Vulnerabilidades em Tenable

81 resultados
Análise Vexday

Com 73 CVEs catalogadas e nenhuma confirmada em exploração ativa pelo CISA KEV, o perfil de risco da Tenable situa-se abaixo da média geral do catálogo, que registra 0,45% de taxa de exploração. A ausência de vulnerabilidades críticas e de novas ocorrências nos últimos 90 dias reforça um cenário de baixa pressão imediata, embora duas CVEs com prova de conceito pública mereçam atenção contínua por reduzirem a barreira técnica para tentativas de exploração. O tipo de falha mais recorrente é CWE-269 (gerenciamento impróprio de privilégios), um padrão que frequentemente serve de vetor para escalonamento de acesso em ambientes corporativos. A CVE mais relevante no momento, CVE-2019-3921, apresenta EPSS de 0,1789, indicando probabilidade não desprezível de exploração e justificando priorização nas rotinas de patching, especialmente em instalações que ainda não aplicaram as correções disponíveis.

CVE-2026-47356HIGHTerrascan v1.18.3 and prior are vulnerable to Server-Side Request Forgery (SSRF) via the webhook_url parameter in the file scan endpoint (POEPSS 0.5%CVE-2018-1153Burp Suite Community Edition 1.7.32 and 1.7.33 fail to validate the server certificate in a couple of HTTPS requests which allows a man in tEPSS 0.5%CVE-2023-5624HIGHBlind SQL InjectionEPSS 0.5%CVE-2026-47357CRITICALTerrascan v1.18.3 and prior are vulnerable to Server-Side Request Forgery (SSRF) via the remote_url parameter in the remote directory scan eEPSS 0.5%CVE-2026-47358CRITICALTerrascan v1.18.3 and prior are vulnerable to Server-Side Request Forgery (SSRF) via external URL resolution in uploaded IaC templates when EPSS 0.5%CVE-2023-5622HIGHPrivilege Escalation EPSS 0.5%CVE-2024-3232HIGHFormula Injection VulnerabilityEPSS 0.5%CVE-2021-21371MEDIUMExecution of untrusted code through config fileEPSS 0.5%CVE-2026-57587LOWSQL Injection in Nessus via Reverse DNS LookupEPSS 0.4%CVE-2024-1471MEDIUMHTML Injection VulnerabilityEPSS 0.4%CVE-2023-2005MEDIUMTenable Plugin Feed ID #202306261202 Fixes Privilege Escalation VulnerabilityEPSS 0.4%CVE-2026-57588LOWSQL Injection in Nessus via Malicious Scan Result File ImportEPSS 0.3%CVE-2024-9158HIGHXSSEPSS 0.3%CVE-2024-1683HIGHDLL Injection in Tenable Identity Exposure Secure RelayEPSS 0.3%CVE-2024-5759MEDIUMImproper privilege managementEPSS 0.3%CVE-2024-1891LOWStored Cross Site ScriptingEPSS 0.3%CVE-2025-36625MEDIUMLog Poisoning in NessusEPSS 0.3%CVE-2025-1091MEDIUMBroken Authorization SchemaEPSS 0.3%CVE-2018-1141When installing Nessus to a directory outside of the default location, Nessus versions prior to 7.0.3 did not enforce secure permissions forEPSS 0.2%CVE-2023-5847MEDIUM Under certain conditions, a low privileged attacker could load a specially crafted file during installation or upgrade to escalate privilegEPSS 0.2%