By vendor
Tenable vulnerabilities
Known CVEs affecting Tenable products, prioritized by severity, with SEC.co remediation and detection guidance.
2 published vulnerabilities
- CVE-2026-57587MEDIUM 5.3
A SQL injection flaw in Nessus allows an unauthenticated attacker to manipulate reverse DNS records for a host being scanned, then inject malicious SQL commands into Nessus's scan results database. This could let the attacker read sensitive data from scan results without needing valid credentials. The attack requires the attacker to control DNS infrastructure for a target host, which limits the scope but is feasible in some network configurations.
- CVE-2026-57588LOW 3.3
A SQL injection flaw exists in Nessus that can be triggered when a privileged user imports a specially crafted scan result file. An attacker could design such a file to inject malicious SQL commands into the scan results database, potentially allowing unauthorized access to sensitive scan data. The vulnerability requires local file access and user interaction, limiting its immediate threat scope, though it could be valuable in targeted attacks against security teams.