VendorsTenablenessusany version
Vulnerabilities

Tenable Nessus any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

60CVEs
CVE-2018-1148
In Nessus before 7.1.0, Session Fixation exists due to insufficient session management within the application. An authenticated attacker could maintain system access due to session fixation after a user password change.
Published 2018-05-18 · Modified
6.5EPSS 0.008
CVE-2022-32974
An authenticated attacker could read arbitrary files from the underlying operating system of the scanner using a custom crafted compliance audit file without providing any valid SSH credentials.
Published 2022-06-21 · Modified
6.5EPSS 0.007
CVE-2022-28291
Insufficiently Protected Credentials: An authenticated user with debug privileges can retrieve stored Nessus policy credentials from the “nessusd” process in cleartext via process dumping. The affected products are all versions of Nessus Essentials and Professional. The vulnerability allows an attacker to access credentials stored in Nessus scanners, potentially compromising its customers’ network of assets.
Published 2022-10-17 · Modified
6.5EPSS 0.007
CVE-2019-3961
Nessus versions 8.4.0 and earlier were found to contain a reflected XSS vulnerability due to improper validation of user-supplied input. An unauthenticated, remote attacker could potentially exploit this vulnerability via a specially crafted request to execute arbitrary script code in a users browser session.
Published 2019-06-25 · Modified
6.1EPSS 0.015
CVE-2021-3449
NULL pointer deref in signature_algorithms processing
Published 2021-03-25 · Modified
5.9EPSS 0.635
CVE-2019-1559
0-byte record padding oracle
Published 2019-02-27 · Modified
5.9EPSS 0.171
CVE-2017-5179
Cross-site scripting (XSS) vulnerability in Tenable Nessus before 6.9.3 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
Published 2017-01-05 · Modified
5.4EPSS 0.013
CVE-2016-9260
Cross-site scripting (XSS) vulnerability in Tenable Nessus before 6.9 allows remote authenticated users to inject arbitrary web script or HTML via vectors related to handling of .nessus files.
Published 2017-01-31 · Modified
5.4EPSS 0.013
CVE-2018-1147
In Nessus before 7.1.0, a XSS vulnerability exists due to improper input validation. A remote authenticated attacker could create and upload a .nessus file, which may be viewed by an administrator allowing for the execution of arbitrary script code in a user's browser session. In other scenarios, XSS could also occur by altering variables from the Advanced Settings.
Published 2018-05-18 · Modified
5.4EPSS 0.011
CVE-2020-5765
Nessus 8.10.0 and earlier were found to contain a Stored XSS vulnerability due to improper validation of input during scan configuration. An authenticated, remote attacker could potentially exploit this vulnerability to execute arbitrary code in a user's session. Tenable has implemented additional input validation mechanisms to correct this issue in Nessus 8.11.0.
Published 2020-07-15 · Modified
5.4EPSS 0.011
CVE-2019-3923
Nessus versions 8.2.1 and earlier were found to contain a stored XSS vulnerability due to improper validation of user-supplied input. An authenticated, remote attacker could potentially exploit this vulnerability via a specially crafted request to execute arbitrary script code in a user's browser session. Tenable has released Nessus 8.2.2 to address this issue.
Published 2019-02-12 · Modified
5.4EPSS 0.009
CVE-2026-57587
SQL Injection in Nessus via Reverse DNS Lookup
Published 2026-06-25 · Analyzed
5.3EPSS 0.004
CVE-2023-3251
Pass-back vulnerability in Nessus
Published 2023-08-29 · Modified
4.9EPSS 0.006
CVE-2016-1000029
Tenable Nessus before 6.8 has a stored XSS issue that requires admin-level authentication to the Nessus UI, and would potentially impact other admins (Tenable IDs 5218 and 5269).
Published 2019-12-27 · Modified
4.8EPSS 0.009
CVE-2016-1000028
Tenable Nessus before 6.8 has a stored XSS issue that requires admin-level authentication to the Nessus UI, and would only potentially impact other admins. (Tenable ID 5198).
Published 2019-12-27 · Modified
4.8EPSS 0.009
CVE-2024-0955
Stored XSS vulnerability
Published 2024-02-06 · Modified
4.8EPSS 0.006
CVE-2018-5407
Simultaneous Multi-threading (SMT) in processors can enable local users to exploit software vulnerable to timing attacks via a side-channel timing attack on 'port contention'.
Published 2018-11-15 · Modified
4.71 PoCEPSS 0.034
CVE-2019-3962
Content Injection vulnerability in Tenable Nessus prior to 8.5.0 may allow an authenticated, local attacker to exploit this vulnerability by convincing another targeted Nessus user to view a malicious URL and use Nessus to send fraudulent messages. Successful exploitation could allow the authenticated adversary to inject arbitrary text into the feed status, which will remain saved post session expiration.
Published 2019-07-01 · Modified
4.3EPSS 0.010
CVE-2023-3253
Improper authorization in Nessus
Published 2023-08-29 · Modified
4.3EPSS 0.005
CVE-2026-57588
SQL Injection in Nessus via Malicious Scan Result File Import
Published 2026-06-25 · Analyzed
3.31 PoCEPSS 0.003
← Prev2 / 2