Tenable
tenable
160 CVEs • 16 products
Products (16)
Click to collapseToggle
Products (16)
Click to collapse
CVEs (160)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
An authenticated attacker could utilize the identical agent and cluster node linking keys to potentially allow for a scenario where unauthorized disclosure of agent logs and data is present. |
An authenticated attacker could read Nessus Debug Log file attachments from the web UI without having the correct privileges to do so. This may lead to the disclosure of information on the scan target and/or the Nessus s...Show more |
Insufficiently Protected Credentials: An authenticated user with debug privileges can retrieve stored Nessus policy credentials from the “nessusd” process in cleartext via process dumping. The affected products are all v...Show more |
An authenticated attacker could read arbitrary files from the underlying operating system of the scanner using a custom crafted compliance audit file without providing any valid SSH credentials. |
An authenticated attacker could create an audit file that bypasses PowerShell cmdlet checks and executes commands with administrator privileges. |
3Fedoraproject GetcomposerTenable3Composer FedoraTenable.scJun 17, 2026 Apr 13, 2022 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Composer is a dependency manager for the PHP programming language. Integrators using Composer code to call `VcsDriver::getFileContent` can have a code injection vulnerability if the user can control the `$file` or `$iden...Show more |
5Debian FedoraprojectMomentjs+2 more5Active Iq Debian LinuxFedora+2 moreJun 17, 2026 Apr 4, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Moment.js is a JavaScript date library for parsing, validating, manipulating, and formatting dates. A path traversal vulnerability impacts npm (server) users of Moment.js between versions 1.0.1 and 2.29.1, especially if...Show more |
7Debian FedoraprojectMariadb+4 more13500f Firmware A250 FirmwareCloud Volumes Ontap Mediator+10 moreJun 17, 2026 Mar 15, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The BN_mod_sqrt() function, which computes a modular square root, contains a bug that can cause it to loop forever for non-prime moduli. Internally this function is used when parsing certificates that contain elliptic cu...Show more |
6Debian FedoraprojectLibexpat Project+3 more6Communications Metasolv Solution Debian LinuxFedora+3 moreJun 17, 2026 Jan 26, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Expat (aka libexpat) before 2.4.4 has an integer overflow in the doProlog function. |
6Debian Libexpat ProjectNetapp+3 more7Clustered Data Ontap Communications Metasolv SolutionDebian Linux+4 moreJun 17, 2026 Jan 24, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Expat (aka libexpat) before 2.4.4 has a signed integer overflow in XML_GetBuffer, for configurations with a nonzero XML_CONTEXT_BYTES. |
Tenable.sc versions 5.14.0 through 5.19.1 were found to contain a remote code execution vulnerability which could allow a remote, unauthenticated attacker to execute code under special circumstances. An attacker would fi...Show more |
4Debian Libexpat ProjectSiemens+1 more4Debian Linux LibexpatNessus+1 moreJun 17, 2026 Jan 10, 2022 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 storeAtts in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow. |
4Debian Libexpat ProjectSiemens+1 more4Debian Linux LibexpatNessus+1 moreJun 17, 2026 Jan 10, 2022 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 nextScaffoldPart in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow. |
4Debian Libexpat ProjectSiemens+1 more4Debian Linux LibexpatNessus+1 moreJun 17, 2026 Jan 10, 2022 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 lookup in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow. |
4Debian Libexpat ProjectSiemens+1 more4Debian Linux LibexpatNessus+1 moreJun 17, 2026 Jan 10, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 defineAttribute in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow. |
4Debian Libexpat ProjectSiemens+1 more4Debian Linux LibexpatNessus+1 moreJun 17, 2026 Jan 10, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 build_model in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow. |
4Debian Libexpat ProjectSiemens+1 more4Debian Linux LibexpatNessus+1 moreJun 17, 2026 Jan 10, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 addBinding in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow. |
4Libexpat Project NetappSiemens+1 more8Active Iq Unified Manager Clustered Data OntapHci Baseboard Management Controller+5 moreJun 17, 2026 Jan 6, 2022 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 In doProlog in xmlparse.c in Expat (aka libexpat) before 2.4.3, an integer overflow exists for m_groupSize. |
5Debian Libexpat ProjectNetapp+2 more8Active Iq Unified Manager Debian LinuxHci Baseboard Management Controller+5 moreJun 17, 2026 Jan 1, 2022 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 In Expat (aka libexpat) before 2.4.3, a left shift by 29 (or more) places in the storeAtts function in xmlparse.c can lead to realloc misbehavior (e.g., allocating too few bytes, or only freeing memory). |
7Apache AppleDebian+4 more14Cloud Backup Communications Element ManagerCommunications Operations Monitor+11 moreJun 17, 2026 Dec 20, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A carefully crafted request body can cause a buffer overflow in the mod_lua multipart parser (r:parsebody() called from Lua scripts). The Apache httpd team is not aware of an exploit for the vulnerabilty though it might...Show more |