VYPR

Tenable Nessus

by Tenable

CVEs (5)

  • CVE-2018-1148MedMay 18, 2018
    risk 0.42cvss 6.5epss 0.01

    In Nessus before 7.1.0, Session Fixation exists due to insufficient session management within the application. An authenticated attacker could maintain system access due to session fixation after a user password change.

  • CVE-2023-2005MedJun 26, 2023
    risk 0.41cvss 6.3epss 0.00

    Vulnerability in Tenable Tenable.Io, Tenable Nessus, Tenable Security Center.This issue affects Tenable.Io: before Plugin Feed ID #202306261202 ; Nessus: before Plugin Feed ID #202306261202 ; Security Center: before Plugin Feed ID #202306261202 . This vulnerability could allow…

  • CVE-2019-3961MedJun 25, 2019
    risk 0.40cvss 6.1epss 0.01

    Nessus versions 8.4.0 and earlier were found to contain a reflected XSS vulnerability due to improper validation of user-supplied input. An unauthenticated, remote attacker could potentially exploit this vulnerability via a specially crafted request to execute arbitrary script…

  • CVE-2019-3923MedFeb 12, 2019
    risk 0.35cvss 5.4epss 0.01

    Nessus versions 8.2.1 and earlier were found to contain a stored XSS vulnerability due to improper validation of user-supplied input. An authenticated, remote attacker could potentially exploit this vulnerability via a specially crafted request to execute arbitrary script code…

  • CVE-2018-1147MedMay 18, 2018
    risk 0.35cvss 5.4epss 0.01

    In Nessus before 7.1.0, a XSS vulnerability exists due to improper input validation. A remote authenticated attacker could create and upload a .nessus file, which may be viewed by an administrator allowing for the execution of arbitrary script code in a user's browser session.…