Known Vulnerabilities for products from Tenable
Listed below are 20 of the newest known vulnerabilities associated with the vendor "Tenable".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-64881 json | The audit file upload handler does not sanitize filenames, allowing shell metacharacters to flow into system command executio... | Not Provided | 2026-07-21 | 2026-08-18 |
| CVE-2026-64880 json | Unsanitized user-supplied input in report filtering parameters is concatenated directly into SQL queries without proper escap... | Not Provided | 2026-07-21 | 2026-08-18 |
| CVE-2026-64879 json | A filename supplied during file upload is not properly sanitized before being used in system command execution, allowing an a... | Not Provided | 2026-07-21 | 2026-08-18 |
| CVE-2026-64878 json | Unvalidated input in asset filter parameters allows shell metacharacters to escape command argument handling, resulting in re... | Not Provided | 2026-07-21 | 2026-08-18 |
| CVE-2026-64877 json | An authenticated non-admin user can exploit a SQL injection flaw in the ticketing REST API to access sensitive data stored in... | Not Provided | 2026-07-21 | 2026-08-18 |
| CVE-2026-57588 json | A SQL injection vulnerability in Nessus allows an attacker to craft a malicious scan result file that, when imported by a pri... | Not Provided | 2026-06-25 | 2026-06-26 |
| CVE-2026-57587 json | A SQL injection vulnerability in Nessus allows a remote, unauthenticated attacker who controls reverse DNS records for a scan... | Not Provided | 2026-06-25 | 2026-06-26 |
| CVE-2026-47358 json | Terrascan v1.18.3 and prior are vulnerable to Server-Side Request Forgery (SSRF) via external URL resolution in uploaded IaC ... | Not Provided | 2026-05-19 | 2026-07-24 |
| CVE-2026-47357 json | Terrascan v1.18.3 and prior are vulnerable to Server-Side Request Forgery (SSRF) via the remote_url parameter in the remote d... | Not Provided | 2026-05-19 | 2026-07-24 |
| CVE-2026-47356 json | Terrascan v1.18.3 and prior are vulnerable to Server-Side Request Forgery (SSRF) via the webhook_url parameter in the file sc... | Not Provided | 2026-05-19 | 2026-07-24 |
| CVE-2026-33694 json | This vulnerability allows an attacker to create a junction, enabling the deletion of arbitrary files with SYSTEM privileges. ... | Not Provided | 2026-04-23 | 2026-08-21 |
| CVE-2026-19682 json | A command injection vulnerability exists in Security Center where a remote, unauthenticated attacker could exploit this issue... | Not Provided | 2026-08-14 | 2026-08-19 |
| CVE-2026-19681 json | An authenticated command injection vulnerability exists in Security Center related to file upload processing. An attacker cou... | Not Provided | 2026-08-14 | 2026-08-19 |
| CVE-2026-19680 json | A SQL injection vulnerability exists in Security Center that could allow an attacker to access unauthorized data from the app... | Not Provided | 2026-08-14 | 2026-08-19 |
| CVE-2026-19679 json | An input validation vulnerability exists in Security Center's file upload handling, where insufficient sanitization of upload... | Not Provided | 2026-08-14 | 2026-08-19 |
| CVE-2026-19639 json | An improper access control vulnerability exists where an authenticated non-administrative application user could potentially ... | Not Provided | 2026-08-14 | 2026-08-19 |
| CVE-2026-19636 json | An issue was identified in which CSRF tokens were generated using a predictable method, potentially reducing their effectiven... | Not Provided | 2026-08-14 | 2026-08-19 |
| CVE-2026-19635 json | A local privilege escalation vulnerability exists in Security Center. An attacker with write access to a specific configurati... | Not Provided | 2026-08-14 | 2026-08-19 |
| CVE-2026-19631 json | A SQL injection vulnerability exists in Security Center that could allow an authenticated administrator to execute arbitrary ... | Not Provided | 2026-08-14 | 2026-08-19 |
| CVE-2026-19629 json | A privilege escalation vulnerability exists in Tenable Security Center that allows a user with "Security Manager" role and "m... | Not Provided | 2026-08-14 | 2026-08-19 |
Known software with vulnerabilities from Tenable
| Type | Vendor | Product | Version |
|---|---|---|---|
| Application | Tenable | Appliance | 2.0.0 |
| Application | Tenable | Log Correlation Engine | 4.8.0 |
| Application | Tenable | Nessus | 4.4.1.15078 |
| Application | Tenable | Nessus Agent | 6.10.2 |
| Application | Tenable | Nessus Network Monitor | 5.11.0 |
| Application | Tenable | Plugin-set | 201402092115 |
| Application | Tenable | Securitycenter | 4.6 |
| Application | Tenable | Tenable.sc | 5.14.0 |
| Application | Tenable | Web Ui | 2.3.3 |