The audit file upload handler does not sanitize filenames, allowing shell metacharacters to flow into system command execution. This input validation…
Unvalidated input in asset filter parameters allows shell metacharacters to escape command argument handling, resulting in remote code execution as a…
A filename supplied during file upload is not properly sanitized before being used in system command execution, allowing an attacker to inject shell …
Unsanitized user-supplied input in report filtering parameters is concatenated directly into SQL queries without proper escaping or parameterized que…
An authenticated non-admin user can exploit a SQL injection flaw in the ticketing REST API to access sensitive data stored in the appliance database.
A SQL injection vulnerability in Nessus allows a remote, unauthenticated attacker who controls reverse DNS records for a scanned host to inject malic…
Terrascan v1.18.3 and prior are vulnerable to Server-Side Request Forgery (SSRF) via external URL resolution in uploaded IaC templates when running i…
Terrascan v1.18.3 and prior are vulnerable to Server-Side Request Forgery (SSRF) via the webhook_url parameter in the file scan endpoint (POST /v1/{i…
Terrascan v1.18.3 and prior are vulnerable to Server-Side Request Forgery (SSRF) via the remote_url parameter in the remote directory scan endpoint (…
An improper access control vulnerability exists where an authenticated user could access areas outside of their authorized scope.
An Indirect Object Reference (IDOR) in Security Center allows an authenticated remote attacker to escalate privileges via the 'owner' parameter.
A vulnerability has been identified where weak file permissions in the Nessus Agent directory on Windows hosts could allow unauthorized access, poten…
In Tenable Nessus versions prior to 10.8.5 on a Windows host, it was found that a non-administrative user could overwrite arbitrary local system file…
In Tenable Agent versions prior to 10.8.5 on a Windows host, it was found that a non-administrative user could execute code with SYSTEM privilege.
In Tenable Agent versions prior to 10.8.5 on a Windows host, it was found that a non-administrative user could arbitrarily delete local system files …
In Tenable Agent versions prior to 10.8.5 on a Windows host, it was found that a non-administrative user could overwrite arbitrary local system files…
In Tenable Network Monitor versions prior to 6.5.1 on a Windows host, it was found that a non-administrative user could stage files in a local direct…
When installing Tenable Network Monitor to a non-default location on a Windows host, Tenable Network Monitor versions prior to 6.5.1 did not enforce …
A formula injection vulnerability exists in Tenable Identity Exposure where an authenticated remote attacker with administrative privileges could man…
An improper privilege management vulnerability exists in Tenable Security Center where an authenticated, remote attacker could view unauthorized obje…
A stored cross site scripting vulnerability exists in Tenable Security Center where an authenticated, remote attacker could inject HTML code into a w…
A DLL injection vulnerability exists where an authenticated, low-privileged local attacker could modify application files on the TIE Secure Relay hos…
A command injection vulnerability exists where an authenticated, remote attacker with administrator privileges on the Security Center application cou…
A SQL injection vulnerability exists where an authenticated, low-privileged remote attacker could potentially alter scan DB content.
An arbitrary file write vulnerability exists where an authenticated, remote attacker with administrator privileges on the Nessus application could al…
An arbitrary file write vulnerability exists where an authenticated attacker with privileges on the managing application could alter Nessus Rules var…
Under certain conditions, a low privileged attacker could load a specially crafted file during installation or upgrade to escalate privileges on Wind…
Under certain conditions, Nessus Network Monitor could allow a low privileged user to escalate privileges to NT AUTHORITY\SYSTEM on Windows hosts by …
NNM failed to properly set ACLs on its installation directory, which could allow a low privileged user to run arbitrary code with SYSTEM privileges w…
Under certain conditions, Nessus Network Monitor was found to not properly enforce input validation. This could allow an admin user to alter paramete…