Nessus

Tenable · 71 CVEs

CVE-2026-57588
LOW

SQL Injection in Nessus via Malicious Scan Result File Import

Jun 25, 2026

CVE-2026-57587
LOW

SQL Injection in Nessus via Reverse DNS Lookup

Jun 25, 2026

CVE-2026-33694
HIGH

Junction File Manipulation

Apr 23, 2026

CVE-2025-36630
HIGH

Local Privilege Escalation

Jul 1, 2025

CVE-2025-36625
MEDIUM

Log Poisoning in Nessus

Apr 18, 2025

CVE-2025-24914
HIGH

Local Priviledge Escalation

Apr 18, 2025

CVE-2024-3290
HIGH

Race Condition

May 17, 2024

CVE-2024-3289
HIGH

When installing Nessus to a directory outside of the default location on a Windows host, Nessus versions prior to 10.7.…

May 17, 2024

CVE-2024-2390
HIGH

Local Privilege Escalation

Mar 18, 2024

CVE-2024-0971
MEDIUM

A SQL injection vulnerability exists where an authenticated, low-privileged remote attacker could potentially alter sca…

Feb 6, 2024

CVE-2024-0955
MEDIUM

Stored XSS vulnerability

Feb 6, 2024

CVE-2023-6178
MEDIUM

An arbitrary file write vulnerability exists where an authenticated attacker with privileges on the managing applicatio…

Nov 20, 2023

CVE-2023-6062
MEDIUM

Arbitrary File Write

Nov 20, 2023

CVE-2023-5847
HIGH

Under certain conditions, a low privileged attacker could load a specially crafted file during installation or upgrade…

Nov 1, 2023

CVE-2023-3253
MEDIUM

Improper authorization in Nessus

Aug 29, 2023

CVE-2023-3252
MEDIUM

Arbitrary File Write

Aug 29, 2023

CVE-2023-3251
MEDIUM

Pass-back vulnerability in Nessus

Aug 29, 2023

CVE-2023-2005
HIGH

Tenable Plugin Feed ID #202306261202 Fixes Privilege Escalation Vulnerability

Jun 26, 2023

CVE-2022-4313
HIGH

A vulnerability was reported where through modifying the scan variables, an authenticated user in Tenable products, tha…

Mar 15, 2023

CVE-2023-0524
HIGH

As part of our Security Development Lifecycle, a potential privilege escalation issue was identified internally. This c…

Feb 1, 2023

CVE-2023-0101
HIGH

A privilege escalation vulnerability was identified in Nessus versions 8.10.1 through 8.15.8 and 10.0.0 through 10.4.1.…

Jan 20, 2023

CVE-2022-3499
MEDIUM

An authenticated attacker could utilize the identical agent and cluster node linking keys to potentially allow for a sc…

Oct 31, 2022

CVE-2022-33757
MEDIUM

An authenticated attacker could read Nessus Debug Log file attachments from the web UI without having the correct privi…

Oct 24, 2022

CVE-2022-28291
MEDIUM

Insufficiently Protected Credentials: An authenticated user with debug privileges can retrieve stored Nessus policy cre…

Oct 17, 2022

CVE-2022-32974
MEDIUM

An authenticated attacker could read arbitrary files from the underlying operating system of the scanner using a custom…

Jun 21, 2022

Showing 1 to 25 of 71 CVEs