VYPR

Nessus

by Tenable

CVEs (80)

  • CVE-2017-7849MedApr 19, 2017
    risk 0.36cvss 5.5epss 0.00

    Nessus 6.10.x before 6.10.5 was found to be vulnerable to a local denial of service condition due to insecure permissions when running in Agent Mode.

  • CVE-2020-5765MedJul 15, 2020
    risk 0.35cvss 5.4epss 0.01

    Nessus 8.10.0 and earlier were found to contain a Stored XSS vulnerability due to improper validation of input during scan configuration. An authenticated, remote attacker could potentially exploit this vulnerability to execute arbitrary code in a user's session. Tenable has…

  • CVE-2019-3923MedFeb 12, 2019
    risk 0.35cvss 5.4epss 0.01

    Nessus versions 8.2.1 and earlier were found to contain a stored XSS vulnerability due to improper validation of user-supplied input. An authenticated, remote attacker could potentially exploit this vulnerability via a specially crafted request to execute arbitrary script code…

  • CVE-2018-1147MedMay 18, 2018
    risk 0.35cvss 5.4epss 0.02

    In Nessus before 7.1.0, a XSS vulnerability exists due to improper input validation. A remote authenticated attacker could create and upload a .nessus file, which may be viewed by an administrator allowing for the execution of arbitrary script code in a user's browser session.…

  • CVE-2017-2122MedMay 12, 2017
    risk 0.35cvss 5.4epss 0.01

    Cross-site scripting vulnerability in Nessus versions 6.8.0, 6.8.1, 6.9.0, 6.9.1 and 6.9.2 allows remote authenticated attackers to inject arbitrary web script or HTML via unspecified vectors.

  • CVE-2016-9259MedFeb 28, 2017
    risk 0.35cvss 5.4epss 0.01

    Cross-site scripting (XSS) vulnerability in Tenable Nessus before 6.9.1 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.

  • CVE-2016-9260MedJan 31, 2017
    risk 0.35cvss 5.4epss 0.02

    Cross-site scripting (XSS) vulnerability in Tenable Nessus before 6.9 allows remote authenticated users to inject arbitrary web script or HTML via vectors related to handling of .nessus files.

  • CVE-2017-5179MedJan 5, 2017
    risk 0.35cvss 5.4epss 0.02

    Cross-site scripting (XSS) vulnerability in Tenable Nessus before 6.9.3 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.

  • CVE-2019-1559MedFeb 27, 2019
    risk 0.33cvss 5.9epss 0.17

    If an application encounters a fatal protocol error and then calls SSL_shutdown() twice (once to send a close_notify, and once to receive one) then OpenSSL can respond differently to the calling application if a 0 byte record is received with invalid padding compared to if a 0…

  • CVE-2024-0955MedFeb 7, 2024
    risk 0.31cvss 4.8epss 0.01

    A stored XSS vulnerability exists where an authenticated, remote attacker with administrator privileges on the Nessus application could alter Nessus proxy settings, which could lead to the execution of remote arbitrary scripts.

  • CVE-2016-1000029MedDec 27, 2019
    risk 0.31cvss 4.8epss 0.01

    Tenable Nessus before 6.8 has a stored XSS issue that requires admin-level authentication to the Nessus UI, and would potentially impact other admins (Tenable IDs 5218 and 5269).

  • CVE-2016-1000028MedDec 27, 2019
    risk 0.31cvss 4.8epss 0.01

    Tenable Nessus before 6.8 has a stored XSS issue that requires admin-level authentication to the Nessus UI, and would only potentially impact other admins. (Tenable ID 5198).

  • CVE-2025-36625MedApr 18, 2025
    risk 0.28cvss 4.3epss 0.00

    In Nessus versions prior to 10.8.4, a non-authenticated attacker could alter Nessus logging entries by manipulating http requests to the application.

  • CVE-2023-3253MedAug 29, 2023
    risk 0.28cvss 4.3epss 0.01

    An improper authorization vulnerability exists where an authenticated, low privileged remote attacker could view a list of all the users available in the application.

  • CVE-2023-3251MedAug 29, 2023
    risk 0.27cvss 4.1epss 0.01

    A pass-back vulnerability exists where an authenticated, remote attacker with administrator privileges could uncover stored SMTP credentials within the Nessus application.This issue affects Nessus: before 10.6.0.

  • CVE-2018-5407MedNov 15, 2018
    risk 0.27cvss 4.7epss 0.03

    Simultaneous Multi-threading (SMT) in processors can enable local users to exploit software vulnerable to timing attacks via a side-channel timing attack on 'port contention'.

  • CVE-2019-3962LowJul 1, 2019
    risk 0.22cvss 3.3epss 0.01

    Content Injection vulnerability in Tenable Nessus prior to 8.5.0 may allow an authenticated, local attacker to exploit this vulnerability by convincing another targeted Nessus user to view a malicious URL and use Nessus to send fraudulent messages. Successful exploitation could…

  • CVE-2026-57588LowJun 25, 2026
    risk 0.03cvss 3.3epss 0.00

    A SQL injection vulnerability in Nessus allows an attacker to craft a malicious scan result file that, when imported by a privileged user, injects malicious SQL into the scan results database, potentially enabling exfiltration of scan-result data.

  • CVE-2014-7280Oct 21, 2014
    risk 0.03cvss —epss 0.03

    Cross-site scripting (XSS) vulnerability in the Web UI before 2.3.4 Build #85 for Tenable Nessus 5.x allows remote web servers to inject arbitrary web script or HTML via the server header.

  • CVE-2003-0372Jun 16, 2003
    risk 0.03cvss —epss 0.01

    Signed integer vulnerability in libnasl in Nessus before 2.0.6 allows local users with plugin upload privileges to cause a denial of service (core dump) and possibly execute arbitrary code by causing a negative argument to be provided to the insstr function as used in a NASL…