Vulnerability index

Browse CVEs

87 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Nessus MEDIUM 5.4
CVE-2020-5765

Nessus 8.10.0 and earlier were found to contain a Stored XSS vulnerability due to improper validation of input during scan configuration. An authenti…

Fix: after 8.10.0
Fix from $1,600 2020-07-15
Tenable.sc MEDIUM 5.4
CVE-2020-5737

Stored XSS in Tenable.Sc before 5.14.0 could allow an authenticated remote attacker to craft a request to execute arbitrary script code in a user's b…

Patch available
Fix from $1,600 2020-04-17
Nessus MEDIUM 6.5
CVE-2019-3982

Nessus versions 8.6.0 and earlier were found to contain a Denial of Service vulnerability due to improper validation of specific imported scan types.…

Fix: after 8.6.0
Fix from $1,600 2019-10-23
Nessus HIGH 8.1
CVE-2019-3974

Nessus 8.5.2 and earlier on Windows platforms were found to contain an issue where certain system files could be overwritten arbitrarily, potentially…

Fix: after 8.5.2
Fix from $1,950 2019-08-15
Nessus MEDIUM 6.1
CVE-2019-3961

Nessus versions 8.4.0 and earlier were found to contain a reflected XSS vulnerability due to improper validation of user-supplied input. An unauthent…

Fix: after 8.4.0
Fix from $1,600 2019-06-25
Nessus MEDIUM 5.4
CVE-2019-3923

Nessus versions 8.2.1 and earlier were found to contain a stored XSS vulnerability due to improper validation of user-supplied input. An authenticate…

Fix: after 8.2.1
Fix from $1,600 2019-02-12
Security Center HIGH 8.8
CVE-2018-1154

In SecurityCenter versions prior to 5.7.0, a username enumeration issue could allow an unauthenticated attacker to automate the discovery of username…

Fix: 5.7.0+
Fix from $1,950 2018-08-02
Security Center MEDIUM 5.4
CVE-2018-1155

In SecurityCenter versions prior to 5.7.0, a cross-site scripting (XSS) issue could allow an authenticated attacker to inject JavaScript code into an…

Fix: 5.7.0+
Fix from $1,600 2018-08-02
Nessus MEDIUM 6.5
CVE-2018-1148

In Nessus before 7.1.0, Session Fixation exists due to insufficient session management within the application. An authenticated attacker could mainta…

Fix: 7.1.0+
Fix from $1,600 2018-05-18
Nessus MEDIUM 5.4
CVE-2018-1147

In Nessus before 7.1.0, a XSS vulnerability exists due to improper input validation. A remote authenticated attacker could create and upload a .nessu…

Fix: 7.1.0+
Fix from $1,600 2018-05-18
Appliance MEDIUM 5.4
CVE-2018-1142

Tenable Appliance versions 4.6.1 and earlier have been found to contain a single XSS vulnerability. Utilizing a specially crafted request, an authent…

Fix: after 4.6.1
Fix from $1,600 2018-03-28
Nessus HIGH 7.0
CVE-2018-1141

When installing Nessus to a directory outside of the default location, Nessus versions prior to 7.0.3 did not enforce secure permissions for sub-dire…

Fix: 7.0.3+
Fix from $1,950 2018-03-20
Security Center HIGH 8.8
CVE-2017-11508

SecurityCenter versions 5.5.0, 5.5.1 and 5.5.2 contain a SQL Injection vulnerability that could be exploited by an authenticated user with sufficient…

Mitigation only
Fix from $1,950 2017-11-02
Nessus HIGH 7.4
CVE-2017-11506

When linking a Nessus scanner or agent to Tenable.io or other manager, Nessus 6.x before 6.11 does not verify the manager's TLS certificate when maki…

Mitigation only
Fix from $1,950 2017-08-09
Nessus MEDIUM 5.4
CVE-2017-2122

Cross-site scripting vulnerability in Nessus versions 6.8.0, 6.8.1, 6.9.0, 6.9.1 and 6.9.2 allows remote authenticated attackers to inject arbitrary …

Patch available
Fix from $1,600 2017-05-12
Appliance CRITICAL 9.8
CVE-2017-8051EPSS 16%

Tenable Appliance 3.5 - 4.4.0, and possibly prior versions, contains a flaw in the simpleupload.py script in the Web UI. Through the manipulation of …

Patch available
Fix from $2,300 2017-04-21
Appliance HIGH 7.5
CVE-2017-8050

Tenable Appliance 4.4.0, and possibly prior, contains a flaw in the Web UI that allows for the unauthorized manipulation of the admin password.

Fix: after 4.4.0
Fix from $1,950 2017-04-21
Nessus HIGH 7.8
CVE-2017-7850

Nessus 6.10.x before 6.10.5 was found to be vulnerable to a local privilege escalation issue due to insecure permissions when running in Agent Mode.

Mitigation only
Fix from $1,950 2017-04-19
Nessus MEDIUM 5.5
CVE-2017-7849

Nessus 6.10.x before 6.10.5 was found to be vulnerable to a local denial of service condition due to insecure permissions when running in Agent Mode.

Mitigation only
Fix from $1,600 2017-04-19
Nessus HIGH 7.8
CVE-2017-7199

Nessus 6.6.2 - 6.10.3 contains a flaw related to insecure permissions that may allow a local attacker to escalate privileges when the software is run…

Mitigation only
Fix from $1,950 2017-03-23
Nessus HIGH 7.3
CVE-2017-6543

Tenable Nessus before 6.10.2 (as used alone or in Tenable Appliance before 4.5.0) was found to contain a flaw that allowed a remote, authenticated at…

Fix: after 6.10.1
Fix from $1,950 2017-03-08
Nessus MEDIUM 5.4
CVE-2016-9259

Cross-site scripting (XSS) vulnerability in Tenable Nessus before 6.9.1 allows remote authenticated users to inject arbitrary web script or HTML via …

Patch available
Fix from $1,600 2017-02-28
Log Correlation Engine MEDIUM 5.4
CVE-2016-9261

Cross-site scripting (XSS) vulnerability in Tenable Log Correlation Engine (aka LCE) before 4.8.1 allows remote authenticated users to inject arbitra…

Fix: after 4.8.0
Fix from $1,600 2017-02-28
Nessus MEDIUM 5.4
CVE-2016-9260

Cross-site scripting (XSS) vulnerability in Tenable Nessus before 6.9 allows remote authenticated users to inject arbitrary web script or HTML via ve…

Fix: after 6.8.1
Fix from $1,600 2017-01-31
Nessus MEDIUM 5.4
CVE-2017-5179

Cross-site scripting (XSS) vulnerability in Tenable Nessus before 6.9.3 allows remote authenticated users to inject arbitrary web script or HTML via …

Fix: after 6.9.2
Fix from $1,600 2017-01-05
Nessus MEDIUM 5.0
CVE-2014-4980

The /server/properties resource in Tenable Web UI before 2.3.5 for Nessus 5.2.3 through 5.2.7 allows remote attackers to obtain sensitive information…

Fix: after 2.3.4
Fix from $1,600 2014-07-23
Nessus MEDIUM 6.9
CVE-2014-2848

A race condition in the wmi_malware_scan.nbin plugin before 201402262215 for Nessus 5.2.1 allows local users to gain privileges by replacing the diss…

Fix: after 201402092115
Fix from $1,600 2014-04-11