Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Tenable

29 known vulnerabilities

6
CRITICAL
13
HIGH
8
MEDIUM
1
LOW

Top Products

security center 18 nessus agent 3 nessus 3 terrascan 3 identity exposure 1 operational technology exposure 1
28 CVEs
9.9
CVE-2026-19682

A command injection vulnerability exists in Security Center where a remote, unauthenticated attacker could exploit this

9.9
CVE-2026-19681

An authenticated command injection vulnerability exists in Security Center related to file upload processing. An attacke

7.1
CVE-2026-19680

A SQL injection vulnerability exists in Security Center that could allow an attacker to access unauthorized data from th

8.8
CVE-2026-19679

An input validation vulnerability exists in Security Center's file upload handling, where insufficient sanitization of u

4.3
CVE-2026-19639

An improper access control vulnerability exists where an authenticated non-administrative application user could potenti

5.3
CVE-2026-19636

An issue was identified in which CSRF tokens were generated using a predictable method, potentially reducing their effec

8.8
CVE-2026-19635

A local privilege escalation vulnerability exists in Security Center. An attacker with write access to a specific config

4.9
CVE-2026-19631

A SQL injection vulnerability exists in Security Center that could allow an authenticated administrator to execute arbit

8.1
CVE-2026-19629

A privilege escalation vulnerability exists in Tenable Security Center that allows a user with "Security Manager" role a

7.2
CVE-2026-19628

A command injection vulnerability exists in Tenable Security Center. An authenticated administrator could modify applica

9.9
CVE-2026-19626

A remote code execution vulnerability exists in Tenable Security Center's report generation functionality. An authentica

8.8
CVE-2026-64881

The audit file upload handler does not sanitize filenames, allowing shell metacharacters to flow into system command exe

7.1
CVE-2026-64880

Unsanitized user-supplied input in report filtering parameters is concatenated directly into SQL queries without proper

9.9
CVE-2026-64879

A filename supplied during file upload is not properly sanitized before being used in system command execution, allowing

9.9
CVE-2026-64878

Unvalidated input in asset filter parameters allows shell metacharacters to escape command argument handling, resulting

8.4
CVE-2026-64877

An authenticated non-admin user can exploit a SQL injection flaw in the ticketing REST API to access sensitive data stor

9.1
CVE-2026-15265

A path traversal vulnerability in Tenable Agent 11.2.0 and 11.1.3 and lower allows a privileged attacker to write arbitr

3.3
CVE-2026-57588

A SQL injection vulnerability in Nessus allows an attacker to craft a malicious scan result file that, when imported by

5.3
CVE-2026-57587

A SQL injection vulnerability in Nessus allows a remote, unauthenticated attacker who controls reverse DNS records for a

7.5
CVE-2026-13007

Tenable Identity Exposure contains multiple unauthenticated API endpoints under /w/api/* that expose sensitive applicati

7.5
CVE-2026-47358

Terrascan v1.18.3 and prior are vulnerable to Server-Side Request Forgery (SSRF) via external URL resolution in uploaded

7.5
CVE-2026-47357

Terrascan v1.18.3 and prior are vulnerable to Server-Side Request Forgery (SSRF) via the remote_url parameter in the rem

7.5
CVE-2026-47356

Terrascan v1.18.3 and prior are vulnerable to Server-Side Request Forgery (SSRF) via the webhook_url parameter in the fi

7.8
CVE-2026-33694

This vulnerability allows an attacker to create a junction, enabling the deletion of arbitrary files with SYSTEM privile

4.3
CVE-2026-4433

An SSH misconfigurations exists in Tenable OT that led to the potential exfiltration of socket, port, and service inform

6.5
CVE-2026-2698

An improper access control vulnerability exists where an authenticated user could access areas outside of their authoriz

6.3
CVE-2026-2697

An Indirect Object Reference (IDOR) in Security Center allows an authenticated remote attacker to escalate privileges vi

6.1
CVE-2026-2026

A vulnerability has been identified where weak file permissions in the Nessus Agent directory on Windows hosts could all

Frequently Asked Questions

How many CVEs affect Tenable?

Tenable has 29 CVE records in our database, including 6 critical and 14 high severity vulnerabilities.

What are the most severe Tenable vulnerabilities?

Tenable has 6 critical severity (CVSS 9.0+) and 14 high severity (CVSS 7.0-8.9) vulnerabilities. Review the list above sorted by publication date to find the most recent high-severity issues.

How can I scan for Tenable vulnerabilities?

CyberStrike's AI-powered security agents automatically detect vulnerabilities in Tenable products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.

Detect Tenable Vulnerabilities

CyberStrike scans your infrastructure for Tenable vulnerabilities and provides real-time remediation guidance.

Get Started