Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2855▼ 333 respecto a la semana anterior
Críticas / altas1381▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 213 respecto a la semana anterior
114 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.5) | 1.8% | — | Tenable Nessus | 23/10/2019 | 17/6/2026 | Nessus versions 8.6.0 and earlier were found to contain a Denial of Service vulnerability due to improper validation of specific imported scan types. An authenticated, remote attacker could potentially exploit this vulnerability to cause a Nessus scanner to become temporarily unresponsive. | |
| Modificada | Media (6.5) | 4.3% | — | SqliteNetapp Active IQ Unified ManagerNetapp E-series Santricity OS ControllerNetapp Oncommand Insight+16 | 9/9/2019 | 17/6/2026 | In SQLite through 3.29.0, whereLoopAddBtreeIndex in sqlite3.c can crash a browser or other application because of missing validation of a sqlite_stat1 sz field, aka a "severe division by zero in the query planner." | |
| Modificada | Alta (8.1) | 1.8% | — | Tenable Nessus | 15/8/2019 | 17/6/2026 | Nessus 8.5.2 and earlier on Windows platforms were found to contain an issue where certain system files could be overwritten arbitrarily, potentially creating a denial of service condition. | |
| Modificada | Baja (3.3) | 0.95% | — | Tenable Nessus | 1/7/2019 | 17/6/2026 | Content Injection vulnerability in Tenable Nessus prior to 8.5.0 may allow an authenticated, local attacker to exploit this vulnerability by convincing another targeted Nessus user to view a malicious URL and use Nessus to send fraudulent messages. Successful exploitation could allow the authenticated adversary to… | |
| Modificada | Media (6.1) | 1.5% | — | Tenable Nessus | 25/6/2019 | 17/6/2026 | Nessus versions 8.4.0 and earlier were found to contain a reflected XSS vulnerability due to improper validation of user-supplied input. An unauthenticated, remote attacker could potentially exploit this vulnerability via a specially crafted request to execute arbitrary script code in a users browser session. | |
| Modificada | Alta (7.5) | 7.1% | — | Libexpat Project LibexpatCanonical Ubuntu LinuxDebian LinuxFedoraproject Fedora+5 | 24/6/2019 | 17/6/2026 | In libexpat in Expat before 2.2.7, XML input including XML names that contain a large number of colons could make the XML parser consume a high amount of RAM and CPU resources while processing (enough to be usable for denial-of-service attacks). | |
| Modificada | Media (5.9) | 17% | — | OpensslCanonical Ubuntu LinuxDebian LinuxNetapp Active IQ Unified Manager+78 | 27/2/2019 | 17/6/2026 | If an application encounters a fatal protocol error and then calls SSL_shutdown() twice (once to send a close_notify, and once to receive one) then OpenSSL can respond differently to the calling application if a 0 byte record is received with invalid padding compared to if a 0 byte record is received with an invalid… | |
| Modificada | Media (5.4) | 0.88% | — | Tenable Nessus | 12/2/2019 | 17/6/2026 | Nessus versions 8.2.1 and earlier were found to contain a stored XSS vulnerability due to improper validation of user-supplied input. An authenticated, remote attacker could potentially exploit this vulnerability via a specially crafted request to execute arbitrary script code in a user's browser session. Tenable has… | |
| Modificada | Media (4.7) | 3.4% | 💥 Exploit | Canonical Ubuntu LinuxDebian LinuxNodejs Node.jsOpenssl+16 | 15/11/2018 | 17/6/2026 | Simultaneous Multi-threading (SMT) in processors can enable local users to exploit software vulnerable to timing attacks via a side-channel timing attack on 'port contention'. | |
| Modificada | Media (6.5) | 0.73% | — | Tenable Nessus | 18/5/2018 | 17/6/2026 | In Nessus before 7.1.0, Session Fixation exists due to insufficient session management within the application. An authenticated attacker could maintain system access due to session fixation after a user password change. | |
| Modificada | Media (5.4) | 1.1% | — | Tenable Nessus | 18/5/2018 | 17/6/2026 | In Nessus before 7.1.0, a XSS vulnerability exists due to improper input validation. A remote authenticated attacker could create and upload a .nessus file, which may be viewed by an administrator allowing for the execution of arbitrary script code in a user's browser session. In other scenarios, XSS could also occur… | |
| Modificada | Alta (7) | 0.23% | — | Tenable Nessus | 20/3/2018 | 17/6/2026 | When installing Nessus to a directory outside of the default location, Nessus versions prior to 7.0.3 did not enforce secure permissions for sub-directories. This could allow for local privilege escalation if users had not secured the directories in the installation location. | |
| Modificada | Alta (7.5) | 3.6% | — | Momentjs MomentTenable Nessus | 4/3/2018 | 17/6/2026 | The moment module before 2.19.3 for Node.js is prone to a regular expression denial of service via a crafted date string, a different vulnerability than CVE-2016-4055. | |
| Modificada | Alta (7.4) | 0.57% | — | Tenable Nessus | 9/8/2017 | 17/6/2026 | When linking a Nessus scanner or agent to Tenable.io or other manager, Nessus 6.x before 6.11 does not verify the manager's TLS certificate when making the initial outgoing connection. This could allow man-in-the-middle attacks. | |
| Modificada | Media (5.4) | 0.78% | — | Tenable Nessus | 12/5/2017 | 17/6/2026 | Cross-site scripting vulnerability in Nessus versions 6.8.0, 6.8.1, 6.9.0, 6.9.1 and 6.9.2 allows remote authenticated attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Alta (7.8) | 0.28% | — | Tenable Nessus | 19/4/2017 | 17/6/2026 | Nessus 6.10.x before 6.10.5 was found to be vulnerable to a local privilege escalation issue due to insecure permissions when running in Agent Mode. | |
| Modificada | Media (5.5) | 0.25% | — | Tenable Nessus | 19/4/2017 | 17/6/2026 | Nessus 6.10.x before 6.10.5 was found to be vulnerable to a local denial of service condition due to insecure permissions when running in Agent Mode. | |
| Modificada | Alta (7.8) | 0.36% | — | Tenable Nessus | 23/3/2017 | 17/6/2026 | Nessus 6.6.2 - 6.10.3 contains a flaw related to insecure permissions that may allow a local attacker to escalate privileges when the software is running in Agent Mode. Version 6.10.4 fixes this issue. | |
| Modificada | Alta (7.3) | 0.84% | — | Tenable NessusTenable Appliance | 8/3/2017 | 17/6/2026 | Tenable Nessus before 6.10.2 (as used alone or in Tenable Appliance before 4.5.0) was found to contain a flaw that allowed a remote, authenticated attacker to upload a crafted file that could be written to anywhere on the system. This could be used to subsequently gain elevated privileges on the system (e.g., after a… | |
| Modificada | Media (5.4) | 0.87% | — | Tenable Nessus | 28/2/2017 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in Tenable Nessus before 6.9.1 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Media (5.4) | 1.3% | — | Tenable Nessus | 31/1/2017 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in Tenable Nessus before 6.9 allows remote authenticated users to inject arbitrary web script or HTML via vectors related to handling of .nessus files. | |
| Modificada | Media (6.5) | 9.9% | — | Momentjs MomentTenable NessusOracle Primavera Unifier | 23/1/2017 | 17/6/2026 | The duration function in the moment package before 2.11.2 for Node.js allows remote attackers to cause a denial of service (CPU consumption) via a long string, aka a "regular expression Denial of Service (ReDoS)." | |
| Modificada | Media (5.4) | 1.2% | — | Tenable Nessus | 5/1/2017 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in Tenable Nessus before 6.9.3 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Media (5) | 1.7% | — | Tenable NessusTenable WEB UI | 23/7/2014 | 17/6/2026 | The /server/properties resource in Tenable Web UI before 2.3.5 for Nessus 5.2.3 through 5.2.7 allows remote attackers to obtain sensitive information via the token parameter. | |
| Modificada | Media (6.9) | 0.24% | — | Tenable NessusTenable Plugin-set | 11/4/2014 | 17/6/2026 | A race condition in the wmi_malware_scan.nbin plugin before 201402262215 for Nessus 5.2.1 allows local users to gain privileges by replacing the dissolvable agent executable in the Windows temp directory with a Trojan horse program. |