Tenable / Tenable.sc
46 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2023-0524 | As part of our Security Development Lifecycle, a potential privilege escalation issue was identified internally. This could allow a malicious actor with suffic… | HIGH | 8.8 | Feb 1, 2023 |
| CVE-2023-24495 | A Server Side Request Forgery (SSRF) vulnerability exists in Tenable.sc due to improper validation of session & user-accessible input data. A privileged, authe… | MEDIUM | 6.5 | Jan 25, 2023 |
| CVE-2023-24494 | A stored cross-site scripting (XSS) vulnerability exists in Tenable.sc due to improper validation of user-supplied input before returning it to users. An authe… | MEDIUM | 5.4 | Jan 25, 2023 |
| CVE-2023-24493 | A formula injection vulnerability exists in Tenable.sc due to improper validation of user-supplied input before returning it to users. An authenticated attacke… | MEDIUM | 5.7 | Jan 25, 2023 |
| CVE-2023-0476 | A LDAP injection vulnerability exists in Tenable.sc due to improper validation of user-supplied input before returning it to users. An authenticated attacker c… | MEDIUM | 6.5 | Jan 25, 2023 |
| CVE-2022-24828 | Missing input validation can lead to command execution in composer | HIGH | 8.8 | Apr 13, 2022 |
| CVE-2022-24785 | Path Traversal in Moment.js | HIGH | 7.5 | Apr 4, 2022 |
| CVE-2022-0130 | Tenable.sc versions 5.14.0 through 5.19.1 were found to contain a remote code execution vulnerability which could allow a remote, unauthenticated attacker to e… | HIGH | 8.1 | Jan 14, 2022 |
| CVE-2021-44224 | Possible NULL dereference or SSRF in forward proxy configurations in Apache HTTP Server 2.4.51 and earlier | HIGH | 8.2 | Dec 20, 2021 |
| CVE-2021-44790 | Possible buffer overflow when parsing multipart content in mod_lua of Apache HTTP Server 2.4.51 and earlier | CRITICAL | 9.8 | Dec 20, 2021 |
| CVE-2021-21707 | Special characters break path parsing in XML functions | MEDIUM | 5.3 | Nov 29, 2021 |
| CVE-2021-41184 | XSS in the `of` option of the `.position()` util | MEDIUM | 6.5 | Oct 26, 2021 |
| CVE-2021-41183 | XSS in `*Text` options of the Datepicker widget | MEDIUM | 6.5 | Oct 26, 2021 |
| CVE-2021-41182 | XSS in the `altField` option of the Datepicker widget | MEDIUM | 6.5 | Oct 26, 2021 |
| CVE-2021-41116 | Command injection in composer on Windows | CRITICAL | 9.8 | Oct 5, 2021 |
| CVE-2021-40438 KEV | mod_proxy SSRF | CRITICAL | 9.0 | Sep 16, 2021 |
| CVE-2021-34798 | NULL pointer dereference in httpd core | HIGH | 7.5 | Sep 16, 2021 |
| CVE-2021-3712 | Read buffer overruns processing ASN.1 strings | HIGH | 7.4 | Aug 24, 2021 |
| CVE-2021-3711 | SM2 Decryption Buffer Overflow | CRITICAL | 9.8 | Aug 24, 2021 |
| CVE-2021-33193 | Request splitting via HTTP/2 method injection and mod_proxy | HIGH | 7.5 | Aug 16, 2021 |
| CVE-2021-23358 | Arbitrary Code Injection | CRITICAL | 9.8 | Mar 29, 2021 |
| CVE-2021-3449 | NULL pointer deref in signature_algorithms processing | MEDIUM | 5.9 | Mar 25, 2021 |
| CVE-2021-20076 | Tenable.sc and Tenable.sc Core versions 5.13.0 through 5.17.0 were found to contain a vulnerability that could allow an authenticated, unprivileged user to per… | HIGH | 8.8 | Mar 3, 2021 |
| CVE-2021-23841 | Null pointer deref in X509_issuer_and_serial_hash() | MEDIUM | 5.9 | Feb 16, 2021 |
| CVE-2020-5808 | In certain scenarios in Tenable.sc prior to 5.17.0, a scanner could potentially be used outside the user's defined scan zone without a particular zone being sp… | HIGH | 7.5 | Dec 21, 2020 |
Showing 1 to 25 of 46 CVEs