Vulnerability index

Browse CVEs

87 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.5 CVE-2023-3252 An arbitrary file write vulnerability exists where an authenticated, remote attacker with administrator privileges could alter logging variables to o… Nessus 10.6.0+ Fix from $1,6002023-08-29 HIGH 8.8 CVE-2023-2005 Vulnerability in Tenable Tenable.Io, Tenable Nessus, Tenable Security Center.This issue affects Tenable.Io: before Plugin Feed ID #202306261202 ; Nes… Nessus Mitigation only Fix from $1,9502023-06-26 HIGH 8.8 CVE-2022-4313 A vulnerability was reported where through modifying the scan variables, an authenticated user in Tenable products, that has Scan Policy Configuratio… Nessus 10.4.2 / 202212081952+ Fix from $1,9502023-03-15 HIGH 8.8 CVE-2023-0524 As part of our Security Development Lifecycle, a potential privilege escalation issue was identified internally. This could allow a malicious actor w… Nessus Mitigation only Fix from $1,9502023-02-01 MEDIUM 6.5 CVE-2023-24495 A Server Side Request Forgery (SSRF) vulnerability exists in Tenable.sc due to improper validation of session & user-accessible input data. A privile… Tenable.sc after 5.23.1 Fix from $1,6002023-01-26 MEDIUM 5.7 CVE-2023-24493 A formula injection vulnerability exists in Tenable.sc due to improper validation of user-supplied input before returning it to users. An authenticat… Tenable.sc after 5.23.1 Fix from $1,6002023-01-26 MEDIUM 5.4 CVE-2023-24494 A stored cross-site scripting (XSS) vulnerability exists in Tenable.sc due to improper validation of user-supplied input before returning it to users… Tenable.sc after 5.23.1 Fix from $1,6002023-01-26 MEDIUM 6.5 CVE-2023-0476 A LDAP injection vulnerability exists in Tenable.sc due to improper validation of user-supplied input before returning it to users. An authenticated … Tenable.sc after 5.23.1 Fix from $1,6002023-01-26 HIGH 8.8 CVE-2023-0101 A privilege escalation vulnerability was identified in Nessus versions 8.10.1 through 8.15.8 and 10.0.0 through 10.4.1. An authenticated attacker cou… Nessus 8.15.8 / 10.4.2+ Fix from $1,9502023-01-20 MEDIUM 6.5 CVE-2022-3499 An authenticated attacker could utilize the identical agent and cluster node linking keys to potentially allow for a scenario where unauthorized disc… Nessus 10.4.0+ Fix from $1,6002022-10-31 MEDIUM 6.5 CVE-2022-33757 An authenticated attacker could read Nessus Debug Log file attachments from the web UI without having the correct privileges to do so. This may lead … Nessus 10.2.0+ Fix from $1,6002022-10-25 MEDIUM 6.5 CVE-2022-28291 Insufficiently Protected Credentials: An authenticated user with debug privileges can retrieve stored Nessus policy credentials from the “nessusd” pr… Nessus No fix yet Fix from $1,6002022-10-17 HIGH 8.8 CVE-2022-32973 An authenticated attacker could create an audit file that bypasses PowerShell cmdlet checks and executes commands with administrator privileges. Nessus 10.2.0+ Fix from $1,9502022-06-21 MEDIUM 6.5 CVE-2022-32974 An authenticated attacker could read arbitrary files from the underlying operating system of the scanner using a custom crafted compliance audit file… Nessus 10.2.0+ Fix from $1,6002022-06-21 HIGH 8.1 CVE-2022-0130 Tenable.sc versions 5.14.0 through 5.19.1 were found to contain a remote code execution vulnerability which could allow a remote, unauthenticated att… Tenable.sc after 5.19.1 Fix from $1,9502022-01-14 MEDIUM 6.7 CVE-2021-20135 Nessus versions 8.15.2 and earlier were found to contain a local privilege escalation vulnerability which could allow an authenticated, local adminis… Nessus after 8.15.2 Fix from $1,6002021-11-03 MEDIUM 6.7 CVE-2021-20118 Nessus Agent 8.3.0 and earlier was found to contain a local privilege escalation vulnerability which could allow an authenticated, local administrato… Nessus Agent after 8.3.0 Fix from $1,6002021-09-09 MEDIUM 6.7 CVE-2021-20117 Nessus Agent 8.3.0 and earlier was found to contain a local privilege escalation vulnerability which could allow an authenticated, local administrato… Nessus Agent after 8.3.0 Fix from $1,6002021-09-09 MEDIUM 6.5 CVE-2021-20106 Nessus Agent versions 8.2.5 and earlier were found to contain a privilege escalation vulnerability which could allow a Nessus administrator user to u… Nessus after 8.2.5 Fix from $1,6002021-07-21 MEDIUM 6.7 CVE-2021-20079 Nessus versions 8.13.2 and earlier were found to contain a privilege escalation vulnerability which could allow a Nessus administrator user to upload… Nessus after 8.13.2 Fix from $1,6002021-06-29 MEDIUM 6.7 CVE-2021-20099 Nessus Agent 8.2.4 and earlier for Windows were found to contain multiple local privilege escalation vulnerabilities which could allow an authenticat… Nessus after 8.2.4 Fix from $1,6002021-06-28 MEDIUM 6.7 CVE-2021-20100 Nessus Agent 8.2.4 and earlier for Windows were found to contain multiple local privilege escalation vulnerabilities which could allow an authenticat… Nessus 8.2.5+ Fix from $1,6002021-06-28 MEDIUM 6.7 CVE-2021-20077 Nessus Agent versions 7.2.0 through 8.2.2 were found to inadvertently capture the IAM role security token on the local host during initial linking of… Nessus Agent 8.2.3+ Fix from $1,6002021-03-19 HIGH 8.6 CVE-2021-21371 Tenable for Jira Cloud is an open source project designed to pull Tenable.io vulnerability data, then generate Jira Tasks and sub-tasks based on the … Jira Cloud 1.1.21+ Fix from $1,9502021-03-10 HIGH 8.8 CVE-2021-20076 Tenable.sc and Tenable.sc Core versions 5.13.0 through 5.17.0 were found to contain a vulnerability that could allow an authenticated, unprivileged u… Tenable.sc after 5.17.0 Fix from $1,9502021-03-03 MEDIUM 5.9 CVE-2020-5812 Nessus AMI versions 8.12.0 and earlier were found to either not validate, or incorrectly validate, a certificate which could allow an attacker to spo… Nessus Amazon Machine Image after 8.12.0 Fix from $1,6002021-02-06 HIGH 7.5 CVE-2020-5808 In certain scenarios in Tenable.sc prior to 5.17.0, a scanner could potentially be used outside the user's defined scan zone without a particular zon… Tenable.sc 5.17.0+ Fix from $1,9502020-12-21 HIGH 7.8 CVE-2020-5794 A vulnerability in Nessus Network Monitor versions 5.11.0, 5.11.1, and 5.12.0 for Windows could allow an authenticated local attacker to execute arbi… Nessus Network Monitor Mitigation only Fix from $1,9502020-11-06 HIGH 7.8 CVE-2020-5793 A vulnerability in Nessus versions 8.9.0 through 8.12.0 for Windows & Nessus Agent 8.0.0 and 8.1.0 for Windows could allow an authenticated local att… Nessus after 8.12.0 Fix from $1,9502020-11-05 HIGH 7.1 CVE-2020-5774 Nessus versions 8.11.0 and earlier were found to maintain sessions longer than the permitted period in certain scenarios. The lack of proper session … Nessus after 8.11.0 Fix from $1,9502020-08-21