VendorsTenablesecurity_centerany version
Vulnerabilities

Tenable Security Center any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

30CVEs
CVE-2026-19681
Command Injection
Published 2026-08-14 · Analyzed
9.9EPSS 0.072
CVE-2026-19682
Command Injection
Published 2026-08-14 · Analyzed
9.9EPSS 0.028
CVE-2026-64879
Command Injection
Published 2026-07-21 · Analyzed
9.9EPSS 0.023
CVE-2026-19626
Remote Code Execution
Published 2026-08-14 · Analyzed
9.9EPSS 0.013
CVE-2026-64878
Command Injection
Published 2026-07-21 · Analyzed
9.9EPSS 0.008
CVE-2019-11049
mail() may release string with refcount==1 twice
Published 2019-12-23 · Modified
9.8EPSS 0.042
CVE-2026-64877
An authenticated non-admin user can exploit a SQL injection flaw in the ticketing REST API to access sensitive data stored in the appliance database.
Published 2026-07-21 · Analyzed
9.4EPSS 0.003
CVE-2026-64881
Command Injection
Published 2026-07-21 · Analyzed
8.8EPSS 0.022
CVE-2026-19679
Improper Input Validation
Published 2026-08-14 · Analyzed
8.8EPSS 0.011
CVE-2018-1154
In SecurityCenter versions prior to 5.7.0, a username enumeration issue could allow an unauthenticated attacker to automate the discovery of username aliases via brute force, ultimately facilitating unauthorized access. Server response output has been unified to correct this issue.
Published 2018-08-02 · Modified
8.8EPSS 0.007
CVE-2023-2005
Tenable Plugin Feed ID #202306261202 Fixes Privilege Escalation Vulnerability
Published 2023-06-26 · Modified
8.8EPSS 0.004
CVE-2026-2697
Indirect Object Reference (IDOR) in Security Center
Published 2026-02-23 · Analyzed
8.8EPSS 0.002
CVE-2026-19635
Local Privilege Escalation
Published 2026-08-14 · Analyzed
8.8EPSS 0.001
CVE-2026-19628
Remote Code Execution
Published 2026-08-14 · Analyzed
8.6EPSS 0.027
CVE-2026-19629
Privilege Escalation
Published 2026-08-14 · Analyzed
8.6EPSS 0.002
CVE-2019-11044
link() silently truncates after a null byte on Windows
Published 2019-12-23 · Modified
7.5EPSS 0.051
CVE-2024-1367
Command Injection Vulnerability in Tenable Security Center
Published 2024-02-14 · Modified
7.2EPSS 0.016
CVE-2026-64880
Blind SQL Injection
Published 2026-07-21 · Analyzed
7.1EPSS 0.003
CVE-2026-19680
SQL Injection
Published 2026-08-14 · Analyzed
7.1EPSS 0.002
CVE-2026-19631
SQL Injection
Published 2026-08-14 · Analyzed
6.9EPSS 0.002
CVE-2019-11050
Use-after-free in exif parsing under memory sanitizer
Published 2019-12-23 · Modified
6.5EPSS 0.076
CVE-2026-2698
Improper Access Control
Published 2026-02-23 · Analyzed
6.5EPSS 0.002
CVE-2024-5759
Improper privilege management
Published 2024-06-12 · Modified
6.3EPSS 0.003
CVE-2026-19636
Insuffucient Protections Lead to Brute Force
Published 2026-08-14 · Analyzed
6.0EPSS 0.002
CVE-2019-11045
DirectoryIterator class silently truncates after a null byte
Published 2019-12-23 · Modified
5.9EPSS 0.088
CVE-2024-1471
HTML Injection Vulnerability
Published 2024-02-14 · Modified
5.9EPSS 0.004
CVE-2018-1155
In SecurityCenter versions prior to 5.7.0, a cross-site scripting (XSS) issue could allow an authenticated attacker to inject JavaScript code into an image filename parameter within the Reports feature area. Properly updated input validation techniques have been implemented to correct this issue.
Published 2018-08-02 · Modified
5.4EPSS 0.006
CVE-2024-1891
Stored Cross Site Scripting
Published 2024-06-12 · Modified
5.4EPSS 0.003
CVE-2019-11046
Buffer underflow in bc_shift_addsub
Published 2019-12-23 · Modified
5.3EPSS 0.041
CVE-2026-19639
Improper Access Control
Published 2026-08-14 · Analyzed
5.3EPSS 0.002