Vulnerabilidades en Tenable, Inc.
20 resultadosAnálisis Vexday
A Tenable registra 8 vulnerabilidades em base, com 5 publicadas nos últimos 90 dias, indicando ritmo significativo de descobertas recentes; 3 delas são críticas, mas nenhuma está sob exploração ativa (KEV), reduzindo o risco imediato. A fraqueza dominante é injeção de comando (CWE-78), padrão que exige atenção em ambientes de produção, recomendando priorização das críticas e monitoramento de novas divulgações.
CVE-2026-19681CRITICALCommand InjectionEPSS 7.8%CVE-2026-19682CRITICALCommand InjectionEPSS 2.8%CVE-2026-19628HIGHRemote Code ExecutionEPSS 2.7%CVE-2026-64879CRITICALCommand InjectionEPSS 2.3%CVE-2026-64881HIGHCommand InjectionEPSS 2.2%CVE-2026-19626CRITICALRemote Code ExecutionEPSS 1.4%CVE-2026-19679HIGHImproper Input ValidationEPSS 1.1%CVE-2022-33757MEDIUMAn authenticated attacker could read Nessus Debug Log file attachments from the web UI without having the correct privileges to do so. This EPSS 0.8%CVE-2026-64878CRITICALCommand InjectionEPSS 0.8%CVE-2026-18667CRITICALSensor Proxy Version 1.4.2 Fixes One VulnerabilityEPSS 0.4%CVE-2026-64877CRITICALAn authenticated non-admin user can exploit a SQL injection flaw in the ticketing REST API to access sensitive data stored in the appliance EPSS 0.3%CVE-2026-64880HIGHBlind SQL InjectionEPSS 0.3%CVE-2026-19680HIGHSQL InjectionEPSS 0.2%CVE-2026-19631MEDIUMSQL InjectionEPSS 0.2%CVE-2026-19629HIGHPrivilege EscalationEPSS 0.2%CVE-2026-19639MEDIUMImproper Access ControlEPSS 0.2%CVE-2026-4433LOWAn SSH misconfigurations exists in Tenable OT that led to the potential exfiltration of socket, port, and service information via the ostunnEPSS 0.2%CVE-2026-19636MEDIUMInsuffucient Protections Lead to Brute ForceEPSS 0.2%CVE-2026-33694HIGHJunction File ManipulationEPSS 0.2%CVE-2026-19635HIGHLocal Privilege EscalationEPSS 0.1%