Search
Search Results (166 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2018-1141 | 1 Tenable | 1 Nessus | 2024-11-21 | N/A |
| When installing Nessus to a directory outside of the default location, Nessus versions prior to 7.0.3 did not enforce secure permissions for sub-directories. This could allow for local privilege escalation if users had not secured the directories in the installation location. | ||||
| CVE-2017-18214 | 3 Momentjs, Redhat, Tenable | 3 Moment, Jboss Enterprise Application Platform, Nessus | 2024-11-21 | 7.5 High |
| The moment module before 2.19.3 for Node.js is prone to a regular expression denial of service via a crafted date string, a different vulnerability than CVE-2016-4055. | ||||
| CVE-2016-1000029 | 1 Tenable | 1 Nessus | 2024-11-21 | 4.8 Medium |
| Tenable Nessus before 6.8 has a stored XSS issue that requires admin-level authentication to the Nessus UI, and would potentially impact other admins (Tenable IDs 5218 and 5269). | ||||
| CVE-2016-1000028 | 1 Tenable | 1 Nessus | 2024-11-21 | 4.8 Medium |
| Tenable Nessus before 6.8 has a stored XSS issue that requires admin-level authentication to the Nessus UI, and would only potentially impact other admins. (Tenable ID 5198). | ||||
| CVE-2024-9158 | 1 Tenable | 1 Nessus Network Monitor | 2024-10-07 | 8.4 High |
| A stored cross site scripting vulnerability exists in Nessus Network Monitor where an authenticated, privileged local attacker could inject arbitrary code into the NNM UI via the local CLI. | ||||
| CVE-2013-5911 | 1 Tenable | 1 Securitycenter | 2024-08-06 | N/A |
| Cross-site scripting (XSS) vulnerability in devform.php in Tenable SecurityCenter 4.6 through 4.7 allows remote attackers to inject arbitrary web script or HTML via the message parameter. | ||||