VYPR

Securitycenter

by Tenable

CVEs (34)

  • CVE-2026-19682CriAug 14, 2026
    risk 0.65cvss 9.9epss 0.03

    A command injection vulnerability exists in Security Center where a remote, unauthenticated attacker could exploit this issue to execute arbitrary commands on the underlying operating system with the privileges of the service account.

  • CVE-2026-19681CriAug 14, 2026
    risk 0.65cvss 9.9epss 0.10

    An authenticated command injection vulnerability exists in Security Center related to file upload processing. An attacker could exploit this issue by uploading a specially crafted file, potentially resulting in arbitrary command execution on the underlying operating system.

  • CVE-2026-64879CriJul 21, 2026
    risk 0.65cvss 9.9epss 0.02

    A filename supplied during file upload is not properly sanitized before being used in system command execution, allowing an attacker to inject shell metacharacters and achieve command injection via the audit file upload functionality.

  • CVE-2026-19626CriAug 14, 2026
    risk 0.64cvss 9.9epss 0.02

    A remote code execution vulnerability exists in Tenable Security Center's report generation functionality. An authenticated, non-administrative user could exploit this issue by supplying specially crafted input that is later processed unsafely during server-side report…

  • CVE-2026-64878CriJul 21, 2026
    risk 0.64cvss 9.9epss 0.01

    Unvalidated input in asset filter parameters allows shell metacharacters to escape command argument handling, resulting in remote code execution as a low-privileged OS user via the Analysis REST endpoint.

  • CVE-2026-19679HigAug 14, 2026
    risk 0.57cvss 8.8epss 0.02

    An input validation vulnerability exists in Security Center's file upload handling, where insufficient sanitization of uploaded filenames could contribute to a downstream command injection issue.

  • CVE-2026-19635HigAug 14, 2026
    risk 0.57cvss 8.8epss 0.00

    A local privilege escalation vulnerability exists in Security Center. An attacker with write access to a specific configuration file could achieve arbitrary code execution with elevated privileges, without requiring further user or victim interaction.

  • CVE-2026-64881HigJul 21, 2026
    risk 0.57cvss 8.8epss 0.02

    The audit file upload handler does not sanitize filenames, allowing shell metacharacters to flow into system command execution. This input validation failure enables command injection when chained with a related vulnerability.

  • CVE-2026-2630HigFeb 17, 2026
    risk 0.57cvss 8.8epss 0.02

    A Command Injection vulnerability exists where an authenticated, remote attacker could execute arbitrary code on the underlying server where Tenable Security Center is hosted.

  • CVE-2018-1154HigAug 2, 2018
    risk 0.57cvss 8.8epss 0.01

    In SecurityCenter versions prior to 5.7.0, a username enumeration issue could allow an unauthenticated attacker to automate the discovery of username aliases via brute force, ultimately facilitating unauthorized access. Server response output has been unified to correct this…

  • CVE-2017-11508HigNov 2, 2017
    risk 0.57cvss 8.8epss 0.01

    SecurityCenter versions 5.5.0, 5.5.1 and 5.5.2 contain a SQL Injection vulnerability that could be exploited by an authenticated user with sufficient privileges to run diagnostic scans. An attacker could exploit this vulnerability by entering a crafted SQL query into the…

  • CVE-2026-64877HigJul 21, 2026
    risk 0.55cvss 8.4epss 0.00

    An authenticated non-admin user can exploit a SQL injection flaw in the ticketing REST API to access sensitive data stored in the appliance database.

  • CVE-2026-19629HigAug 14, 2026
    risk 0.53cvss 8.1epss 0.00

    A privilege escalation vulnerability exists in Tenable Security Center that allows a user with "Security Manager" role and "manage user" permission on a single group to modify users belonging to other groups. This bypasses the intended access control restrictions and enables…

  • CVE-2026-19628HigAug 14, 2026
    risk 0.47cvss 7.2epss 0.02

    A command injection vulnerability exists in Tenable Security Center. An authenticated administrator could modify application configuration values to achieve arbitrary command execution on the underlying operating system when specific backend operations are triggered.

  • CVE-2024-1367HigFeb 14, 2024
    risk 0.47cvss 7.2epss 0.02

    A command injection vulnerability exists where an authenticated, remote attacker with administrator privileges on the Security Center application could modify Logging parameters, which could lead to the execution of arbitrary code on the Security Center host.

  • CVE-2026-19680HigAug 14, 2026
    risk 0.46cvss 7.1epss 0.00

    A SQL injection vulnerability exists in Security Center that could allow an attacker to access unauthorized data from the application's database.

  • CVE-2026-64880HigJul 21, 2026
    risk 0.46cvss 7.1epss 0.00

    Unsanitized user-supplied input in report filtering parameters is concatenated directly into SQL queries without proper escaping or parameterized queries, enabling blind SQL injection and unauthorized database read access.

  • CVE-2019-11049MedDec 23, 2019
    risk 0.43cvss 6.5epss 0.04

    In PHP versions 7.3.x below 7.3.13 and 7.4.0 on Windows, when supplying custom headers to mail() function, due to mistake introduced in commit 78f4b4a2dcf92ddbccea1bb95f8390a18ac3342e, if the header is supplied in lowercase, this can result in double-freeing certain memory…

  • CVE-2026-2698MedFeb 23, 2026
    risk 0.42cvss 6.5epss 0.00

    An improper access control vulnerability exists where an authenticated user could access areas outside of their authorized scope.

  • CVE-2026-2697MedFeb 23, 2026
    risk 0.41cvss 6.3epss 0.00

    An Indirect Object Reference (IDOR) in Security Center allows an authenticated remote attacker to escalate privileges via the 'owner' parameter.

Page 1 of 2