CVE-2026-2698
- EPSS 0.04%
- Veröffentlicht 23.02.2026 16:28:07
- Zuletzt bearbeitet 26.02.2026 16:39:12
An improper access control vulnerability exists where an authenticated user could access areas outside of their authorized scope.
CVE-2026-2697
- EPSS 0.15%
- Veröffentlicht 23.02.2026 15:17:13
- Zuletzt bearbeitet 29.04.2026 01:00:01
An Indirect Object Reference (IDOR) in Security Center allows an authenticated remote attacker to escalate privileges via the 'owner' parameter.
CVE-2026-2630
- EPSS 0.41%
- Veröffentlicht 17.02.2026 18:19:38
- Zuletzt bearbeitet 15.04.2026 00:35:42
A Command Injection vulnerability exists where an authenticated, remote attacker could execute arbitrary code on the underlying server where Tenable Security Center is hosted.
CVE-2025-36636
- EPSS 0.04%
- Veröffentlicht 08.10.2025 15:19:33
- Zuletzt bearbeitet 15.04.2026 00:35:42
In Tenable Security Center versions prior to 6.7.0, an improper access control vulnerability exists where an authenticated user could access areas outside of their authorized scope.
CVE-2024-12174
- EPSS 0.07%
- Veröffentlicht 09.12.2024 22:15:22
- Zuletzt bearbeitet 15.04.2026 00:35:42
An Improper Certificate Validation vulnerability exists in Tenable Security Center where an authenticated, privileged attacker could intercept email messages sent from Security Center via a rogue SMTP server.
CVE-2024-5759
- EPSS 0.64%
- Veröffentlicht 12.06.2024 16:15:12
- Zuletzt bearbeitet 21.11.2024 09:48:17
An improper privilege management vulnerability exists in Tenable Security Center where an authenticated, remote attacker could view unauthorized objects and launch scans without having the required privileges
CVE-2024-1891
- EPSS 0.21%
- Veröffentlicht 12.06.2024 16:15:10
- Zuletzt bearbeitet 21.11.2024 08:51:32
A stored cross site scripting vulnerability exists in Tenable Security Center where an authenticated, remote attacker could inject HTML code into a web application scan result page.
CVE-2024-1367
- EPSS 5.1%
- Veröffentlicht 14.02.2024 22:15:47
- Zuletzt bearbeitet 21.11.2024 08:50:25
A command injection vulnerability exists where an authenticated, remote attacker with administrator privileges on the Security Center application could modify Logging parameters, which could lead to the execution of arbitrary code on the Security Ce...
CVE-2024-1471
- EPSS 0.16%
- Veröffentlicht 14.02.2024 22:15:47
- Zuletzt bearbeitet 21.11.2024 08:50:39
An HTML injection vulnerability exists where an authenticated, remote attacker with administrator privileges on the Security Center application could modify Repository parameters, which could lead to HTML redirection attacks.