Vulnerabilidades em Tenable, Inc.
9 resultadosAnálise Vexday
A Tenable registra 8 vulnerabilidades em base, com 5 publicadas nos últimos 90 dias, indicando ritmo significativo de descobertas recentes; 3 delas são críticas, mas nenhuma está sob exploração ativa (KEV), reduzindo o risco imediato. A fraqueza dominante é injeção de comando (CWE-78), padrão que exige atenção em ambientes de produção, recomendando priorização das críticas e monitoramento de novas divulgações.
CVE-2026-64879CRITICALCommand InjectionEPSS 2.6%CVE-2026-64881HIGHCommand InjectionEPSS 1.4%CVE-2022-33757MEDIUMAn authenticated attacker could read Nessus Debug Log file attachments from the web UI without having the correct privileges to do so. This EPSS 0.8%CVE-2026-64878CRITICALCommand InjectionEPSS 0.5%CVE-2026-18667CRITICALSensor Proxy Version 1.4.2 Fixes One VulnerabilityEPSS 0.4%CVE-2026-4433LOWAn SSH misconfigurations exists in Tenable OT that led to the potential exfiltration of socket, port, and service information via the ostunnEPSS 0.2%CVE-2026-64877CRITICALAn authenticated non-admin user can exploit a SQL injection flaw in the ticketing REST API to access sensitive data stored in the appliance EPSS 0.2%CVE-2026-64880HIGHBlind SQL InjectionEPSS 0.2%CVE-2026-33694HIGHJunction File ManipulationEPSS 0.1%