Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

198 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.4)0.30%—Tenable Security Center12/6/202417/6/2026
A stored cross site scripting vulnerability exists in Tenable Security Center where an authenticated, remote attacker could inject HTML code into a web application scan result page.
AplazadaAlta (8.2)0.17%—Tenable NessusAI17/5/202417/6/2026
A race condition vulnerability exists where an authenticated, local attacker on a Windows Nessus Agent host could modify installation parameters at installation time, which could lead to the execution of arbitrary code on the Nessus host. - CVE-2024-3292
AplazadaAlta (7.8)0.18%—Tenable Nessus AgentAI17/5/202417/6/2026
When installing Nessus Agent to a directory outside of the default location on a Windows host, Nessus Agent versions prior to 10.6.4 did not enforce secure permissions for sub-directories. This could allow for local privilege escalation if users had not secured the directories in the non-default installation location.
AplazadaAlta (8.2)0.18%—Tenable NessusAI17/5/202417/6/2026
A race condition vulnerability exists where an authenticated, local attacker on a Windows Nessus host could modify installation parameters at installation time, which could lead to the execution of arbitrary code on the Nessus host
AplazadaAlta (7.8)0.18%—Tenable NessusAI17/5/202417/6/2026
When installing Nessus to a directory outside of the default location on a Windows host, Nessus versions prior to 10.7.3 did not enforce secure permissions for sub-directories. This could allow for local privilege escalation if users had not secured the directories in the non-default installation location.
AplazadaAlta (7.8)0.19%—Tenable NessusAI18/3/202417/6/2026
As a part of Tenable’s vulnerability disclosure program, a vulnerability in a Nessus plugin was identified and reported. This vulnerability could allow a malicious actor with sufficient permissions on a scan target to place a binary in a specific filesystem location, and abuse the impacted plugin in order to escalate…
AnalizadaAlta (7.3)0.31%—Tenable Identity Exposure23/2/202417/6/2026
A DLL injection vulnerability exists where an authenticated, low-privileged local attacker could modify application files on the TIE Secure Relay host, which could allow for overriding of the configuration and running of new Secure Relay services.
ModificadaMedia (4.8)0.41%—Tenable Security Center14/2/202417/6/2026
An HTML injection vulnerability exists where an authenticated, remote attacker with administrator privileges on the Security Center application could modify Repository parameters, which could lead to HTML redirection attacks.
ModificadaAlta (7.2)1.6%—Tenable Security Center14/2/202417/6/2026
A command injection vulnerability exists where an authenticated, remote attacker with administrator privileges on the Security Center application could modify Logging parameters, which could lead to the execution of arbitrary code on the Security Center host.
ModificadaMedia (6.5)0.78%—Tenable Nessus7/2/202417/6/2026
A SQL injection vulnerability exists where an authenticated, low-privileged remote attacker could potentially alter scan DB content.
ModificadaMedia (4.8)0.56%—Tenable Nessus7/2/202417/6/2026
A stored XSS vulnerability exists where an authenticated, remote attacker with administrator privileges on the Nessus application could alter Nessus proxy settings, which could lead to the execution of remote arbitrary scripts.
ModificadaMedia (6.5)0.83%—Tenable Nessus20/11/202317/6/2026
An arbitrary file write vulnerability exists where an authenticated attacker with privileges on the managing application could alter Nessus Rules variables to overwrite arbitrary files on the remote host, which could lead to a denial of service condition.
ModificadaMedia (6.5)1.0%—Tenable Nessus20/11/202317/6/2026
An arbitrary file write vulnerability exists where an authenticated, remote attacker with administrator privileges on the Nessus application could alter Nessus Rules variables to overwrite arbitrary files on the remote host, which could lead to a denial of service condition.
ModificadaAlta (7.3)0.22%—Tenable NessusTenable Nessus Agent1/11/202317/6/2026
Under certain conditions, a low privileged attacker could load a specially crafted file during installation or upgrade to escalate privileges on Windows and Linux hosts.
ModificadaAlta (7.2)0.48%—Tenable Nessus Network Monitor26/10/202317/6/2026
Under certain conditions, Nessus Network Monitor was found to not properly enforce input validation. This could allow an admin user to alter parameters that could potentially allow a blindSQL injection.
ModificadaAlta (7.8)0.15%—Tenable Nessus Network Monitor26/10/202317/6/2026
NNM failed to properly set ACLs on its installation directory, which could allow a low privileged user to run arbitrary code with SYSTEM privileges where NNM is installed to a non-standard location
ModificadaAlta (8.8)0.47%—Tenable Nessus Network Monitor26/10/202317/6/2026
Under certain conditions, Nessus Network Monitor could allow a low privileged user to escalate privileges to NT AUTHORITY\SYSTEM on Windows hosts by replacing a specially crafted file.
ModificadaMedia (4.3)0.52%—Tenable Nessus29/8/202317/6/2026
An improper authorization vulnerability exists where an authenticated, low privileged remote attacker could view a list of all the users available in the application.
ModificadaMedia (6.5)0.80%—Tenable Nessus29/8/202317/6/2026
An arbitrary file write vulnerability exists where an authenticated, remote attacker with administrator privileges could alter logging variables to overwrite arbitrary files on the remote host with log data, which could lead to a denial of service condition.
ModificadaMedia (4.9)0.61%—Tenable Nessus29/8/202317/6/2026
A pass-back vulnerability exists where an authenticated, remote attacker with administrator privileges could uncover stored SMTP credentials within the Nessus application.This issue affects Nessus: before 10.6.0.
ModificadaAlta (8.8)0.38%—Tenable NessusTenable Security CenterTenable.io26/6/202317/8/2026
Vulnerability in Tenable Tenable.Io, Tenable Nessus, Tenable Security Center.This issue affects Tenable.Io: before Plugin Feed ID #202306261202 ; Nessus: before Plugin Feed ID #202306261202 ; Security Center: before Plugin Feed ID #202306261202 . This vulnerability could allow a malicious actor with sufficient…
ModificadaAlta (8.8)1.2%—Tenable NessusTenable Plugin Feed15/3/202317/6/2026
A vulnerability was reported where through modifying the scan variables, an authenticated user in Tenable products, that has Scan Policy Configuration roles, could manipulate audit policy variables to execute arbitrary commands on credentialed scan targets.
ModificadaAlta (8.8)0.64%—Tenable NessusTenable.ioTenable.sc1/2/202317/6/2026
As part of our Security Development Lifecycle, a potential privilege escalation issue was identified internally. This could allow a malicious actor with sufficient permissions to modify environment variables and abuse an impacted plugin in order to escalate privileges. We have resolved the issue and also made several…
ModificadaMedia (6.5)0.89%—Tenable.sc26/1/202317/6/2026
A Server Side Request Forgery (SSRF) vulnerability exists in Tenable.sc due to improper validation of session & user-accessible input data. A privileged, authenticated remote attacker could interact with external and internal services covertly.
ModificadaMedia (5.4)0.69%—Tenable.sc26/1/202317/6/2026
A stored cross-site scripting (XSS) vulnerability exists in Tenable.sc due to improper validation of user-supplied input before returning it to users. An authenticated, remote attacker can exploit this by convincing a user to click a specially crafted URL, to execute arbitrary script code in a user's browser session.
Orbitaley — Vulnerabilidades