Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
HIGH 8.8
CVE-2026-64881
The audit file upload handler does not sanitize filenames, allowing shell metacharacters to flow into system command execution. This input validation…
Security Center
No fix yet
CRITICAL 9.9
CVE-2026-64878
Unvalidated input in asset filter parameters allows shell metacharacters to escape command argument handling, resulting in remote code execution as a…
Security Center
No fix yet
CRITICAL 9.9
CVE-2026-64879
A filename supplied during file upload is not properly sanitized before being used in system command execution, allowing an attacker to inject shell …
Security Center
No fix yet
HIGH 7.1
CVE-2026-64880
Unsanitized user-supplied input in report filtering parameters is concatenated directly into SQL queries without proper escaping or parameterized que…
Security Center
No fix yet
HIGH 8.4
CVE-2026-64877
An authenticated non-admin user can exploit a SQL injection flaw in the ticketing REST API to access sensitive data stored in the appliance database.
Security Center
Mitigation only
MEDIUM 5.3
CVE-2026-57587
A SQL injection vulnerability in Nessus allows a remote, unauthenticated attacker who controls reverse DNS records for a scanned host to inject malic…
Nessus
10.12.1+
HIGH 8.6
CVE-2026-47358
Terrascan v1.18.3 and prior are vulnerable to Server-Side Request Forgery (SSRF) via external URL resolution in uploaded IaC templates when running i…
Terrascan
after 1.18.3
HIGH 8.6
CVE-2026-47356
Terrascan v1.18.3 and prior are vulnerable to Server-Side Request Forgery (SSRF) via the webhook_url parameter in the file scan endpoint (POST /v1/{i…
Terrascan
after 1.18.3
HIGH 8.6
CVE-2026-47357
Terrascan v1.18.3 and prior are vulnerable to Server-Side Request Forgery (SSRF) via the remote_url parameter in the remote directory scan endpoint (…
Terrascan
after 1.18.3
MEDIUM 6.5
CVE-2026-2698
An improper access control vulnerability exists where an authenticated user could access areas outside of their authorized scope.
Security Center
6.8.0+
HIGH 8.8
CVE-2026-2697
An Indirect Object Reference (IDOR) in Security Center allows an authenticated remote attacker to escalate privileges via the 'owner' parameter.
Security Center
6.8.0+
MEDIUM 6.1
CVE-2026-2026
A vulnerability has been identified where weak file permissions in the Nessus Agent directory on Windows hosts could allow unauthorized access, poten…
Nessus Agent
11.0.4 / 11.1.2+
HIGH 7.1
CVE-2025-36630
In Tenable Nessus versions prior to 10.8.5 on a Windows host, it was found that a non-administrative user could overwrite arbitrary local system file…
Nessus
10.8.5+
HIGH 7.8
CVE-2025-36632
In Tenable Agent versions prior to 10.8.5 on a Windows host, it was found that a non-administrative user could execute code with SYSTEM privilege.
Nessus Agent
10.8.5+
HIGH 7.8
CVE-2025-36633
In Tenable Agent versions prior to 10.8.5 on a Windows host, it was found that a non-administrative user could arbitrarily delete local system files …
Nessus Agent
10.8.5+
HIGH 7.8
CVE-2025-36631
In Tenable Agent versions prior to 10.8.5 on a Windows host, it was found that a non-administrative user could overwrite arbitrary local system files…
Nessus Agent
10.8.5+
HIGH 7.8
CVE-2025-24917
In Tenable Network Monitor versions prior to 6.5.1 on a Windows host, it was found that a non-administrative user could stage files in a local direct…
Nessus Network Monitor
6.5.1+
HIGH 7.8
CVE-2025-24916
When installing Tenable Network Monitor to a non-default location on a Windows host, Tenable Network Monitor versions prior to 6.5.1 did not enforce …
Nessus Network Monitor
6.5.1+
MEDIUM 6.8
CVE-2024-3232
A formula injection vulnerability exists in Tenable Identity Exposure where an authenticated remote attacker with administrative privileges could man…
Identity Exposure
3.59.4+
MEDIUM 6.3
CVE-2024-5759
An improper privilege management vulnerability exists in Tenable Security Center where an authenticated, remote attacker could view unauthorized obje…
Security Center
after 6.3.0
MEDIUM 5.4
CVE-2024-1891
A stored cross site scripting vulnerability exists in Tenable Security Center where an authenticated, remote attacker could inject HTML code into a w…
Security Center
6.4.0+
HIGH 7.3
CVE-2024-1683
A DLL injection vulnerability exists where an authenticated, low-privileged local attacker could modify application files on the TIE Secure Relay hos…
Identity Exposure
3.59.4+
HIGH 7.2
CVE-2024-1367
A command injection vulnerability exists where an authenticated, remote attacker with administrator privileges on the Security Center application cou…
Security Center
6.3.0+
MEDIUM 6.5
CVE-2024-0971
A SQL injection vulnerability exists where an authenticated, low-privileged remote attacker could potentially alter scan DB content.
Nessus
10.7.0+
MEDIUM 6.5
CVE-2023-6062
An arbitrary file write vulnerability exists where an authenticated, remote attacker with administrator privileges on the Nessus application could al…
Nessus
10.5.7 / 10.6.3+
MEDIUM 6.5
CVE-2023-6178
An arbitrary file write vulnerability exists where an authenticated attacker with privileges on the managing application could alter Nessus Rules var…
Nessus
10.4.4+
HIGH 7.3
CVE-2023-5847
Under certain conditions, a low privileged attacker could load a specially crafted file during installation or upgrade to escalate privileges on Wind…
Nessus
10.4.3 / 10.6.2+
HIGH 8.8
CVE-2023-5622
Under certain conditions, Nessus Network Monitor could allow a low privileged user to escalate privileges to NT AUTHORITY\SYSTEM on Windows hosts by …
Nessus Network Monitor
6.3.0+
HIGH 7.8
CVE-2023-5623
NNM failed to properly set ACLs on its installation directory, which could allow a low privileged user to run arbitrary code with SYSTEM privileges w…
Nessus Network Monitor
6.3.0+
HIGH 7.2
CVE-2023-5624
Under certain conditions, Nessus Network Monitor was found to not properly enforce input validation. This could allow an admin user to alter paramete…
Nessus Network Monitor
6.3.0+