VendorsTenabletenable.scany version
Vulnerabilities

Tenable .sc any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

45CVEs
CVE-2023-24494
A stored cross-site scripting (XSS) vulnerability exists in Tenable.sc due to improper validation of user-supplied input before returning it to users. An authenticated, remote attacker can exploit this by convincing a user to click a specially crafted URL, to execute arbitrary script code in a user's browser session.
Published 2023-01-25 · Modified
5.4EPSS 0.007
CVE-2021-21707
Special characters break path parsing in XML functions
Published 2021-11-29 · Modified
5.3EPSS 0.260
CVE-2020-7070
PHP parses encoded cookie names so malicious `__Host-` cookies can be sent
Published 2020-10-02 · Modified
5.3EPSS 0.050
CVE-2020-7066
get_headers() silently truncates after a null byte
Published 2020-04-01 · Modified
5.3EPSS 0.028
CVE-2020-7068
Use of freed hash key in the phar_parse_zipfile function
Published 2020-09-09 · Modified
4.8EPSS 0.017
← Prev2 / 2