Vulnerability index

Browse CVEs

87 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 5.4 CVE-2020-5765 Nessus 8.10.0 and earlier were found to contain a Stored XSS vulnerability due to improper validation of input during scan configuration. An authenti… Nessus after 8.10.0 Fix from $1,6002020-07-15 MEDIUM 5.4 CVE-2020-5737 Stored XSS in Tenable.Sc before 5.14.0 could allow an authenticated remote attacker to craft a request to execute arbitrary script code in a user's b… Tenable.sc Patch available Fix from $1,6002020-04-17 MEDIUM 6.5 CVE-2019-3982 Nessus versions 8.6.0 and earlier were found to contain a Denial of Service vulnerability due to improper validation of specific imported scan types.… Nessus after 8.6.0 Fix from $1,6002019-10-23 HIGH 8.1 CVE-2019-3974 Nessus 8.5.2 and earlier on Windows platforms were found to contain an issue where certain system files could be overwritten arbitrarily, potentially… Nessus after 8.5.2 Fix from $1,9502019-08-15 MEDIUM 6.1 CVE-2019-3961 Nessus versions 8.4.0 and earlier were found to contain a reflected XSS vulnerability due to improper validation of user-supplied input. An unauthent… Nessus after 8.4.0 Fix from $1,6002019-06-25 MEDIUM 5.4 CVE-2019-3923 Nessus versions 8.2.1 and earlier were found to contain a stored XSS vulnerability due to improper validation of user-supplied input. An authenticate… Nessus after 8.2.1 Fix from $1,6002019-02-12 HIGH 8.8 CVE-2018-1154 In SecurityCenter versions prior to 5.7.0, a username enumeration issue could allow an unauthenticated attacker to automate the discovery of username… Security Center 5.7.0+ Fix from $1,9502018-08-02 MEDIUM 5.4 CVE-2018-1155 In SecurityCenter versions prior to 5.7.0, a cross-site scripting (XSS) issue could allow an authenticated attacker to inject JavaScript code into an… Security Center 5.7.0+ Fix from $1,6002018-08-02 MEDIUM 6.5 CVE-2018-1148 In Nessus before 7.1.0, Session Fixation exists due to insufficient session management within the application. An authenticated attacker could mainta… Nessus 7.1.0+ Fix from $1,6002018-05-18 MEDIUM 5.4 CVE-2018-1147 In Nessus before 7.1.0, a XSS vulnerability exists due to improper input validation. A remote authenticated attacker could create and upload a .nessu… Nessus 7.1.0+ Fix from $1,6002018-05-18 MEDIUM 5.4 CVE-2018-1142 Tenable Appliance versions 4.6.1 and earlier have been found to contain a single XSS vulnerability. Utilizing a specially crafted request, an authent… Appliance after 4.6.1 Fix from $1,6002018-03-28 HIGH 7.0 CVE-2018-1141 When installing Nessus to a directory outside of the default location, Nessus versions prior to 7.0.3 did not enforce secure permissions for sub-dire… Nessus 7.0.3+ Fix from $1,9502018-03-20 HIGH 8.8 CVE-2017-11508 SecurityCenter versions 5.5.0, 5.5.1 and 5.5.2 contain a SQL Injection vulnerability that could be exploited by an authenticated user with sufficient… Security Center Mitigation only Fix from $1,9502017-11-02 HIGH 7.4 CVE-2017-11506 When linking a Nessus scanner or agent to Tenable.io or other manager, Nessus 6.x before 6.11 does not verify the manager's TLS certificate when maki… Nessus Mitigation only Fix from $1,9502017-08-09 MEDIUM 5.4 CVE-2017-2122 Cross-site scripting vulnerability in Nessus versions 6.8.0, 6.8.1, 6.9.0, 6.9.1 and 6.9.2 allows remote authenticated attackers to inject arbitrary … Nessus Patch available Fix from $1,6002017-05-12 CRITICAL 9.8 CVE-2017-8051EPSS 16% Tenable Appliance 3.5 - 4.4.0, and possibly prior versions, contains a flaw in the simpleupload.py script in the Web UI. Through the manipulation of … Appliance Patch available Fix from $2,3002017-04-21 HIGH 7.5 CVE-2017-8050 Tenable Appliance 4.4.0, and possibly prior, contains a flaw in the Web UI that allows for the unauthorized manipulation of the admin password. Appliance after 4.4.0 Fix from $1,9502017-04-21 HIGH 7.8 CVE-2017-7850 Nessus 6.10.x before 6.10.5 was found to be vulnerable to a local privilege escalation issue due to insecure permissions when running in Agent Mode. Nessus Mitigation only Fix from $1,9502017-04-19 MEDIUM 5.5 CVE-2017-7849 Nessus 6.10.x before 6.10.5 was found to be vulnerable to a local denial of service condition due to insecure permissions when running in Agent Mode. Nessus Mitigation only Fix from $1,6002017-04-19 HIGH 7.8 CVE-2017-7199 Nessus 6.6.2 - 6.10.3 contains a flaw related to insecure permissions that may allow a local attacker to escalate privileges when the software is run… Nessus Mitigation only Fix from $1,9502017-03-23 HIGH 7.3 CVE-2017-6543 Tenable Nessus before 6.10.2 (as used alone or in Tenable Appliance before 4.5.0) was found to contain a flaw that allowed a remote, authenticated at… Nessus after 6.10.1 Fix from $1,9502017-03-08 MEDIUM 5.4 CVE-2016-9259 Cross-site scripting (XSS) vulnerability in Tenable Nessus before 6.9.1 allows remote authenticated users to inject arbitrary web script or HTML via … Nessus Patch available Fix from $1,6002017-02-28 MEDIUM 5.4 CVE-2016-9261 Cross-site scripting (XSS) vulnerability in Tenable Log Correlation Engine (aka LCE) before 4.8.1 allows remote authenticated users to inject arbitra… Log Correlation Engine after 4.8.0 Fix from $1,6002017-02-28 MEDIUM 5.4 CVE-2016-9260 Cross-site scripting (XSS) vulnerability in Tenable Nessus before 6.9 allows remote authenticated users to inject arbitrary web script or HTML via ve… Nessus after 6.8.1 Fix from $1,6002017-01-31 MEDIUM 5.4 CVE-2017-5179 Cross-site scripting (XSS) vulnerability in Tenable Nessus before 6.9.3 allows remote authenticated users to inject arbitrary web script or HTML via … Nessus after 6.9.2 Fix from $1,6002017-01-05 MEDIUM 5.0 CVE-2014-4980 The /server/properties resource in Tenable Web UI before 2.3.5 for Nessus 5.2.3 through 5.2.7 allows remote attackers to obtain sensitive information… Nessus after 2.3.4 Fix from $1,6002014-07-23 MEDIUM 6.9 CVE-2014-2848 A race condition in the wmi_malware_scan.nbin plugin before 201402262215 for Nessus 5.2.1 allows local users to gain privileges by replacing the diss… Nessus after 201402092115 Fix from $1,6002014-04-11