« Volver al listado

Tenable

Tenable Security Center: vulnerabilidades y CVE

Tenable Security Center tiene 35 vulnerabilidades publicadas, 20 de ellas en los últimos 12 meses. 7 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE35
Últimos 12 meses20
Críticas7
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-19682Crítica (9.4)2.8%—14 ago 2026
A command injection vulnerability exists in Security Center where a remote, unauthenticated attacker could exploit this issue to execute arbitrary commands on the underlying operating system with the privileges of the…
CVE-2026-19681Crítica (9.4)9.9%—14 ago 2026
An authenticated command injection vulnerability exists in Security Center related to file upload processing. An attacker could exploit this issue by uploading a specially crafted file, potentially resulting in…
CVE-2026-19680Alta (7.1)0.32%—14 ago 2026
A SQL injection vulnerability exists in Security Center that could allow an attacker to access unauthorized data from the application's database.
CVE-2026-19679Alta (8.7)1.6%—14 ago 2026
An input validation vulnerability exists in Security Center's file upload handling, where insufficient sanitization of uploaded filenames could contribute to a downstream command injection issue.
CVE-2026-19639Media (5.3)0.30%—14 ago 2026
An improper access control vulnerability exists where an authenticated non-administrative application user could potentially view settings outside of their assigned scope.
CVE-2026-19636Media (6)0.26%—14 ago 2026
An issue was identified in which CSRF tokens were generated using a predictable method, potentially reducing their effectiveness as a security control. This has been addressed by improving the randomness and entropy of…
CVE-2026-19635Alta (8.5)0.19%—14 ago 2026
A local privilege escalation vulnerability exists in Security Center. An attacker with write access to a specific configuration file could achieve arbitrary code execution with elevated privileges, without requiring…
CVE-2026-19631Media (6.9)0.39%—14 ago 2026
A SQL injection vulnerability exists in Security Center that could allow an authenticated administrator to execute arbitrary SQL queries, potentially resulting in unauthorized access to sensitive data, including…
CVE-2026-19629Alta (8.6)0.39%—14 ago 2026
A privilege escalation vulnerability exists in Tenable Security Center that allows a user with "Security Manager" role and "manage user" permission on a single group to modify users belonging to other groups. This…
CVE-2026-19628Alta (8.6)2.1%—14 ago 2026
A command injection vulnerability exists in Tenable Security Center. An authenticated administrator could modify application configuration values to achieve arbitrary command execution on the underlying operating system…
CVE-2026-19626Crítica (9.4)1.9%—14 ago 2026
A remote code execution vulnerability exists in Tenable Security Center's report generation functionality. An authenticated, non-administrative user could exploit this issue by supplying specially crafted input that is…
CVE-2026-64881Alta (8.7)2.2%—21 jul 2026
The audit file upload handler does not sanitize filenames, allowing shell metacharacters to flow into system command execution. This input validation failure enables command injection when chained with a related…
CVE-2026-64880Alta (7.1)0.32%—21 jul 2026
Unsanitized user-supplied input in report filtering parameters is concatenated directly into SQL queries without proper escaping or parameterized queries, enabling blind SQL injection and unauthorized database read…
CVE-2026-64879Crítica (9.4)2.3%—21 jul 2026
A filename supplied during file upload is not properly sanitized before being used in system command execution, allowing an attacker to inject shell metacharacters and achieve command injection via the audit file upload…
CVE-2026-64878Crítica (9.4)0.80%—21 jul 2026
Unvalidated input in asset filter parameters allows shell metacharacters to escape command argument handling, resulting in remote code execution as a low-privileged OS user via the Analysis REST endpoint.
CVE-2026-64877Crítica (9.4)0.32%—21 jul 2026
An authenticated non-admin user can exploit a SQL injection flaw in the ticketing REST API to access sensitive data stored in the appliance database.
CVE-2026-2698Media (5.7)0.37%—23 feb 2026
An improper access control vulnerability exists where an authenticated user could access areas outside of their authorized scope.
CVE-2026-2697Baja (2.1)0.38%—23 feb 2026
An Indirect Object Reference (IDOR) in Security Center allows an authenticated remote attacker to escalate privileges via the 'owner' parameter.
CVE-2026-2630Alta (7.4)1.7%—17 feb 2026
A Command Injection vulnerability exists where an authenticated, remote attacker could execute arbitrary code on the underlying server where Tenable Security Center is hosted.
CVE-2025-36636Media (4.3)0.19%—8 oct 2025
In Tenable Security Center versions prior to 6.7.0, an improper access control vulnerability exists where an authenticated user could access areas outside of their authorized scope.
CVE-2024-12174Baja (2.7)0.18%—9 dic 2024
An Improper Certificate Validation vulnerability exists in Tenable Security Center where an authenticated, privileged attacker could intercept email messages sent from Security Center via a rogue SMTP server.
CVE-2024-5759Media (6.3)0.30%—12 jun 2024
An improper privilege management vulnerability exists in Tenable Security Center where an authenticated, remote attacker could view unauthorized objects and launch scans without having the required privileges
CVE-2024-1891Media (5.4)0.30%—12 jun 2024
A stored cross site scripting vulnerability exists in Tenable Security Center where an authenticated, remote attacker could inject HTML code into a web application scan result page.
CVE-2024-1471Media (4.8)0.41%—14 feb 2024
An HTML injection vulnerability exists where an authenticated, remote attacker with administrator privileges on the Security Center application could modify Repository parameters, which could lead to HTML redirection…
CVE-2024-1367Alta (7.2)1.6%—14 feb 2024
A command injection vulnerability exists where an authenticated, remote attacker with administrator privileges on the Security Center application could modify Logging parameters, which could lead to the execution of…
CVE-2023-2005Alta (8.8)0.38%—26 jun 2023
Vulnerability in Tenable Tenable.Io, Tenable Nessus, Tenable Security Center.This issue affects Tenable.Io: before Plugin Feed ID #202306261202 ; Nessus: before Plugin Feed ID #202306261202 ; Security Center: before…
CVE-2019-11050Media (6.5)7.6%—23 dic 2019
When PHP EXIF extension is parsing EXIF information from an image, e.g. via exif_read_data() function, in PHP versions 7.2.x below 7.2.26, 7.3.x below 7.3.13 and 7.4.0 it is possible to supply it with data what will…
CVE-2019-11049Crítica (9.8)4.2%—23 dic 2019
In PHP versions 7.3.x below 7.3.13 and 7.4.0 on Windows, when supplying custom headers to mail() function, due to mistake introduced in commit 78f4b4a2dcf92ddbccea1bb95f8390a18ac3342e, if the header is supplied in…
CVE-2019-11046Media (5.3)4.1%—23 dic 2019
In PHP versions 7.2.x below 7.2.26, 7.3.x below 7.3.13 and 7.4.0, PHP bcmath extension functions on some systems, including Windows, can be tricked into reading beyond the allocated space by supplying it with string…
CVE-2019-11045Media (5.9)8.8%—23 dic 2019
In PHP versions 7.2.x below 7.2.26, 7.3.x below 7.3.13 and 7.4.0, PHP DirectoryIterator class accepts filenames with embedded \0 byte and treats them as terminating at that byte. This could lead to security…

Otros productos de Tenable