Known Vulnerabilities for products from Tenable

Listed below are 20 of the newest known vulnerabilities associated with the vendor "Tenable".

These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.

Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.

Known Vulnerabilities

CVE Shortened Description Severity Publish Date Last Modified
CVE-2026-64881 json The audit file upload handler does not sanitize filenames, allowing shell metacharacters to flow into system command executio... Not Provided 2026-07-21 2026-08-18
CVE-2026-64880 json Unsanitized user-supplied input in report filtering parameters is concatenated directly into SQL queries without proper escap... Not Provided 2026-07-21 2026-08-18
CVE-2026-64879 json A filename supplied during file upload is not properly sanitized before being used in system command execution, allowing an a... Not Provided 2026-07-21 2026-08-18
CVE-2026-64878 json Unvalidated input in asset filter parameters allows shell metacharacters to escape command argument handling, resulting in re... Not Provided 2026-07-21 2026-08-18
CVE-2026-64877 json An authenticated non-admin user can exploit a SQL injection flaw in the ticketing REST API to access sensitive data stored in... Not Provided 2026-07-21 2026-08-18
CVE-2026-57588 json A SQL injection vulnerability in Nessus allows an attacker to craft a malicious scan result file that, when imported by a pri... Not Provided 2026-06-25 2026-06-26
CVE-2026-57587 json A SQL injection vulnerability in Nessus allows a remote, unauthenticated attacker who controls reverse DNS records for a scan... Not Provided 2026-06-25 2026-06-26
CVE-2026-47358 json Terrascan v1.18.3 and prior are vulnerable to Server-Side Request Forgery (SSRF) via external URL resolution in uploaded IaC ... Not Provided 2026-05-19 2026-07-24
CVE-2026-47357 json Terrascan v1.18.3 and prior are vulnerable to Server-Side Request Forgery (SSRF) via the remote_url parameter in the remote d... Not Provided 2026-05-19 2026-07-24
CVE-2026-47356 json Terrascan v1.18.3 and prior are vulnerable to Server-Side Request Forgery (SSRF) via the webhook_url parameter in the file sc... Not Provided 2026-05-19 2026-07-24
CVE-2026-33694 json This vulnerability allows an attacker to create a junction, enabling the deletion of arbitrary files with SYSTEM privileges. ... Not Provided 2026-04-23 2026-08-21
CVE-2026-19682 json A command injection vulnerability exists in Security Center where a remote, unauthenticated attacker could exploit this issue... Not Provided 2026-08-14 2026-08-19
CVE-2026-19681 json An authenticated command injection vulnerability exists in Security Center related to file upload processing. An attacker cou... Not Provided 2026-08-14 2026-08-19
CVE-2026-19680 json A SQL injection vulnerability exists in Security Center that could allow an attacker to access unauthorized data from the app... Not Provided 2026-08-14 2026-08-19
CVE-2026-19679 json An input validation vulnerability exists in Security Center's file upload handling, where insufficient sanitization of upload... Not Provided 2026-08-14 2026-08-19
CVE-2026-19639 json An improper access control vulnerability exists where an authenticated non-administrative application user could potentially ... Not Provided 2026-08-14 2026-08-19
CVE-2026-19636 json An issue was identified in which CSRF tokens were generated using a predictable method, potentially reducing their effectiven... Not Provided 2026-08-14 2026-08-19
CVE-2026-19635 json A local privilege escalation vulnerability exists in Security Center. An attacker with write access to a specific configurati... Not Provided 2026-08-14 2026-08-19
CVE-2026-19631 json A SQL injection vulnerability exists in Security Center that could allow an authenticated administrator to execute arbitrary ... Not Provided 2026-08-14 2026-08-19
CVE-2026-19629 json A privilege escalation vulnerability exists in Tenable Security Center that allows a user with "Security Manager" role and "m... Not Provided 2026-08-14 2026-08-19

Known software with vulnerabilities from Tenable

Type Vendor Product Version
ApplicationTenableAppliance2.0.0
ApplicationTenableLog Correlation Engine4.8.0
ApplicationTenableNessus4.4.1.15078
ApplicationTenableNessus Agent6.10.2
ApplicationTenableNessus Network Monitor5.11.0
ApplicationTenablePlugin-set201402092115
ApplicationTenableSecuritycenter4.6
ApplicationTenableTenable.sc5.14.0
ApplicationTenableWeb Ui2.3.3

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report