSTEM privilege, potentially leading to local privilege escalatio...Show more
In Tenable Agent versions prior to 10.8.5 on a Windows host, it was found that a non-administrative user could arbitrarily delete local system files with SYSTEM privilege, potentially leading to local privilege escalation.Show less
1Tenable
1Nessus Agent
Jun 17, 2026
Jun 13, 2025
N/A· v4
7.8 HIGH· v3
N/A· v2
In Tenable Agent versions prior to 10.8.5 on a Windows host, it was found that a non-administrative user could overwrite arbitrary local system files with log content at SYSTEM privilege.
1Tenable
1Nessus Network Monitor
Jun 17, 2026
May 23, 2025
N/A· v4
7.8 HIGH· v3
N/A· v2
In Tenable Network Monitor versions prior to 6.5.1 on a Windows host, it was found that a non-administrative user could stage files in a local directory to run arbitrary code with SYSTEM privileges, potentially leading t...Show more
In Tenable Network Monitor versions prior to 6.5.1 on a Windows host, it was found that a non-administrative user could stage files in a local directory to run arbitrary code with SYSTEM privileges, potentially leading to local privilege escalation.Show less
1Tenable
1Nessus Network Monitor
Jun 17, 2026
May 23, 2025
N/A· v4
7.8 HIGH· v3
N/A· v2
When installing Tenable Network Monitor to a non-default location on a Windows host, Tenable Network Monitor versions prior to 6.5.1 did not enforce secure permissions for sub-directories. This could allow for local priv...Show more
When installing Tenable Network Monitor to a non-default location on a Windows host, Tenable Network Monitor versions prior to 6.5.1 did not enforce secure permissions for sub-directories. This could allow for local privilege escalation if users had not secured the directories in the non-default installation location.Show less
1Tenable
1Nessus Network Monitor
Jun 17, 2026
Sep 30, 2024
N/A· v4
4.6 MEDIUM· v3
N/A· v2
A stored cross site scripting vulnerability exists in Nessus Network Monitor where an authenticated, privileged local attacker could inject arbitrary code into the NNM UI via the local CLI.
1Tenable
1Identity Exposure
Jun 17, 2026
Jul 16, 2024
N/A· v4
6.8 MEDIUM· v3
N/A· v2
A formula injection vulnerability exists in Tenable Identity Exposure where an authenticated remote attacker with administrative privileges could manipulate application form fields in order to trick another administrator...Show more
A formula injection vulnerability exists in Tenable Identity Exposure where an authenticated remote attacker with administrative privileges could manipulate application form fields in order to trick another administrator into executing CSV payloads. - CVE-2024-3232Show less
1Tenable
1Security Center
Jun 17, 2026
Jun 12, 2024
N/A· v4
6.3 MEDIUM· v3
N/A· v2
An improper privilege management vulnerability exists in Tenable Security Center where an authenticated, remote attacker could view unauthorized objects and launch scans without having the required privileges
1Tenable
1Security Center
Jun 17, 2026
Jun 12, 2024
N/A· v4
5.4 MEDIUM· v3
N/A· v2
A stored cross site scripting vulnerability exists in Tenable Security Center where an authenticated, remote attacker could inject HTML code into a web application scan result page.
1Tenable
1Identity Exposure
Jun 17, 2026
Feb 23, 2024
N/A· v4
7.3 HIGH· v3
N/A· v2
A DLL injection vulnerability exists where an authenticated, low-privileged local attacker could modify application files on the TIE Secure Relay host, which could allow for overriding of the configuration and running o...Show more
A DLL injection vulnerability exists where an authenticated, low-privileged local attacker could modify application files on the TIE Secure Relay host, which could allow for overriding of the configuration and running of new Secure Relay services. Show less
1Tenable
1Security Center
Jun 17, 2026
Feb 14, 2024
N/A· v4
4.8 MEDIUM· v3
N/A· v2
An HTML injection vulnerability exists where an authenticated, remote attacker with administrator privileges on the Security Center application could modify Repository parameters, which could lead to HTML redirection at...Show more
An HTML injection vulnerability exists where an authenticated, remote attacker with administrator privileges on the Security Center application could modify Repository parameters, which could lead to HTML redirection attacks.Show less