Securitycenter
by Tenable
CVEs (29)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-19682 | Cri | 0.64 | 9.9 | — | Aug 14, 2026 | A command injection vulnerability exists in Security Center where a remote, unauthenticated attacker could exploit this issue to execute arbitrary commands on the underlying operating system with the privileges of the service account. | ||
| CVE-2026-19681 | Cri | 0.64 | 9.9 | — | Aug 14, 2026 | An authenticated command injection vulnerability exists in Security Center related to file upload processing. An attacker could exploit this issue by uploading a specially crafted file, potentially resulting in arbitrary command execution on the underlying operating system. | ||
| CVE-2026-19626 | Cri | 0.64 | 9.9 | — | Aug 14, 2026 | A remote code execution vulnerability exists in Tenable Security Center's report generation functionality. An authenticated, non-administrative user could exploit this issue by supplying specially crafted input that is later processed unsafely during server-side report… | ||
| CVE-2026-19679 | Hig | 0.57 | 8.8 | — | Aug 14, 2026 | An input validation vulnerability exists in Security Center's file upload handling, where insufficient sanitization of uploaded filenames could contribute to a downstream command injection issue. | ||
| CVE-2026-19635 | Hig | 0.57 | 8.8 | — | Aug 14, 2026 | A local privilege escalation vulnerability exists in Security Center. An attacker with write access to a specific configuration file could achieve arbitrary code execution with elevated privileges, without requiring further user or victim interaction. | ||
| CVE-2026-2630 | Hig | 0.57 | 8.8 | 0.01 | Feb 17, 2026 | A Command Injection vulnerability exists where an authenticated, remote attacker could execute arbitrary code on the underlying server where Tenable Security Center is hosted. | ||
| CVE-2018-1154 | Hig | 0.57 | 8.8 | 0.01 | Aug 2, 2018 | In SecurityCenter versions prior to 5.7.0, a username enumeration issue could allow an unauthenticated attacker to automate the discovery of username aliases via brute force, ultimately facilitating unauthorized access. Server response output has been unified to correct this… | ||
| CVE-2017-11508 | Hig | 0.57 | 8.8 | 0.01 | Nov 2, 2017 | SecurityCenter versions 5.5.0, 5.5.1 and 5.5.2 contain a SQL Injection vulnerability that could be exploited by an authenticated user with sufficient privileges to run diagnostic scans. An attacker could exploit this vulnerability by entering a crafted SQL query into the… | ||
| CVE-2026-19629 | Hig | 0.53 | 8.1 | — | Aug 14, 2026 | A privilege escalation vulnerability exists in Tenable Security Center that allows a user with "Security Manager" role and "manage user" permission on a single group to modify users belonging to other groups. This bypasses the intended access control restrictions and enables… | ||
| CVE-2026-19628 | Hig | 0.47 | 7.2 | — | Aug 14, 2026 | A command injection vulnerability exists in Tenable Security Center. An authenticated administrator could modify application configuration values to achieve arbitrary command execution on the underlying operating system when specific backend operations are triggered. | ||
| CVE-2024-1367 | Hig | 0.47 | 7.2 | 0.02 | Feb 14, 2024 | A command injection vulnerability exists where an authenticated, remote attacker with administrator privileges on the Security Center application could modify Logging parameters, which could lead to the execution of arbitrary code on the Security Center host. | ||
| CVE-2026-19680 | Hig | 0.46 | 7.1 | — | Aug 14, 2026 | A SQL injection vulnerability exists in Security Center that could allow an attacker to access unauthorized data from the application's database. | ||
| CVE-2019-11049 | Med | 0.43 | 6.5 | 0.04 | Dec 23, 2019 | In PHP versions 7.3.x below 7.3.13 and 7.4.0 on Windows, when supplying custom headers to mail() function, due to mistake introduced in commit 78f4b4a2dcf92ddbccea1bb95f8390a18ac3342e, if the header is supplied in lowercase, this can result in double-freeing certain memory… | ||
| CVE-2026-2698 | Med | 0.42 | 6.5 | 0.00 | Feb 23, 2026 | An improper access control vulnerability exists where an authenticated user could access areas outside of their authorized scope. | ||
| CVE-2026-2697 | Med | 0.41 | 6.3 | 0.00 | Feb 23, 2026 | An Indirect Object Reference (IDOR) in Security Center allows an authenticated remote attacker to escalate privileges via the 'owner' parameter. | ||
| CVE-2023-2005 | Med | 0.41 | 6.3 | 0.00 | Jun 26, 2023 | Vulnerability in Tenable Tenable.Io, Tenable Nessus, Tenable Security Center.This issue affects Tenable.Io: before Plugin Feed ID #202306261202 ; Nessus: before Plugin Feed ID #202306261202 ; Security Center: before Plugin Feed ID #202306261202 . This vulnerability could allow… | ||
| CVE-2024-1471 | Med | 0.38 | 5.9 | 0.00 | Feb 14, 2024 | An HTML injection vulnerability exists where an authenticated, remote attacker with administrator privileges on the Security Center application could modify Repository parameters, which could lead to HTML redirection attacks. | ||
| CVE-2024-5759 | Med | 0.35 | 5.4 | 0.00 | Jun 12, 2024 | An improper privilege management vulnerability exists in Tenable Security Center where an authenticated, remote attacker could view unauthorized objects and launch scans without having the required privileges | ||
| CVE-2018-1155 | Med | 0.35 | 5.4 | 0.01 | Aug 2, 2018 | In SecurityCenter versions prior to 5.7.0, a cross-site scripting (XSS) issue could allow an authenticated attacker to inject JavaScript code into an image filename parameter within the Reports feature area. Properly updated input validation techniques have been implemented to… | ||
| CVE-2026-19631 | Med | 0.32 | 4.9 | — | Aug 14, 2026 | A SQL injection vulnerability exists in Security Center that could allow an authenticated administrator to execute arbitrary SQL queries, potentially resulting in unauthorized access to sensitive data, including credentials. |
- risk 0.64cvss 9.9epss —
A command injection vulnerability exists in Security Center where a remote, unauthenticated attacker could exploit this issue to execute arbitrary commands on the underlying operating system with the privileges of the service account.
- risk 0.64cvss 9.9epss —
An authenticated command injection vulnerability exists in Security Center related to file upload processing. An attacker could exploit this issue by uploading a specially crafted file, potentially resulting in arbitrary command execution on the underlying operating system.
- risk 0.64cvss 9.9epss —
A remote code execution vulnerability exists in Tenable Security Center's report generation functionality. An authenticated, non-administrative user could exploit this issue by supplying specially crafted input that is later processed unsafely during server-side report…
- risk 0.57cvss 8.8epss —
An input validation vulnerability exists in Security Center's file upload handling, where insufficient sanitization of uploaded filenames could contribute to a downstream command injection issue.
- risk 0.57cvss 8.8epss —
A local privilege escalation vulnerability exists in Security Center. An attacker with write access to a specific configuration file could achieve arbitrary code execution with elevated privileges, without requiring further user or victim interaction.
- risk 0.57cvss 8.8epss 0.01
A Command Injection vulnerability exists where an authenticated, remote attacker could execute arbitrary code on the underlying server where Tenable Security Center is hosted.
- risk 0.57cvss 8.8epss 0.01
In SecurityCenter versions prior to 5.7.0, a username enumeration issue could allow an unauthenticated attacker to automate the discovery of username aliases via brute force, ultimately facilitating unauthorized access. Server response output has been unified to correct this…
- risk 0.57cvss 8.8epss 0.01
SecurityCenter versions 5.5.0, 5.5.1 and 5.5.2 contain a SQL Injection vulnerability that could be exploited by an authenticated user with sufficient privileges to run diagnostic scans. An attacker could exploit this vulnerability by entering a crafted SQL query into the…
- risk 0.53cvss 8.1epss —
A privilege escalation vulnerability exists in Tenable Security Center that allows a user with "Security Manager" role and "manage user" permission on a single group to modify users belonging to other groups. This bypasses the intended access control restrictions and enables…
- risk 0.47cvss 7.2epss —
A command injection vulnerability exists in Tenable Security Center. An authenticated administrator could modify application configuration values to achieve arbitrary command execution on the underlying operating system when specific backend operations are triggered.
- risk 0.47cvss 7.2epss 0.02
A command injection vulnerability exists where an authenticated, remote attacker with administrator privileges on the Security Center application could modify Logging parameters, which could lead to the execution of arbitrary code on the Security Center host.
- risk 0.46cvss 7.1epss —
A SQL injection vulnerability exists in Security Center that could allow an attacker to access unauthorized data from the application's database.
- risk 0.43cvss 6.5epss 0.04
In PHP versions 7.3.x below 7.3.13 and 7.4.0 on Windows, when supplying custom headers to mail() function, due to mistake introduced in commit 78f4b4a2dcf92ddbccea1bb95f8390a18ac3342e, if the header is supplied in lowercase, this can result in double-freeing certain memory…
- risk 0.42cvss 6.5epss 0.00
An improper access control vulnerability exists where an authenticated user could access areas outside of their authorized scope.
- risk 0.41cvss 6.3epss 0.00
An Indirect Object Reference (IDOR) in Security Center allows an authenticated remote attacker to escalate privileges via the 'owner' parameter.
- risk 0.41cvss 6.3epss 0.00
Vulnerability in Tenable Tenable.Io, Tenable Nessus, Tenable Security Center.This issue affects Tenable.Io: before Plugin Feed ID #202306261202 ; Nessus: before Plugin Feed ID #202306261202 ; Security Center: before Plugin Feed ID #202306261202 . This vulnerability could allow…
- risk 0.38cvss 5.9epss 0.00
An HTML injection vulnerability exists where an authenticated, remote attacker with administrator privileges on the Security Center application could modify Repository parameters, which could lead to HTML redirection attacks.
- risk 0.35cvss 5.4epss 0.00
An improper privilege management vulnerability exists in Tenable Security Center where an authenticated, remote attacker could view unauthorized objects and launch scans without having the required privileges
- risk 0.35cvss 5.4epss 0.01
In SecurityCenter versions prior to 5.7.0, a cross-site scripting (XSS) issue could allow an authenticated attacker to inject JavaScript code into an image filename parameter within the Reports feature area. Properly updated input validation techniques have been implemented to…
- risk 0.32cvss 4.9epss —
A SQL injection vulnerability exists in Security Center that could allow an authenticated administrator to execute arbitrary SQL queries, potentially resulting in unauthorized access to sensitive data, including credentials.
Page 1 of 2