VulnSea

tenable has 8 CVEs on record between 2013 and 2026. 1 was published in the last 90 days. The median CVSS is 7.0 (high), with 1 rated critical. None have a confirmed exploitation report. Most affected products: security_center (4), nessus (2), nessus_agent (1).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
7.0
Publish → KEV
Last 90 days
1 prev 1

Products

  • security_center 4
  • nessus 2
  • nessus_agent 1
  • operational_technology_exposure 1
8
Total CVEs
1
Critical
0
CISA KEV
0
Exploited

tenable vulnerabilities

CVEs affecting tenable, newest first. Open any entry for full detail, references, and exploit status.

8 CVEsRSS

CVE-2026-15265Critical· 9.1
2mo ago

A path traversal vulnerability in Tenable Agent 11.2.0 and 11.1.3 and lower allows a privileged attacker to write arbitrary files outside the intended plugin directory, potentially leading to remote code execution.

A path traversal vulnerability in Tenable Agent 11.2.0 and 11.1.3 and lower allows a privileged attacker to write arbitrary files outside the intended plugin directory, potentially leading to remote code execution.

Midnighttenable · nessus_agentEPSS 0.56%via NVD
CVE-2026-33694High· 7.8
5mo ago

This vulnerability allows an attacker to create a junction, enabling the deletion of arbitrary files with SYSTEM privileges

This vulnerability allows an attacker to create a junction, enabling the deletion of arbitrary files with SYSTEM privileges. As a result, this condition potentially facilitates arbitrary code execution, whereby an attacker may exploit th…

Twilighttenable · nessusEPSS 0.15%via NVD
CVE-2026-4433Medium· 4.3
6mo ago

An SSH misconfigurations exists in Tenable OT that led to the potential exfiltration of socket, port, and service information via the ostunnel user and GatewayPorts

An SSH misconfigurations exists in Tenable OT that led to the potential exfiltration of socket, port, and service information via the ostunnel user and GatewayPorts. This could be used to potentially glean information about the underlyin…

Sunlittenable · operational_technology_exposureEPSS 0.16%via NVD
CVE-2023-2005Medium· 6.3
3y ago

Vulnerability in Tenable Tenable.Io, Tenable Nessus, Tenable Security Center.This issue affects Tenable.Io: before Plugin Feed ID #202306261202 ; Nessus: before Plugin Feed ID #202306261202 ; Security Center: before Plugin Feed ID #20230…

Vulnerability in Tenable Tenable.Io, Tenable Nessus, Tenable Security Center.This issue affects Tenable.Io: before Plugin Feed ID #202306261202 ; Nessus: before Plugin Feed ID #202306261202 ; Security Center: before Plugin Feed ID #20230…

Sunlittenable · nessusEPSS 0.38%via NVD
CVE-2018-1155Medium· 5.4
8y ago

In SecurityCenter versions prior to 5.7.0, a cross-site scripting (XSS) issue could allow an authenticated attacker to inject JavaScript code into an image filename parameter within the Reports feature area

In SecurityCenter versions prior to 5.7.0, a cross-site scripting (XSS) issue could allow an authenticated attacker to inject JavaScript code into an image filename parameter within the Reports feature area. Properly updated input valida…

Sunlittenable · security_centerEPSS 0.77%via NVD
CVE-2018-1154High· 8.8
8y ago

In SecurityCenter versions prior to 5.7.0, a username enumeration issue could allow an unauthenticated attacker to automate the discovery of username aliases via brute force, ultimately facilitating unauthorized access

In SecurityCenter versions prior to 5.7.0, a username enumeration issue could allow an unauthenticated attacker to automate the discovery of username aliases via brute force, ultimately facilitating unauthorized access. Server response o…

Twilighttenable · security_centerEPSS 0.49%via NVD
CVE-2017-11508High· 8.8
8y ago

SecurityCenter versions 5.5.0, 5.5.1 and 5.5.2 contain a SQL Injection vulnerability that could be exploited by an authenticated user with sufficient privileges to run diagnostic scans

SecurityCenter versions 5.5.0, 5.5.1 and 5.5.2 contain a SQL Injection vulnerability that could be exploited by an authenticated user with sufficient privileges to run diagnostic scans. An attacker could exploit this vulnerability by ent…

Twilighttenable · security_centerEPSS 1.0%via NVD
CVE-2013-5911Medium· 4.3
13y ago

Cross-site scripting (XSS) vulnerability in devform.php in Tenable SecurityCenter 4.6 through 4.7 allows remote attackers to inject arbitrary web script or HTML via the message parameter.

Cross-site scripting (XSS) vulnerability in devform.php in Tenable SecurityCenter 4.6 through 4.7 allows remote attackers to inject arbitrary web script or HTML via the message parameter.

Sunlittenable · security_centerEPSS 0.93%via NVD
tenable vulnerabilities (CVEs) · VulnSea