Tenable

Security Center

35 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.88%
  • Veröffentlicht 14.08.2026 16:55:36
  • Zuletzt bearbeitet 19.08.2026 17:04:32

A remote code execution vulnerability exists in Tenable Security Center's report generation functionality. An authenticated, non-administrative user could exploit this issue by supplying specially crafted input that is later processed unsafely during...

  • EPSS 0.18%
  • Veröffentlicht 21.07.2026 20:17:04
  • Zuletzt bearbeitet 18.08.2026 17:58:35

Unsanitized user-supplied input in report filtering parameters is concatenated directly into SQL queries without proper escaping or parameterized queries, enabling blind SQL injection and unauthorized database read access.

  • EPSS 2.59%
  • Veröffentlicht 21.07.2026 20:17:04
  • Zuletzt bearbeitet 18.08.2026 17:57:23

A filename supplied during file upload is not properly sanitized before being used in system command execution, allowing an attacker to inject shell metacharacters and achieve command injection via the audit file upload functionality.

  • EPSS 0.54%
  • Veröffentlicht 21.07.2026 20:17:04
  • Zuletzt bearbeitet 18.08.2026 17:54:33

Unvalidated input in asset filter parameters allows shell metacharacters to escape command argument handling, resulting in remote code execution as a low-privileged OS user via the Analysis REST endpoint.

  • EPSS 1.44%
  • Veröffentlicht 21.07.2026 20:09:50
  • Zuletzt bearbeitet 18.08.2026 17:43:48

The audit file upload handler does not sanitize filenames, allowing shell metacharacters to flow into system command execution. This input validation failure enables command injection when chained with a related vulnerability.

  • EPSS 0.19%
  • Veröffentlicht 21.07.2026 18:06:22
  • Zuletzt bearbeitet 18.08.2026 17:50:04

An authenticated non-admin user can exploit a SQL injection flaw in the ticketing REST API to access sensitive data stored in the appliance database.

  • EPSS 0.21%
  • Veröffentlicht 23.02.2026 16:28:07
  • Zuletzt bearbeitet 26.02.2026 16:39:12

An improper access control vulnerability exists where an authenticated user could access areas outside of their authorized scope.

  • EPSS 0.21%
  • Veröffentlicht 23.02.2026 15:17:13
  • Zuletzt bearbeitet 29.04.2026 01:00:01

An Indirect Object Reference (IDOR) in Security Center allows an authenticated remote attacker to escalate privileges via the 'owner' parameter.

  • EPSS 1.17%
  • Veröffentlicht 17.02.2026 18:19:38
  • Zuletzt bearbeitet 15.04.2026 00:35:42

A Command Injection vulnerability exists where an authenticated, remote attacker could execute arbitrary code on the underlying server where Tenable Security Center is hosted.

  • EPSS 0.18%
  • Veröffentlicht 08.10.2025 15:19:33
  • Zuletzt bearbeitet 30.09.2026 23:10:00

In Tenable Security Center versions prior to 6.7.0, an improper access control vulnerability exists where an authenticated user could access areas outside of their authorized scope.