Vulnerability index

Browse CVEs

87 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Nessus MEDIUM 6.5
CVE-2023-3252

An arbitrary file write vulnerability exists where an authenticated, remote attacker with administrator privileges could alter logging variables to o…

Fix: 10.6.0+
Fix from $1,600 2023-08-29
Nessus HIGH 8.8
CVE-2023-2005

Vulnerability in Tenable Tenable.Io, Tenable Nessus, Tenable Security Center.This issue affects Tenable.Io: before Plugin Feed ID #202306261202 ; Nes…

Mitigation only
Fix from $1,950 2023-06-26
Nessus HIGH 8.8
CVE-2022-4313

A vulnerability was reported where through modifying the scan variables, an authenticated user in Tenable products, that has Scan Policy Configuratio…

Fix: 10.4.2 / 202212081952+
Fix from $1,950 2023-03-15
Nessus HIGH 8.8
CVE-2023-0524

As part of our Security Development Lifecycle, a potential privilege escalation issue was identified internally. This could allow a malicious actor w…

Mitigation only
Fix from $1,950 2023-02-01
Tenable.sc MEDIUM 6.5
CVE-2023-24495

A Server Side Request Forgery (SSRF) vulnerability exists in Tenable.sc due to improper validation of session & user-accessible input data. A privile…

Fix: after 5.23.1
Fix from $1,600 2023-01-26
Tenable.sc MEDIUM 5.7
CVE-2023-24493

A formula injection vulnerability exists in Tenable.sc due to improper validation of user-supplied input before returning it to users. An authenticat…

Fix: after 5.23.1
Fix from $1,600 2023-01-26
Tenable.sc MEDIUM 5.4
CVE-2023-24494

A stored cross-site scripting (XSS) vulnerability exists in Tenable.sc due to improper validation of user-supplied input before returning it to users…

Fix: after 5.23.1
Fix from $1,600 2023-01-26
Tenable.sc MEDIUM 6.5
CVE-2023-0476

A LDAP injection vulnerability exists in Tenable.sc due to improper validation of user-supplied input before returning it to users. An authenticated …

Fix: after 5.23.1
Fix from $1,600 2023-01-26
Nessus HIGH 8.8
CVE-2023-0101

A privilege escalation vulnerability was identified in Nessus versions 8.10.1 through 8.15.8 and 10.0.0 through 10.4.1. An authenticated attacker cou…

Fix: 8.15.8 / 10.4.2+
Fix from $1,950 2023-01-20
Nessus MEDIUM 6.5
CVE-2022-3499

An authenticated attacker could utilize the identical agent and cluster node linking keys to potentially allow for a scenario where unauthorized disc…

Fix: 10.4.0+
Fix from $1,600 2022-10-31
Nessus MEDIUM 6.5
CVE-2022-33757

An authenticated attacker could read Nessus Debug Log file attachments from the web UI without having the correct privileges to do so. This may lead …

Fix: 10.2.0+
Fix from $1,600 2022-10-25
Nessus MEDIUM 6.5
CVE-2022-28291

Insufficiently Protected Credentials: An authenticated user with debug privileges can retrieve stored Nessus policy credentials from the “nessusd” pr…

No fix yet
Fix from $1,600 2022-10-17
Nessus HIGH 8.8
CVE-2022-32973

An authenticated attacker could create an audit file that bypasses PowerShell cmdlet checks and executes commands with administrator privileges.

Fix: 10.2.0+
Fix from $1,950 2022-06-21
Nessus MEDIUM 6.5
CVE-2022-32974

An authenticated attacker could read arbitrary files from the underlying operating system of the scanner using a custom crafted compliance audit file…

Fix: 10.2.0+
Fix from $1,600 2022-06-21
Tenable.sc HIGH 8.1
CVE-2022-0130

Tenable.sc versions 5.14.0 through 5.19.1 were found to contain a remote code execution vulnerability which could allow a remote, unauthenticated att…

Fix: after 5.19.1
Fix from $1,950 2022-01-14
Nessus MEDIUM 6.7
CVE-2021-20135

Nessus versions 8.15.2 and earlier were found to contain a local privilege escalation vulnerability which could allow an authenticated, local adminis…

Fix: after 8.15.2
Fix from $1,600 2021-11-03
Nessus Agent MEDIUM 6.7
CVE-2021-20118

Nessus Agent 8.3.0 and earlier was found to contain a local privilege escalation vulnerability which could allow an authenticated, local administrato…

Fix: after 8.3.0
Fix from $1,600 2021-09-09
Nessus Agent MEDIUM 6.7
CVE-2021-20117

Nessus Agent 8.3.0 and earlier was found to contain a local privilege escalation vulnerability which could allow an authenticated, local administrato…

Fix: after 8.3.0
Fix from $1,600 2021-09-09
Nessus MEDIUM 6.5
CVE-2021-20106

Nessus Agent versions 8.2.5 and earlier were found to contain a privilege escalation vulnerability which could allow a Nessus administrator user to u…

Fix: after 8.2.5
Fix from $1,600 2021-07-21
Nessus MEDIUM 6.7
CVE-2021-20079

Nessus versions 8.13.2 and earlier were found to contain a privilege escalation vulnerability which could allow a Nessus administrator user to upload…

Fix: after 8.13.2
Fix from $1,600 2021-06-29
Nessus MEDIUM 6.7
CVE-2021-20099

Nessus Agent 8.2.4 and earlier for Windows were found to contain multiple local privilege escalation vulnerabilities which could allow an authenticat…

Fix: after 8.2.4
Fix from $1,600 2021-06-28
Nessus MEDIUM 6.7
CVE-2021-20100

Nessus Agent 8.2.4 and earlier for Windows were found to contain multiple local privilege escalation vulnerabilities which could allow an authenticat…

Fix: 8.2.5+
Fix from $1,600 2021-06-28
Nessus Agent MEDIUM 6.7
CVE-2021-20077

Nessus Agent versions 7.2.0 through 8.2.2 were found to inadvertently capture the IAM role security token on the local host during initial linking of…

Fix: 8.2.3+
Fix from $1,600 2021-03-19
Jira Cloud HIGH 8.6
CVE-2021-21371

Tenable for Jira Cloud is an open source project designed to pull Tenable.io vulnerability data, then generate Jira Tasks and sub-tasks based on the …

Fix: 1.1.21+
Fix from $1,950 2021-03-10
Tenable.sc HIGH 8.8
CVE-2021-20076

Tenable.sc and Tenable.sc Core versions 5.13.0 through 5.17.0 were found to contain a vulnerability that could allow an authenticated, unprivileged u…

Fix: after 5.17.0
Fix from $1,950 2021-03-03
Nessus Amazon Machine Image MEDIUM 5.9
CVE-2020-5812

Nessus AMI versions 8.12.0 and earlier were found to either not validate, or incorrectly validate, a certificate which could allow an attacker to spo…

Fix: after 8.12.0
Fix from $1,600 2021-02-06
Tenable.sc HIGH 7.5
CVE-2020-5808

In certain scenarios in Tenable.sc prior to 5.17.0, a scanner could potentially be used outside the user's defined scan zone without a particular zon…

Fix: 5.17.0+
Fix from $1,950 2020-12-21
Nessus Network Monitor HIGH 7.8
CVE-2020-5794

A vulnerability in Nessus Network Monitor versions 5.11.0, 5.11.1, and 5.12.0 for Windows could allow an authenticated local attacker to execute arbi…

Mitigation only
Fix from $1,950 2020-11-06
Nessus HIGH 7.8
CVE-2020-5793

A vulnerability in Nessus versions 8.9.0 through 8.12.0 for Windows & Nessus Agent 8.0.0 and 8.1.0 for Windows could allow an authenticated local att…

Fix: after 8.12.0
Fix from $1,950 2020-11-05
Nessus HIGH 7.1
CVE-2020-5774

Nessus versions 8.11.0 and earlier were found to maintain sessions longer than the permitted period in certain scenarios. The lack of proper session …

Fix: after 8.11.0
Fix from $1,950 2020-08-21