Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 554 respecto a la semana anterior
Críticas / altas1325▼ 178 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 242 respecto a la semana anterior
197 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.4) | 0.51% | — | Tenable Appliance | 28/3/2018 | 17/6/2026 | Tenable Appliance versions 4.6.1 and earlier have been found to contain a single XSS vulnerability. Utilizing a specially crafted request, an authenticated attacker could potentially execute arbitrary JavaScript code by manipulating certain URL parameters related to offline plugins. | |
| Modificada | Alta (7) | 0.23% | — | Tenable Nessus | 20/3/2018 | 17/6/2026 | When installing Nessus to a directory outside of the default location, Nessus versions prior to 7.0.3 did not enforce secure permissions for sub-directories. This could allow for local privilege escalation if users had not secured the directories in the installation location. | |
| Modificada | Alta (7.5) | 3.6% | — | Momentjs MomentTenable Nessus | 4/3/2018 | 17/6/2026 | The moment module before 2.19.3 for Node.js is prone to a regular expression denial of service via a crafted date string, a different vulnerability than CVE-2016-4055. | |
| Modificada | Alta (8.8) | 1.2% | — | Tenable Security Center | 2/11/2017 | 17/8/2026 | SecurityCenter versions 5.5.0, 5.5.1 and 5.5.2 contain a SQL Injection vulnerability that could be exploited by an authenticated user with sufficient privileges to run diagnostic scans. An attacker could exploit this vulnerability by entering a crafted SQL query into the password field of a diagnostic scan within… | |
| Modificada | Alta (7.4) | 0.57% | — | Tenable Nessus | 9/8/2017 | 17/6/2026 | When linking a Nessus scanner or agent to Tenable.io or other manager, Nessus 6.x before 6.11 does not verify the manager's TLS certificate when making the initial outgoing connection. This could allow man-in-the-middle attacks. | |
| Modificada | Media (5.4) | 0.78% | — | Tenable Nessus | 12/5/2017 | 17/6/2026 | Cross-site scripting vulnerability in Nessus versions 6.8.0, 6.8.1, 6.9.0, 6.9.1 and 6.9.2 allows remote authenticated attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Crítica (9.8) | 16% | 💥 Exploit | Tenable Appliance | 21/4/2017 | 17/6/2026 | Tenable Appliance 3.5 - 4.4.0, and possibly prior versions, contains a flaw in the simpleupload.py script in the Web UI. Through the manipulation of the tns_appliance_session_user parameter, a remote attacker can inject arbitrary commands. | |
| Modificada | Alta (7.5) | 0.87% | — | Tenable Appliance | 21/4/2017 | 17/6/2026 | Tenable Appliance 4.4.0, and possibly prior, contains a flaw in the Web UI that allows for the unauthorized manipulation of the admin password. | |
| Modificada | Alta (7.8) | 0.28% | — | Tenable Nessus | 19/4/2017 | 17/6/2026 | Nessus 6.10.x before 6.10.5 was found to be vulnerable to a local privilege escalation issue due to insecure permissions when running in Agent Mode. | |
| Modificada | Media (5.5) | 0.25% | — | Tenable Nessus | 19/4/2017 | 17/6/2026 | Nessus 6.10.x before 6.10.5 was found to be vulnerable to a local denial of service condition due to insecure permissions when running in Agent Mode. | |
| Modificada | Alta (7.8) | 0.36% | — | Tenable Nessus | 23/3/2017 | 17/6/2026 | Nessus 6.6.2 - 6.10.3 contains a flaw related to insecure permissions that may allow a local attacker to escalate privileges when the software is running in Agent Mode. Version 6.10.4 fixes this issue. | |
| Modificada | Alta (7.3) | 0.84% | — | Tenable NessusTenable Appliance | 8/3/2017 | 17/6/2026 | Tenable Nessus before 6.10.2 (as used alone or in Tenable Appliance before 4.5.0) was found to contain a flaw that allowed a remote, authenticated attacker to upload a crafted file that could be written to anywhere on the system. This could be used to subsequently gain elevated privileges on the system (e.g., after a… | |
| Modificada | Media (5.4) | 0.70% | — | Tenable LOG Correlation Engine | 28/2/2017 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in Tenable Log Correlation Engine (aka LCE) before 4.8.1 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Media (5.4) | 0.87% | — | Tenable Nessus | 28/2/2017 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in Tenable Nessus before 6.9.1 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Media (5.4) | 1.3% | — | Tenable Nessus | 31/1/2017 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in Tenable Nessus before 6.9 allows remote authenticated users to inject arbitrary web script or HTML via vectors related to handling of .nessus files. | |
| Modificada | Media (6.5) | 9.9% | — | Momentjs MomentTenable NessusOracle Primavera Unifier | 23/1/2017 | 17/6/2026 | The duration function in the moment package before 2.11.2 for Node.js allows remote attackers to cause a denial of service (CPU consumption) via a long string, aka a "regular expression Denial of Service (ReDoS)." | |
| Modificada | Media (5.4) | 1.2% | — | Tenable Nessus | 5/1/2017 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in Tenable Nessus before 6.9.3 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Crítica (9.8) | 7.0% | — | HP Icewall Federation AgentApple WatchosApple MAC OS XXmlsoft Libxml2+15 | 9/6/2016 | 17/6/2026 | Format string vulnerability in libxml2 before 2.9.4 allows attackers to have unspecified impact via format string specifiers in unknown vectors. | |
| Modificada | Media (4.3) | 3.3% | 💥 Exploit | Tenable WEB UI | 21/10/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the Web UI before 2.3.4 Build #85 for Tenable Nessus 5.x allows remote web servers to inject arbitrary web script or HTML via the server header. | |
| Modificada | Media (5) | 1.7% | — | Tenable NessusTenable WEB UI | 23/7/2014 | 17/6/2026 | The /server/properties resource in Tenable Web UI before 2.3.5 for Nessus 5.2.3 through 5.2.7 allows remote attackers to obtain sensitive information via the token parameter. | |
| Modificada | Media (6.9) | 0.24% | — | Tenable NessusTenable Plugin-set | 11/4/2014 | 17/6/2026 | A race condition in the wmi_malware_scan.nbin plugin before 201402262215 for Nessus 5.2.1 allows local users to gain privileges by replacing the dissolvable agent executable in the Windows temp directory with a Trojan horse program. | |
| Modificada | Media (4.3) | 0.93% | — | Tenable Security Center | 24/9/2013 | 17/8/2026 | Cross-site scripting (XSS) vulnerability in devform.php in Tenable SecurityCenter 4.6 through 4.7 allows remote attackers to inject arbitrary web script or HTML via the message parameter. |