Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2768▼ 554 respecto a la semana anterior
Críticas / altas1325▼ 178 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 242 respecto a la semana anterior
–

197 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.4)0.51%—Tenable Appliance28/3/201817/6/2026
Tenable Appliance versions 4.6.1 and earlier have been found to contain a single XSS vulnerability. Utilizing a specially crafted request, an authenticated attacker could potentially execute arbitrary JavaScript code by manipulating certain URL parameters related to offline plugins.
ModificadaAlta (7)0.23%—Tenable Nessus20/3/201817/6/2026
When installing Nessus to a directory outside of the default location, Nessus versions prior to 7.0.3 did not enforce secure permissions for sub-directories. This could allow for local privilege escalation if users had not secured the directories in the installation location.
ModificadaAlta (7.5)3.6%—Momentjs MomentTenable Nessus4/3/201817/6/2026
The moment module before 2.19.3 for Node.js is prone to a regular expression denial of service via a crafted date string, a different vulnerability than CVE-2016-4055.
ModificadaAlta (8.8)1.2%—Tenable Security Center2/11/201717/8/2026
SecurityCenter versions 5.5.0, 5.5.1 and 5.5.2 contain a SQL Injection vulnerability that could be exploited by an authenticated user with sufficient privileges to run diagnostic scans. An attacker could exploit this vulnerability by entering a crafted SQL query into the password field of a diagnostic scan within…
ModificadaAlta (7.4)0.57%—Tenable Nessus9/8/201717/6/2026
When linking a Nessus scanner or agent to Tenable.io or other manager, Nessus 6.x before 6.11 does not verify the manager's TLS certificate when making the initial outgoing connection. This could allow man-in-the-middle attacks.
ModificadaMedia (5.4)0.78%—Tenable Nessus12/5/201717/6/2026
Cross-site scripting vulnerability in Nessus versions 6.8.0, 6.8.1, 6.9.0, 6.9.1 and 6.9.2 allows remote authenticated attackers to inject arbitrary web script or HTML via unspecified vectors.
ModificadaCrítica (9.8)16%💥 ExploitTenable Appliance21/4/201717/6/2026
Tenable Appliance 3.5 - 4.4.0, and possibly prior versions, contains a flaw in the simpleupload.py script in the Web UI. Through the manipulation of the tns_appliance_session_user parameter, a remote attacker can inject arbitrary commands.
ModificadaAlta (7.5)0.87%—Tenable Appliance21/4/201717/6/2026
Tenable Appliance 4.4.0, and possibly prior, contains a flaw in the Web UI that allows for the unauthorized manipulation of the admin password.
ModificadaAlta (7.8)0.28%—Tenable Nessus19/4/201717/6/2026
Nessus 6.10.x before 6.10.5 was found to be vulnerable to a local privilege escalation issue due to insecure permissions when running in Agent Mode.
ModificadaMedia (5.5)0.25%—Tenable Nessus19/4/201717/6/2026
Nessus 6.10.x before 6.10.5 was found to be vulnerable to a local denial of service condition due to insecure permissions when running in Agent Mode.
ModificadaAlta (7.8)0.36%—Tenable Nessus23/3/201717/6/2026
Nessus 6.6.2 - 6.10.3 contains a flaw related to insecure permissions that may allow a local attacker to escalate privileges when the software is running in Agent Mode. Version 6.10.4 fixes this issue.
ModificadaAlta (7.3)0.84%—Tenable NessusTenable Appliance8/3/201717/6/2026
Tenable Nessus before 6.10.2 (as used alone or in Tenable Appliance before 4.5.0) was found to contain a flaw that allowed a remote, authenticated attacker to upload a crafted file that could be written to anywhere on the system. This could be used to subsequently gain elevated privileges on the system (e.g., after a…
ModificadaMedia (5.4)0.70%—Tenable LOG Correlation Engine28/2/201717/6/2026
Cross-site scripting (XSS) vulnerability in Tenable Log Correlation Engine (aka LCE) before 4.8.1 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
ModificadaMedia (5.4)0.87%—Tenable Nessus28/2/201717/6/2026
Cross-site scripting (XSS) vulnerability in Tenable Nessus before 6.9.1 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
ModificadaMedia (5.4)1.3%—Tenable Nessus31/1/201717/6/2026
Cross-site scripting (XSS) vulnerability in Tenable Nessus before 6.9 allows remote authenticated users to inject arbitrary web script or HTML via vectors related to handling of .nessus files.
ModificadaMedia (6.5)9.9%—Momentjs MomentTenable NessusOracle Primavera Unifier23/1/201717/6/2026
The duration function in the moment package before 2.11.2 for Node.js allows remote attackers to cause a denial of service (CPU consumption) via a long string, aka a "regular expression Denial of Service (ReDoS)."
ModificadaMedia (5.4)1.2%—Tenable Nessus5/1/201717/6/2026
Cross-site scripting (XSS) vulnerability in Tenable Nessus before 6.9.3 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
ModificadaCrítica (9.8)7.0%—HP Icewall Federation AgentApple WatchosApple MAC OS XXmlsoft Libxml2+159/6/201617/6/2026
Format string vulnerability in libxml2 before 2.9.4 allows attackers to have unspecified impact via format string specifiers in unknown vectors.
ModificadaMedia (4.3)3.3%💥 ExploitTenable WEB UI21/10/201417/6/2026
Cross-site scripting (XSS) vulnerability in the Web UI before 2.3.4 Build #85 for Tenable Nessus 5.x allows remote web servers to inject arbitrary web script or HTML via the server header.
ModificadaMedia (5)1.7%—Tenable NessusTenable WEB UI23/7/201417/6/2026
The /server/properties resource in Tenable Web UI before 2.3.5 for Nessus 5.2.3 through 5.2.7 allows remote attackers to obtain sensitive information via the token parameter.
ModificadaMedia (6.9)0.24%—Tenable NessusTenable Plugin-set11/4/201417/6/2026
A race condition in the wmi_malware_scan.nbin plugin before 201402262215 for Nessus 5.2.1 allows local users to gain privileges by replacing the dissolvable agent executable in the Windows temp directory with a Trojan horse program.
ModificadaMedia (4.3)0.93%—Tenable Security Center24/9/201317/8/2026
Cross-site scripting (XSS) vulnerability in devform.php in Tenable SecurityCenter 4.6 through 4.7 allows remote attackers to inject arbitrary web script or HTML via the message parameter.
Orbitaley — Vulnerabilidades