Tenable Nessus vulnerabilities
68 known vulnerabilities affecting tenable/nessus.
Total CVEs
68
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL4HIGH28MEDIUM35LOW1
Vulnerabilities
Page 4 of 4
CVE-2017-7199HIGHCVSS 7.8v6.6.2v6.7+10 more2017-03-23
CVE-2017-7199 [HIGH] CWE-732 CVE-2017-7199: Nessus 6.6.2 - 6.10.3 contains a flaw related to insecure permissions that may allow a local attacke
Nessus 6.6.2 - 6.10.3 contains a flaw related to insecure permissions that may allow a local attacker to escalate privileges when the software is running in Agent Mode. Version 6.10.4 fixes this issue.
nvd
CVE-2017-6543HIGHCVSS 7.3≤ 6.10.12017-03-08
CVE-2017-6543 [HIGH] CVE-2017-6543: Tenable Nessus before 6.10.2 (as used alone or in Tenable Appliance before 4.5.0) was found to conta
Tenable Nessus before 6.10.2 (as used alone or in Tenable Appliance before 4.5.0) was found to contain a flaw that allowed a remote, authenticated attacker to upload a crafted file that could be written to anywhere on the system. This could be used to subsequently gain elevated privileges on the system (e.g., after a reboot). This issue only affects installatio
nvd
CVE-2016-9259MEDIUMCVSS 5.4v6.8v6.8.1+2 more2017-02-28
CVE-2016-9259 [MEDIUM] CWE-79 CVE-2016-9259: Cross-site scripting (XSS) vulnerability in Tenable Nessus before 6.9.1 allows remote authenticated
Cross-site scripting (XSS) vulnerability in Tenable Nessus before 6.9.1 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
nvd
CVE-2016-9260MEDIUMCVSS 5.4≤ 6.8.12017-01-31
CVE-2016-9260 [MEDIUM] CWE-79 CVE-2016-9260: Cross-site scripting (XSS) vulnerability in Tenable Nessus before 6.9 allows remote authenticated us
Cross-site scripting (XSS) vulnerability in Tenable Nessus before 6.9 allows remote authenticated users to inject arbitrary web script or HTML via vectors related to handling of .nessus files.
nvd
CVE-2016-4055MEDIUMCVSS 6.5≤ 8.2.32017-01-23
CVE-2016-4055 [MEDIUM] CWE-400 CVE-2016-4055: The duration function in the moment package before 2.11.2 for Node.js allows remote attackers to cau
The duration function in the moment package before 2.11.2 for Node.js allows remote attackers to cause a denial of service (CPU consumption) via a long string, aka a "regular expression Denial of Service (ReDoS)."
nvd
CVE-2017-5179MEDIUMCVSS 5.4≤ 6.9.22017-01-05
CVE-2017-5179 [MEDIUM] CWE-79 CVE-2017-5179: Cross-site scripting (XSS) vulnerability in Tenable Nessus before 6.9.3 allows remote authenticated
Cross-site scripting (XSS) vulnerability in Tenable Nessus before 6.9.3 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
nvd
CVE-2014-4980MEDIUMCVSS 5.0v5.2.3v5.2.4+3 more2014-07-23
CVE-2014-4980 [MEDIUM] CWE-200 CVE-2014-4980: The /server/properties resource in Tenable Web UI before 2.3.5 for Nessus 5.2.3 through 5.2.7 allows
The /server/properties resource in Tenable Web UI before 2.3.5 for Nessus 5.2.3 through 5.2.7 allows remote attackers to obtain sensitive information via the token parameter.
nvd
CVE-2014-2848MEDIUMCVSS 6.9v5.2.12014-04-11
CVE-2014-2848 [MEDIUM] CWE-362 CVE-2014-2848: A race condition in the wmi_malware_scan.nbin plugin before 201402262215 for Nessus 5.2.1 allows loc
A race condition in the wmi_malware_scan.nbin plugin before 201402262215 for Nessus 5.2.1 allows local users to gain privileges by replacing the dissolvable agent executable in the Windows temp directory with a Trojan horse program.
nvd
← Previous4 / 4