Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3028▼ 62 respecto a la semana anterior
Críticas / altas1422▲ 60 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
198 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Crítica (9.2) | 0.59% | — | Tenable Terrascan | 19/5/2026 | 24/7/2026 | Terrascan v1.18.3 and prior are vulnerable to Server-Side Request Forgery (SSRF) via the remote_url parameter in the remote directory scan endpoint (POST /v1/{iac}/{iacVersion}/{cloud}/remote/dir/scan) when running in server mode. An unauthenticated remote attacker can supply an attacker-controlled HTTP URL as… | |
| Analizada | Alta (8.7) | 0.61% | — | Tenable Terrascan | 19/5/2026 | 24/7/2026 | Terrascan v1.18.3 and prior are vulnerable to Server-Side Request Forgery (SSRF) via the webhook_url parameter in the file scan endpoint (POST /v1/{iac}/{iacVersion}/{cloud}/local/file/scan) when running in server mode. An unauthenticated remote attacker can supply an arbitrary URL as the webhook_url multipart form… | |
| Analizada | Alta (7.4) | 0.20% | — | Tenable NessusTenable Nessus Agent | 23/4/2026 | 21/8/2026 | This vulnerability allows an attacker to create a junction, enabling the deletion of arbitrary files with SYSTEM privileges. As a result, this condition potentially facilitates arbitrary code execution, whereby an attacker may exploit the vulnerability to execute malicious code with elevated SYSTEM privileges. | |
| Analizada | Baja (1.9) | 0.27% | — | Tenable Operational Technology Exposure | 24/3/2026 | 18/8/2026 | An SSH misconfigurations exists in Tenable OT that led to the potential exfiltration of socket, port, and service information via the ostunnel user and GatewayPorts. This could be used to potentially glean information about the underlying system and give an attacker information that could be used to attempt to… | |
| Analizada | Media (5.7) | 0.37% | — | Tenable Security Center | 23/2/2026 | 17/6/2026 | An improper access control vulnerability exists where an authenticated user could access areas outside of their authorized scope. | |
| Analizada | Baja (2.1) | 0.38% | — | Tenable Security Center | 23/2/2026 | 17/6/2026 | An Indirect Object Reference (IDOR) in Security Center allows an authenticated remote attacker to escalate privileges via the 'owner' parameter. | |
| Aplazada | Alta (7.4) | 1.8% | — | Tenable Security CenterAI | 17/2/2026 | 17/6/2026 | A Command Injection vulnerability exists where an authenticated, remote attacker could execute arbitrary code on the underlying server where Tenable Security Center is hosted. | |
| Analizada | Media (5.4) | 0.11% | — | Tenable Nessus Agent | 13/2/2026 | 17/6/2026 | A vulnerability has been identified where weak file permissions in the Nessus Agent directory on Windows hosts could allow unauthorized access, potentially permitting Denial of Service (DoS) attacks. | |
| Aplazada | Alta (7.3) | 0.13% | — | Tenable Nessus AgentAI | 13/1/2026 | 17/6/2026 | A vulnerability has been identified in the installation/uninstallation of the Nessus Agent Tray App on Windows Hosts which could lead to escalation of privileges. | |
| Aplazada | Media (4.3) | 0.19% | — | Tenable Security CenterAI | 8/10/2025 | 30/9/2026 | In Tenable Security Center versions prior to 6.7.0, an improper access control vulnerability exists where an authenticated user could access areas outside of their authorized scope. | |
| Analizada | Alta (7.1) | 0.19% | — | Tenable Nessus | 2/7/2025 | 17/6/2026 | In Tenable Nessus versions prior to 10.8.5 on a Windows host, it was found that a non-administrative user could overwrite arbitrary local system files with log content at SYSTEM privilege. | |
| Analizada | Alta (7.8) | 0.20% | — | Tenable Nessus Agent | 16/6/2025 | 17/6/2026 | In Tenable Agent versions prior to 10.8.5 on a Windows host, it was found that a non-administrative user could execute code with SYSTEM privilege. | |
| Analizada | Alta (7.8) | 0.18% | — | Tenable Nessus Agent | 13/6/2025 | 17/6/2026 | In Tenable Agent versions prior to 10.8.5 on a Windows host, it was found that a non-administrative user could arbitrarily delete local system files with SYSTEM privilege, potentially leading to local privilege escalation. | |
| Analizada | Alta (7.8) | 0.17% | — | Tenable Nessus Agent | 13/6/2025 | 17/6/2026 | In Tenable Agent versions prior to 10.8.5 on a Windows host, it was found that a non-administrative user could overwrite arbitrary local system files with log content at SYSTEM privilege. | |
| Analizada | Alta (7.8) | 0.16% | — | Tenable Nessus Network Monitor | 23/5/2025 | 17/6/2026 | In Tenable Network Monitor versions prior to 6.5.1 on a Windows host, it was found that a non-administrative user could stage files in a local directory to run arbitrary code with SYSTEM privileges, potentially leading to local privilege escalation. | |
| Analizada | Alta (7.8) | 0.15% | — | Tenable Nessus Network Monitor | 23/5/2025 | 17/6/2026 | When installing Tenable Network Monitor to a non-default location on a Windows host, Tenable Network Monitor versions prior to 6.5.1 did not enforce secure permissions for sub-directories. This could allow for local privilege escalation if users had not secured the directories in the non-default installation location. | |
| Aplazada | Media (4.3) | 0.29% | — | Tenable NessusAI | 18/4/2025 | 17/6/2026 | In Nessus versions prior to 10.8.4, a non-authenticated attacker could alter Nessus logging entries by manipulating http requests to the application. | |
| Aplazada | Alta (7.8) | 0.15% | — | Tenable NessusAI | 18/4/2025 | 17/6/2026 | When installing Nessus to a non-default location on a Windows host, Nessus versions prior to 10.8.4 did not enforce secure permissions for sub-directories. This could allow for local privilege escalation if users had not secured the directories in the non-default installation location. - CVE-2025-24914 | |
| Aplazada | Alta (7.8) | 0.18% | — | Tenable Nessus AgentAI | 21/3/2025 | 17/6/2026 | When installing Nessus Agent to a non-default location on a Windows host, Nessus Agent versions prior to 10.8.3 did not enforce secure permissions for sub-directories. This could allow for local privilege escalation if users had not secured the directories in the non-default installation location. | |
| Analizada | Media (5.4) | 0.30% | — | Bmltenabled Meeting MAP | 24/1/2025 | 17/6/2026 | The BMLT Meeting Map plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'bmlt_meeting_map' shortcode in all versions up to, and including, 2.6.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers,… | |
| Analizada | Alta (8.8) | 0.72% | — | Bmltenabled Meeting MAP | 23/1/2025 | 17/6/2026 | The BMLT Meeting Map plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.6.0 via the 'bmlt_meeting_map' shortcode. This makes it possible for authenticated attackers, with Contributor-level access and above, to include and execute arbitrary files on the server, allowing… | |
| Aplazada | Baja (2.7) | 0.18% | — | Tenable Security CenterAI | 9/12/2024 | 17/6/2026 | An Improper Certificate Validation vulnerability exists in Tenable Security Center where an authenticated, privileged attacker could intercept email messages sent from Security Center via a rogue SMTP server. | |
| Analizada | Media (4.6) | 0.32% | — | Tenable Nessus Network Monitor | 30/9/2024 | 17/6/2026 | A stored cross site scripting vulnerability exists in Nessus Network Monitor where an authenticated, privileged local attacker could inject arbitrary code into the NNM UI via the local CLI. | |
| Analizada | Media (6.8) | 0.47% | — | Tenable Identity Exposure | 16/7/2024 | 17/6/2026 | A formula injection vulnerability exists in Tenable Identity Exposure where an authenticated remote attacker with administrative privileges could manipulate application form fields in order to trick another administrator into executing CSV payloads. - CVE-2024-3232 | |
| Modificada | Media (6.3) | 0.30% | — | Tenable Security Center | 12/6/2024 | 17/6/2026 | An improper privilege management vulnerability exists in Tenable Security Center where an authenticated, remote attacker could view unauthorized objects and launch scans without having the required privileges |