VendorsTenabletenable.scall versions
Vulnerabilities

Tenable .sc

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

46CVEs
CVE-2019-11043
Underflow in PHP-FPM can lead to RCE
Published 2019-10-28 · Analyzed
9.8KEV2 PoCEPSS 0.998
CVE-2021-44790
Possible buffer overflow when parsing multipart content in mod_lua of Apache HTTP Server 2.4.51 and earlier
Published 2021-12-20 · Analyzed
9.81 PoCEPSS 0.968
CVE-2021-3711
SM2 Decryption Buffer Overflow
Published 2021-08-24 · Modified
9.8EPSS 0.878
CVE-2020-11656
In SQLite through 3.31.1, the ALTER TABLE implementation has a use-after-free, as demonstrated by an ORDER BY clause that belongs to a compound SELECT statement.
Published 2020-04-09 · Modified
9.8EPSS 0.076
CVE-2019-19919
Versions of handlebars prior to 4.3.0 are vulnerable to Prototype Pollution leading to Remote Code Execution. Templates may alter an Object's __proto__ and __defineGetter__ properties, which may allow an attacker to execute arbitrary code through crafted payloads.
Published 2019-12-20 · Modified
9.8EPSS 0.071
CVE-2019-19646
pragma.c in SQLite through 3.30.1 mishandles NOT NULL in an integrity_check PRAGMA command in certain cases of generated columns.
Published 2019-12-09 · Modified
9.8EPSS 0.054
CVE-2021-41116
Command injection in composer on Windows
Published 2021-10-05 · Modified
9.8EPSS 0.029
CVE-2020-7060
global buffer-overflow in mbfl_filt_conv_big5_wchar
Published 2020-02-10 · Modified
9.1EPSS 0.089
CVE-2020-7059
OOB read in php_strip_tags_ex
Published 2020-02-10 · Modified
9.1EPSS 0.071
CVE-2020-7061
heap-buffer-overflow in phar_extract_file
Published 2020-02-27 · Modified
9.1EPSS 0.041
CVE-2021-40438
mod_proxy SSRF
Published 2021-09-16 · Analyzed
9.0KEVEPSS 1.000
CVE-2020-7065
mb_strtolower (UTF-32LE): stack-buffer-overflow at php_unicode_tolower_full
Published 2020-04-01 · Modified
8.8EPSS 0.049
CVE-2021-20076
Tenable.sc and Tenable.sc Core versions 5.13.0 through 5.17.0 were found to contain a vulnerability that could allow an authenticated, unprivileged user to perform Remote Code Execution (RCE) on the Tenable.sc server via Hypertext Preprocessor unserialization.
Published 2021-03-03 · Modified
8.8EPSS 0.021
CVE-2022-24828
Missing input validation can lead to command execution in composer
Published 2022-04-13 · Modified
8.8EPSS 0.019
CVE-2023-0524
As part of our Security Development Lifecycle, a potential privilege escalation issue was identified internally. This could allow a malicious actor with sufficient permissions to modify environment variables and abuse an impacted plugin in order to escalate privileges. We have resolved the issue and also made several defense-in-depth fixes alongside. While the probability of successful exploitation is low, Tenable is committed to securing our customers’ environments and our products. The updates have been distributed via the Tenable plugin feed in feed serial numbers equal to or greater than #202212212055.
Published 2023-02-01 · Modified
8.8EPSS 0.006
CVE-2021-44224
Possible NULL dereference or SSRF in forward proxy configurations in Apache HTTP Server 2.4.51 and earlier
Published 2021-12-20 · Modified
8.2EPSS 0.823
CVE-2022-0130
Tenable.sc versions 5.14.0 through 5.19.1 were found to contain a remote code execution vulnerability which could allow a remote, unauthenticated attacker to execute code under special circumstances. An attacker would first have to stage a specific file type in the web server root of the Tenable.sc host prior to remote exploitation.
Published 2022-01-14 · Modified
8.1EPSS 0.016
CVE-2021-34798
NULL pointer dereference in httpd core
Published 2021-09-16 · Modified
7.5EPSS 0.645
CVE-2021-33193
Request splitting via HTTP/2 method injection and mod_proxy
Published 2021-08-16 · Analyzed
7.5EPSS 0.462
CVE-2022-24785
Path Traversal in Moment.js
Published 2022-04-04 · Modified
7.5EPSS 0.139
CVE-2020-11655
SQLite through 3.31.1 allows attackers to cause a denial of service (segmentation fault) via a malformed window-function query because the AggInfo object's initialization is mishandled.
Published 2020-04-09 · Modified
7.5EPSS 0.043
CVE-2020-7067
OOB Read in urldecode()
Published 2020-04-27 · Modified
7.5EPSS 0.043
CVE-2020-5808
In certain scenarios in Tenable.sc prior to 5.17.0, a scanner could potentially be used outside the user's defined scan zone without a particular zone being specified within the Automatic Distribution configuration.
Published 2020-12-21 · Modified
7.5EPSS 0.011
CVE-2021-3712
Read buffer overruns processing ASN.1 strings
Published 2021-08-24 · Modified
7.4EPSS 0.504
CVE-2021-23358
Arbitrary Code Injection
Published 2021-03-29 · Modified
7.2EPSS 0.041
CVE-2019-11041
heap-buffer-overflow on exif_scan_thumbnail in EXIF extension
Published 2019-08-09 · Modified
7.1EPSS 0.044
CVE-2019-11042
heap-buffer-overflow on exif_process_user_comment in EXIF extension
Published 2019-08-09 · Modified
7.1EPSS 0.044
CVE-2021-41184
XSS in the `of` option of the `.position()` util
Published 2021-10-26 · Modified
6.5EPSS 0.408
CVE-2021-41182
XSS in the `altField` option of the Datepicker widget
Published 2021-10-26 · Modified
6.5EPSS 0.394
CVE-2021-41183
XSS in `*Text` options of the Datepicker widget
Published 2021-10-26 · Modified
6.5EPSS 0.085
CVE-2020-7064
Use-of-uninitialized-value in exif
Published 2020-04-01 · Modified
6.5EPSS 0.043
CVE-2020-7069
Wrong ciphertext/tag in AES-CCM encryption for a 12 bytes IV
Published 2020-10-02 · Modified
6.5EPSS 0.021
CVE-2023-24495
A Server Side Request Forgery (SSRF) vulnerability exists in Tenable.sc due to improper validation of session & user-accessible input data. A privileged, authenticated remote attacker could interact with external and internal services covertly.
Published 2023-01-25 · Modified
6.5EPSS 0.009
CVE-2023-0476
A LDAP injection vulnerability exists in Tenable.sc due to improper validation of user-supplied input before returning it to users. An authenticated attacker could generate data in Active Directory using the application account through blind LDAP injection.
Published 2023-01-25 · Modified
6.5EPSS 0.007
CVE-2019-8331
In Bootstrap before 3.4.1 and 4.3.x before 4.3.1, XSS is possible in the tooltip or popover data-template attribute.
Published 2019-02-20 · Modified
6.1EPSS 0.164
CVE-2021-3449
NULL pointer deref in signature_algorithms processing
Published 2021-03-25 · Modified
5.9EPSS 0.635
CVE-2021-23841
Null pointer deref in X509_issuer_and_serial_hash()
Published 2021-02-16 · Modified
5.9EPSS 0.074
CVE-2023-24493
A formula injection vulnerability exists in Tenable.sc due to improper validation of user-supplied input before returning it to users. An authenticated attacker could leverage the reporting system to export reports containing formulas, which would then require a victim to approve and execute on a host.
Published 2023-01-25 · Modified
5.7EPSS 0.007
CVE-2020-7063
Files added to tar with Phar::buildFromIterator have all-access permissions
Published 2020-02-27 · Modified
5.5EPSS 0.016
CVE-2019-19645
alter.c in SQLite through 3.30.1 allows attackers to trigger infinite recursion via certain types of self-referential views in conjunction with ALTER TABLE statements.
Published 2019-12-09 · Modified
5.5EPSS 0.006
1 / 2Next →