Vulnerability index

Browse CVEs

87 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Security Center HIGH 8.8
CVE-2026-64881

The audit file upload handler does not sanitize filenames, allowing shell metacharacters to flow into system command execution. This input validation…

No fix yet
Fix from $1,950 2026-07-21
Security Center CRITICAL 9.9
CVE-2026-64878

Unvalidated input in asset filter parameters allows shell metacharacters to escape command argument handling, resulting in remote code execution as a…

No fix yet
Fix from $2,300 2026-07-21
Security Center CRITICAL 9.9
CVE-2026-64879

A filename supplied during file upload is not properly sanitized before being used in system command execution, allowing an attacker to inject shell …

No fix yet
Fix from $2,300 2026-07-21
Security Center HIGH 7.1
CVE-2026-64880

Unsanitized user-supplied input in report filtering parameters is concatenated directly into SQL queries without proper escaping or parameterized que…

No fix yet
Fix from $1,950 2026-07-21
Security Center HIGH 8.4
CVE-2026-64877

An authenticated non-admin user can exploit a SQL injection flaw in the ticketing REST API to access sensitive data stored in the appliance database.

Mitigation only
Fix from $1,950 2026-07-21
Nessus MEDIUM 5.3
CVE-2026-57587

A SQL injection vulnerability in Nessus allows a remote, unauthenticated attacker who controls reverse DNS records for a scanned host to inject malic…

Fix: 10.12.1+
Fix from $1,600 2026-06-25
Terrascan HIGH 8.6
CVE-2026-47358

Terrascan v1.18.3 and prior are vulnerable to Server-Side Request Forgery (SSRF) via external URL resolution in uploaded IaC templates when running i…

Fix: after 1.18.3
Fix from $1,950 2026-05-19
Terrascan HIGH 8.6
CVE-2026-47356

Terrascan v1.18.3 and prior are vulnerable to Server-Side Request Forgery (SSRF) via the webhook_url parameter in the file scan endpoint (POST /v1/{i…

Fix: after 1.18.3
Fix from $1,950 2026-05-19
Terrascan HIGH 8.6
CVE-2026-47357

Terrascan v1.18.3 and prior are vulnerable to Server-Side Request Forgery (SSRF) via the remote_url parameter in the remote directory scan endpoint (…

Fix: after 1.18.3
Fix from $1,950 2026-05-19
Security Center MEDIUM 6.5
CVE-2026-2698

An improper access control vulnerability exists where an authenticated user could access areas outside of their authorized scope.

Fix: 6.8.0+
Fix from $1,600 2026-02-23
Security Center HIGH 8.8
CVE-2026-2697

An Indirect Object Reference (IDOR) in Security Center allows an authenticated remote attacker to escalate privileges via the 'owner' parameter.

Fix: 6.8.0+
Fix from $1,950 2026-02-23
Nessus Agent MEDIUM 6.1
CVE-2026-2026

A vulnerability has been identified where weak file permissions in the Nessus Agent directory on Windows hosts could allow unauthorized access, poten…

Fix: 11.0.4 / 11.1.2+
Fix from $1,600 2026-02-13
Nessus HIGH 7.1
CVE-2025-36630

In Tenable Nessus versions prior to 10.8.5 on a Windows host, it was found that a non-administrative user could overwrite arbitrary local system file…

Fix: 10.8.5+
Fix from $1,950 2025-07-02
Nessus Agent HIGH 7.8
CVE-2025-36632

In Tenable Agent versions prior to 10.8.5 on a Windows host, it was found that a non-administrative user could execute code with SYSTEM privilege.

Fix: 10.8.5+
Fix from $1,950 2025-06-16
Nessus Agent HIGH 7.8
CVE-2025-36633

In Tenable Agent versions prior to 10.8.5 on a Windows host, it was found that a non-administrative user could arbitrarily delete local system files …

Fix: 10.8.5+
Fix from $1,950 2025-06-13
Nessus Agent HIGH 7.8
CVE-2025-36631

In Tenable Agent versions prior to 10.8.5 on a Windows host, it was found that a non-administrative user could overwrite arbitrary local system files…

Fix: 10.8.5+
Fix from $1,950 2025-06-13
Nessus Network Monitor HIGH 7.8
CVE-2025-24917

In Tenable Network Monitor versions prior to 6.5.1 on a Windows host, it was found that a non-administrative user could stage files in a local direct…

Fix: 6.5.1+
Fix from $1,950 2025-05-23
Nessus Network Monitor HIGH 7.8
CVE-2025-24916

When installing Tenable Network Monitor to a non-default location on a Windows host, Tenable Network Monitor versions prior to 6.5.1 did not enforce …

Fix: 6.5.1+
Fix from $1,950 2025-05-23
Identity Exposure MEDIUM 6.8
CVE-2024-3232

A formula injection vulnerability exists in Tenable Identity Exposure where an authenticated remote attacker with administrative privileges could man…

Fix: 3.59.4+
Fix from $1,600 2024-07-16
Security Center MEDIUM 6.3
CVE-2024-5759

An improper privilege management vulnerability exists in Tenable Security Center where an authenticated, remote attacker could view unauthorized obje…

Fix: after 6.3.0
Fix from $1,600 2024-06-12
Security Center MEDIUM 5.4
CVE-2024-1891

A stored cross site scripting vulnerability exists in Tenable Security Center where an authenticated, remote attacker could inject HTML code into a w…

Fix: 6.4.0+
Fix from $1,600 2024-06-12
Identity Exposure HIGH 7.3
CVE-2024-1683

A DLL injection vulnerability exists where an authenticated, low-privileged local attacker could modify application files on the TIE Secure Relay hos…

Fix: 3.59.4+
Fix from $1,950 2024-02-23
Security Center HIGH 7.2
CVE-2024-1367

A command injection vulnerability exists where an authenticated, remote attacker with administrator privileges on the Security Center application cou…

Fix: 6.3.0+
Fix from $1,950 2024-02-14
Nessus MEDIUM 6.5
CVE-2024-0971

A SQL injection vulnerability exists where an authenticated, low-privileged remote attacker could potentially alter scan DB content.

Fix: 10.7.0+
Fix from $1,600 2024-02-07
Nessus MEDIUM 6.5
CVE-2023-6062

An arbitrary file write vulnerability exists where an authenticated, remote attacker with administrator privileges on the Nessus application could al…

Fix: 10.5.7 / 10.6.3+
Fix from $1,600 2023-11-20
Nessus MEDIUM 6.5
CVE-2023-6178

An arbitrary file write vulnerability exists where an authenticated attacker with privileges on the managing application could alter Nessus Rules var…

Fix: 10.4.4+
Fix from $1,600 2023-11-20
Nessus HIGH 7.3
CVE-2023-5847

Under certain conditions, a low privileged attacker could load a specially crafted file during installation or upgrade to escalate privileges on Wind…

Fix: 10.4.3 / 10.6.2+
Fix from $1,950 2023-11-01
Nessus Network Monitor HIGH 8.8
CVE-2023-5622

Under certain conditions, Nessus Network Monitor could allow a low privileged user to escalate privileges to NT AUTHORITY\SYSTEM on Windows hosts by …

Fix: 6.3.0+
Fix from $1,950 2023-10-26
Nessus Network Monitor HIGH 7.8
CVE-2023-5623

NNM failed to properly set ACLs on its installation directory, which could allow a low privileged user to run arbitrary code with SYSTEM privileges w…

Fix: 6.3.0+
Fix from $1,950 2023-10-26
Nessus Network Monitor HIGH 7.2
CVE-2023-5624

Under certain conditions, Nessus Network Monitor was found to not properly enforce input validation. This could allow an admin user to alter paramete…

Fix: 6.3.0+
Fix from $1,950 2023-10-26