← Back

Tenable

tenable

160 CVEs • 16 products

Products (16)

Click to collapse
Toggle
Nessus
nessus
Tenable.sc
tenable.sc
Nessus Agent
nessus_agent
Appliance
appliance
Terrascan
terrascan
Web Ui
web_ui
Tenable.io
tenable.io
Plugin Set
plugin-set
Jira Cloud
jira_cloud
Plugin Feed
plugin_feed

CVEs (160)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
2Momentjs
Tenable
2Moment
Nessus
Nov 21, 2024
Mar 4, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The moment module before 2.19.3 for Node.js is prone to a regular expression denial of service via a crafted date string, a different vulnerability than CVE-2016-4055.
1Tenable
1Securitycenter
May 13, 2026
Nov 2, 2017
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
SecurityCenter versions 5.5.0, 5.5.1 and 5.5.2 contain a SQL Injection vulnerability that could be exploited by an authenticated user with sufficient privileges to run diagnostic scans. An attacker could exploit this vul...Show more
SecurityCenter versions 5.5.0, 5.5.1 and 5.5.2 contain a SQL Injection vulnerability that could be exploited by an authenticated user with sufficient privileges to run diagnostic scans. An attacker could exploit this vulnerability by entering a crafted SQL query into the password field of a diagnostic scan within SecurityCenter. Successful exploitation of this vulnerability could allow an attacker to gain unauthorized access.Show less
1Tenable
1Nessus
May 13, 2026
Aug 9, 2017
N/A· v4
7.4 HIGH· v3
5.8 MEDIUM· v2
When linking a Nessus scanner or agent to Tenable.io or other manager, Nessus 6.x before 6.11 does not verify the manager's TLS certificate when making the initial outgoing connection. This could allow man-in-the-middle...Show more
When linking a Nessus scanner or agent to Tenable.io or other manager, Nessus 6.x before 6.11 does not verify the manager's TLS certificate when making the initial outgoing connection. This could allow man-in-the-middle attacks.Show less
1Tenable
1Nessus
May 13, 2026
May 12, 2017
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Cross-site scripting vulnerability in Nessus versions 6.8.0, 6.8.1, 6.9.0, 6.9.1 and 6.9.2 allows remote authenticated attackers to inject arbitrary web script or HTML via unspecified vectors.
1Tenable
1Appliance
May 13, 2026
Apr 21, 2017
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Tenable Appliance 3.5 - 4.4.0, and possibly prior versions, contains a flaw in the simpleupload.py script in the Web UI. Through the manipulation of the tns_appliance_session_user parameter, a remote attacker can inject...Show more
Tenable Appliance 3.5 - 4.4.0, and possibly prior versions, contains a flaw in the simpleupload.py script in the Web UI. Through the manipulation of the tns_appliance_session_user parameter, a remote attacker can inject arbitrary commands.Show less
1Tenable
1Appliance
May 13, 2026
Apr 21, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Tenable Appliance 4.4.0, and possibly prior, contains a flaw in the Web UI that allows for the unauthorized manipulation of the admin password.
1Tenable
1Nessus
May 13, 2026
Apr 19, 2017
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
Nessus 6.10.x before 6.10.5 was found to be vulnerable to a local privilege escalation issue due to insecure permissions when running in Agent Mode.
1Tenable
1Nessus
May 13, 2026
Apr 19, 2017
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
Nessus 6.10.x before 6.10.5 was found to be vulnerable to a local denial of service condition due to insecure permissions when running in Agent Mode.
1Tenable
1Nessus
May 13, 2026
Mar 23, 2017
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
Nessus 6.6.2 - 6.10.3 contains a flaw related to insecure permissions that may allow a local attacker to escalate privileges when the software is running in Agent Mode. Version 6.10.4 fixes this issue.
1Tenable
2Appliance
Nessus
May 13, 2026
Mar 8, 2017
N/A· v4
7.3 HIGH· v3
6.0 MEDIUM· v2
Tenable Nessus before 6.10.2 (as used alone or in Tenable Appliance before 4.5.0) was found to contain a flaw that allowed a remote, authenticated attacker to upload a crafted file that could be written to anywhere on th...Show more
Tenable Nessus before 6.10.2 (as used alone or in Tenable Appliance before 4.5.0) was found to contain a flaw that allowed a remote, authenticated attacker to upload a crafted file that could be written to anywhere on the system. This could be used to subsequently gain elevated privileges on the system (e.g., after a reboot). This issue only affects installations on Windows.Show less
1Tenable
1Log Correlation Engine
May 13, 2026
Feb 28, 2017
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Cross-site scripting (XSS) vulnerability in Tenable Log Correlation Engine (aka LCE) before 4.8.1 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
1Tenable
1Nessus
May 13, 2026
Feb 28, 2017
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Cross-site scripting (XSS) vulnerability in Tenable Nessus before 6.9.1 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
1Tenable
1Nessus
May 13, 2026
Jan 31, 2017
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Cross-site scripting (XSS) vulnerability in Tenable Nessus before 6.9 allows remote authenticated users to inject arbitrary web script or HTML via vectors related to handling of .nessus files.
3Momentjs
OracleTenable
3Moment
NessusPrimavera Unifier
May 13, 2026
Jan 23, 2017
N/A· v4
6.5 MEDIUM· v3
7.8 HIGH· v2
The duration function in the moment package before 2.11.2 for Node.js allows remote attackers to cause a denial of service (CPU consumption) via a long string, aka a "regular expression Denial of Service (ReDoS)."
1Tenable
1Nessus
May 6, 2026
Jan 5, 2017
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Cross-site scripting (XSS) vulnerability in Tenable Nessus before 6.9.3 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
8Apple
HpMcafee+5 more
19Enterprise Linux Desktop
Enterprise Linux ServerEnterprise Linux Server Aus+16 more
May 6, 2026
Jun 9, 2016
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Format string vulnerability in libxml2 before 2.9.4 allows attackers to have unspecified impact via format string specifiers in unknown vectors.
1Tenable
1Web Ui
May 6, 2026
Oct 21, 2014
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in the Web UI before 2.3.4 Build #85 for Tenable Nessus 5.x allows remote web servers to inject arbitrary web script or HTML via the server header.
1Tenable
2Nessus
Web Ui
May 6, 2026
Jul 23, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The /server/properties resource in Tenable Web UI before 2.3.5 for Nessus 5.2.3 through 5.2.7 allows remote attackers to obtain sensitive information via the token parameter.
1Tenable
2Nessus
Plugin Set
May 6, 2026
Apr 11, 2014
N/A· v4
N/A· v3
6.9 MEDIUM· v2
A race condition in the wmi_malware_scan.nbin plugin before 201402262215 for Nessus 5.2.1 allows local users to gain privileges by replacing the dissolvable agent executable in the Windows temp directory with a Trojan ho...Show more
A race condition in the wmi_malware_scan.nbin plugin before 201402262215 for Nessus 5.2.1 allows local users to gain privileges by replacing the dissolvable agent executable in the Windows temp directory with a Trojan horse program.Show less
1Tenable
1Securitycenter
Apr 29, 2026
Sep 24, 2013
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in devform.php in Tenable SecurityCenter 4.6 through 4.7 allows remote attackers to inject arbitrary web script or HTML via the message parameter.