Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3028▼ 62 respecto a la semana anterior
Críticas / altas1422▲ 60 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

198 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaCrítica (9.2)0.59%—Tenable Terrascan19/5/202624/7/2026
Terrascan v1.18.3 and prior are vulnerable to Server-Side Request Forgery (SSRF) via the remote_url parameter in the remote directory scan endpoint (POST /v1/{iac}/{iacVersion}/{cloud}/remote/dir/scan) when running in server mode. An unauthenticated remote attacker can supply an attacker-controlled HTTP URL as…
AnalizadaAlta (8.7)0.61%—Tenable Terrascan19/5/202624/7/2026
Terrascan v1.18.3 and prior are vulnerable to Server-Side Request Forgery (SSRF) via the webhook_url parameter in the file scan endpoint (POST /v1/{iac}/{iacVersion}/{cloud}/local/file/scan) when running in server mode. An unauthenticated remote attacker can supply an arbitrary URL as the webhook_url multipart form…
AnalizadaAlta (7.4)0.20%—Tenable NessusTenable Nessus Agent23/4/202621/8/2026
This vulnerability allows an attacker to create a junction, enabling the deletion of arbitrary files with SYSTEM privileges. As a result, this condition potentially facilitates arbitrary code execution, whereby an attacker may exploit the vulnerability to execute malicious code with elevated SYSTEM privileges.
AnalizadaBaja (1.9)0.27%—Tenable Operational Technology Exposure24/3/202618/8/2026
An SSH misconfigurations exists in Tenable OT that led to the potential exfiltration of socket, port, and service information via the ostunnel user and GatewayPorts. This could be used to potentially glean information about the underlying system and give an attacker information that could be used to attempt to…
AnalizadaMedia (5.7)0.37%—Tenable Security Center23/2/202617/6/2026
An improper access control vulnerability exists where an authenticated user could access areas outside of their authorized scope.
AnalizadaBaja (2.1)0.38%—Tenable Security Center23/2/202617/6/2026
An Indirect Object Reference (IDOR) in Security Center allows an authenticated remote attacker to escalate privileges via the 'owner' parameter.
AplazadaAlta (7.4)1.8%—Tenable Security CenterAI17/2/202617/6/2026
A Command Injection vulnerability exists where an authenticated, remote attacker could execute arbitrary code on the underlying server where Tenable Security Center is hosted.
AnalizadaMedia (5.4)0.11%—Tenable Nessus Agent13/2/202617/6/2026
A vulnerability has been identified where weak file permissions in the Nessus Agent directory on Windows hosts could allow unauthorized access, potentially permitting Denial of Service (DoS) attacks.
AplazadaAlta (7.3)0.13%—Tenable Nessus AgentAI13/1/202617/6/2026
A vulnerability has been identified in the installation/uninstallation of the Nessus Agent Tray App on Windows Hosts which could lead to escalation of privileges.
AplazadaMedia (4.3)0.19%—Tenable Security CenterAI8/10/202530/9/2026
In Tenable Security Center versions prior to 6.7.0, an improper access control vulnerability exists where an authenticated user could access areas outside of their authorized scope.
AnalizadaAlta (7.1)0.19%—Tenable Nessus2/7/202517/6/2026
In Tenable Nessus versions prior to 10.8.5 on a Windows host, it was found that a non-administrative user could overwrite arbitrary local system files with log content at SYSTEM privilege.
AnalizadaAlta (7.8)0.20%—Tenable Nessus Agent16/6/202517/6/2026
In Tenable Agent versions prior to 10.8.5 on a Windows host, it was found that a non-administrative user could execute code with SYSTEM privilege.
AnalizadaAlta (7.8)0.18%—Tenable Nessus Agent13/6/202517/6/2026
In Tenable Agent versions prior to 10.8.5 on a Windows host, it was found that a non-administrative user could arbitrarily delete local system files with SYSTEM privilege, potentially leading to local privilege escalation.
AnalizadaAlta (7.8)0.17%—Tenable Nessus Agent13/6/202517/6/2026
In Tenable Agent versions prior to 10.8.5 on a Windows host, it was found that a non-administrative user could overwrite arbitrary local system files with log content at SYSTEM privilege.
AnalizadaAlta (7.8)0.16%—Tenable Nessus Network Monitor23/5/202517/6/2026
In Tenable Network Monitor versions prior to 6.5.1 on a Windows host, it was found that a non-administrative user could stage files in a local directory to run arbitrary code with SYSTEM privileges, potentially leading to local privilege escalation.
AnalizadaAlta (7.8)0.15%—Tenable Nessus Network Monitor23/5/202517/6/2026
When installing Tenable Network Monitor to a non-default location on a Windows host, Tenable Network Monitor versions prior to 6.5.1 did not enforce secure permissions for sub-directories. This could allow for local privilege escalation if users had not secured the directories in the non-default installation location.
AplazadaMedia (4.3)0.29%—Tenable NessusAI18/4/202517/6/2026
In Nessus versions prior to 10.8.4, a non-authenticated attacker could alter Nessus logging entries by manipulating http requests to the application.
AplazadaAlta (7.8)0.15%—Tenable NessusAI18/4/202517/6/2026
When installing Nessus to a non-default location on a Windows host, Nessus versions prior to 10.8.4 did not enforce secure permissions for sub-directories. This could allow for local privilege escalation if users had not secured the directories in the non-default installation location. - CVE-2025-24914
AplazadaAlta (7.8)0.18%—Tenable Nessus AgentAI21/3/202517/6/2026
When installing Nessus Agent to a non-default location on a Windows host, Nessus Agent versions prior to 10.8.3 did not enforce secure permissions for sub-directories. This could allow for local privilege escalation if users had not secured the directories in the non-default installation location.
AnalizadaMedia (5.4)0.30%—Bmltenabled Meeting MAP24/1/202517/6/2026
The BMLT Meeting Map plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'bmlt_meeting_map' shortcode in all versions up to, and including, 2.6.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers,…
AnalizadaAlta (8.8)0.72%—Bmltenabled Meeting MAP23/1/202517/6/2026
The BMLT Meeting Map plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.6.0 via the 'bmlt_meeting_map' shortcode. This makes it possible for authenticated attackers, with Contributor-level access and above, to include and execute arbitrary files on the server, allowing…
AplazadaBaja (2.7)0.18%—Tenable Security CenterAI9/12/202417/6/2026
An Improper Certificate Validation vulnerability exists in Tenable Security Center where an authenticated, privileged attacker could intercept email messages sent from Security Center via a rogue SMTP server.
AnalizadaMedia (4.6)0.32%—Tenable Nessus Network Monitor30/9/202417/6/2026
A stored cross site scripting vulnerability exists in Nessus Network Monitor where an authenticated, privileged local attacker could inject arbitrary code into the NNM UI via the local CLI.
AnalizadaMedia (6.8)0.47%—Tenable Identity Exposure16/7/202417/6/2026
A formula injection vulnerability exists in Tenable Identity Exposure where an authenticated remote attacker with administrative privileges could manipulate application form fields in order to trick another administrator into executing CSV payloads. - CVE-2024-3232
ModificadaMedia (6.3)0.30%—Tenable Security Center12/6/202417/6/2026
An improper privilege management vulnerability exists in Tenable Security Center where an authenticated, remote attacker could view unauthorized objects and launch scans without having the required privileges