Tenable / Nessus
71 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-57588 | SQL Injection in Nessus via Malicious Scan Result File Import | LOW | 1.8 | Jun 25, 2026 |
| CVE-2026-57587 | SQL Injection in Nessus via Reverse DNS Lookup | LOW | 2.9 | Jun 25, 2026 |
| CVE-2026-33694 | Junction File Manipulation | HIGH | 7.4 | Apr 23, 2026 |
| CVE-2025-36630 | Local Privilege Escalation | HIGH | 8.4 | Jul 1, 2025 |
| CVE-2025-36625 | Log Poisoning in Nessus | MEDIUM | 4.3 | Apr 18, 2025 |
| CVE-2025-24914 | Local Priviledge Escalation | HIGH | 7.8 | Apr 18, 2025 |
| CVE-2024-3290 | Race Condition | HIGH | 8.2 | May 17, 2024 |
| CVE-2024-3289 | When installing Nessus to a directory outside of the default location on a Windows host, Nessus versions prior to 10.7.3 did not enforce secure permissions for… | HIGH | 7.8 | May 17, 2024 |
| CVE-2024-2390 | Local Privilege Escalation | HIGH | 7.8 | Mar 18, 2024 |
| CVE-2024-0971 | A SQL injection vulnerability exists where an authenticated, low-privileged remote attacker could potentially alter scan DB content. | MEDIUM | 6.5 | Feb 6, 2024 |
| CVE-2024-0955 | Stored XSS vulnerability | MEDIUM | 4.8 | Feb 6, 2024 |
| CVE-2023-6178 | An arbitrary file write vulnerability exists where an authenticated attacker with privileges on the managing application could alter Nessus Rules variables to… | MEDIUM | 6.8 | Nov 20, 2023 |
| CVE-2023-6062 | Arbitrary File Write | MEDIUM | 6.8 | Nov 20, 2023 |
| CVE-2023-5847 | Under certain conditions, a low privileged attacker could load a specially crafted file during installation or upgrade to escalate privileges on Windows and Li… | HIGH | 7.3 | Nov 1, 2023 |
| CVE-2023-3253 | Improper authorization in Nessus | MEDIUM | 4.3 | Aug 29, 2023 |
| CVE-2023-3252 | Arbitrary File Write | MEDIUM | 6.8 | Aug 29, 2023 |
| CVE-2023-3251 | Pass-back vulnerability in Nessus | MEDIUM | 4.9 | Aug 29, 2023 |
| CVE-2023-2005 | Tenable Plugin Feed ID #202306261202 Fixes Privilege Escalation Vulnerability | HIGH | 8.8 | Jun 26, 2023 |
| CVE-2022-4313 | A vulnerability was reported where through modifying the scan variables, an authenticated user in Tenable products, that has Scan Policy Configuration roles, c… | HIGH | 8.8 | Mar 15, 2023 |
| CVE-2023-0524 | As part of our Security Development Lifecycle, a potential privilege escalation issue was identified internally. This could allow a malicious actor with suffic… | HIGH | 8.8 | Feb 1, 2023 |
| CVE-2023-0101 | A privilege escalation vulnerability was identified in Nessus versions 8.10.1 through 8.15.8 and 10.0.0 through 10.4.1. An authenticated attacker could potenti… | HIGH | 8.8 | Jan 20, 2023 |
| CVE-2022-3499 | An authenticated attacker could utilize the identical agent and cluster node linking keys to potentially allow for a scenario where unauthorized disclosure of… | MEDIUM | 6.5 | Oct 31, 2022 |
| CVE-2022-33757 | An authenticated attacker could read Nessus Debug Log file attachments from the web UI without having the correct privileges to do so. This may lead to the dis… | MEDIUM | 6.5 | Oct 24, 2022 |
| CVE-2022-28291 | Insufficiently Protected Credentials: An authenticated user with debug privileges can retrieve stored Nessus policy credentials from the “nessusd” process in c… | MEDIUM | 6.5 | Oct 17, 2022 |
| CVE-2022-32974 | An authenticated attacker could read arbitrary files from the underlying operating system of the scanner using a custom crafted compliance audit file without p… | MEDIUM | 6.5 | Jun 21, 2022 |
Showing 1 to 25 of 71 CVEs