tenable
37 known vulnerabilities affecting tenable products.
Products
security_center 26
tenable.sc 4
terrascan 3
nessus 2
nessus_agent 2
operational_technology_exposure 1
tenable.io 1
identity_exposure 1
Vulnerabilities by priority
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2021-40438 | Act now | 100.0% | 9.0 | ● | A crafted request uri-path can cause mod_proxy to forward the request to an orig… |
| CVE-2021-41184 | Medium | 40.8% | 6.5 | jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0… | |
| CVE-2021-41182 | Medium | 39.4% | 6.5 | jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0… | |
| CVE-2026-19681 | Medium | 7.8% | 9.9 | An authenticated command injection vulnerability exists in Security Center relat… | |
| CVE-2026-19682 | Medium | 2.8% | 9.9 | A command injection vulnerability exists in Security Center where a remote, unau… | |
| CVE-2026-19628 | Medium | 2.7% | 7.2 | A command injection vulnerability exists in Tenable Security Center. An authenti… | |
| CVE-2026-64879 | Medium | 2.3% | 9.9 | A filename supplied during file upload is not properly sanitized before being us… | |
| CVE-2026-64881 | Medium | 2.2% | 8.8 | The audit file upload handler does not sanitize filenames, allowing shell metach… | |
| CVE-2026-19626 | Medium | 1.4% | 9.9 | A remote code execution vulnerability exists in Tenable Security Center's report… | |
| CVE-2017-11508 | Medium | 1.2% | 8.8 | SecurityCenter versions 5.5.0, 5.5.1 and 5.5.2 contain a SQL Injection vulnerabi… | |
| CVE-2026-19679 | Medium | 1.1% | 8.8 | An input validation vulnerability exists in Security Center's file upload handli… | |
| CVE-2026-64878 | Medium | 0.8% | 9.9 | Unvalidated input in asset filter parameters allows shell metacharacters to esca… | |
| CVE-2018-1154 | Medium | 0.7% | 8.8 | In SecurityCenter versions prior to 5.7.0, a username enumeration issue could al… | |
| CVE-2026-13007 | Medium | 0.6% | 7.5 | Tenable Identity Exposure contains multiple unauthenticated API endpoints under … | |
| CVE-2026-15265 | Medium | 0.6% | 9.1 | A path traversal vulnerability in Tenable Agent 11.2.0 and 11.1.3 and lower allo… | |
| CVE-2026-47356 | Medium | 0.5% | 7.5 | Terrascan v1.18.3 and prior are vulnerable to Server-Side Request Forgery (SSRF)… | |
| CVE-2026-47357 | Medium | 0.5% | 7.5 | Terrascan v1.18.3 and prior are vulnerable to Server-Side Request Forgery (SSRF)… | |
| CVE-2026-47358 | Medium | 0.5% | 7.5 | Terrascan v1.18.3 and prior are vulnerable to Server-Side Request Forgery (SSRF)… | |
| CVE-2026-64877 | Medium | 0.3% | 8.4 | An authenticated non-admin user can exploit a SQL injection flaw in the ticketin… | |
| CVE-2026-64880 | Medium | 0.3% | 7.1 | Unsanitized user-supplied input in report filtering parameters is concatenated d… | |
| CVE-2026-19680 | Medium | 0.2% | 7.1 | A SQL injection vulnerability exists in Security Center that could allow an atta… | |
| CVE-2026-19629 | Medium | 0.2% | 8.1 | A privilege escalation vulnerability exists in Tenable Security Center that allo… | |
| CVE-2026-33694 | Medium | 0.2% | 7.8 | This vulnerability allows an attacker to create a junction, enabling the deletio… | |
| CVE-2026-19635 | Medium | 0.1% | 8.8 | A local privilege escalation vulnerability exists in Security Center. An attacke… | |
| CVE-2019-11045 | Low | 8.8% | 3.7 | In PHP versions 7.2.x below 7.2.26, 7.3.x below 7.3.13 and 7.4.0, PHP DirectoryI… | |
| CVE-2021-41183 | Low | 8.5% | 6.5 | jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0… | |
| CVE-2019-11050 | Low | 7.6% | 4.8 | When PHP EXIF extension is parsing EXIF information from an image, e.g. via exif… | |
| CVE-2019-11044 | Low | 5.1% | 3.7 | In PHP versions 7.2.x below 7.2.26, 7.3.x below 7.3.13 and 7.4.0 on Windows, PHP… | |
| CVE-2019-11049 | Low | 4.2% | 6.5 | In PHP versions 7.3.x below 7.3.13 and 7.4.0 on Windows, when supplying custom h… | |
| CVE-2019-11046 | Low | 4.1% | 3.7 | In PHP versions 7.2.x below 7.2.26, 7.3.x below 7.3.13 and 7.4.0, PHP bcmath ext… | |
| CVE-2013-5911 | Low | 0.9% | 4.3 | Cross-site scripting (XSS) vulnerability in devform.php in Tenable SecurityCente… | |
| CVE-2018-1155 | Low | 0.6% | 5.4 | In SecurityCenter versions prior to 5.7.0, a cross-site scripting (XSS) issue co… | |
| CVE-2023-2005 | Low | 0.4% | 6.3 | Vulnerability in Tenable Tenable.Io, Tenable Nessus, Tenable Security Center.Thi… | |
| CVE-2026-19631 | Low | 0.2% | 4.9 | A SQL injection vulnerability exists in Security Center that could allow an auth… | |
| CVE-2026-19639 | Low | 0.2% | 4.3 | An improper access control vulnerability exists where an authenticated non-admin… | |
| CVE-2026-4433 | Low | 0.2% | 4.3 | An SSH misconfigurations exists in Tenable OT that led to the potential exfiltra… | |
| CVE-2026-19636 | Low | 0.2% | 5.3 | An issue was identified in which CSRF tokens were generated using a predictable … |