Vulnerabilities > Tenable > Nessus > Medium

DATE CVE VULNERABILITY TITLE RISK
2022-06-21 CVE-2022-32974 Unspecified vulnerability in Tenable Nessus
An authenticated attacker could read arbitrary files from the underlying operating system of the scanner using a custom crafted compliance audit file without providing any valid SSH credentials.
network
low complexity
tenable
6.5
2021-11-03 CVE-2021-20135 Unspecified vulnerability in Tenable Nessus
Nessus versions 8.15.2 and earlier were found to contain a local privilege escalation vulnerability which could allow an authenticated, local administrator to run specific executables on the Nessus Agent host.
local
low complexity
tenable
6.7
2021-07-21 CVE-2021-20106 Unspecified vulnerability in Tenable Nessus
Nessus Agent versions 8.2.5 and earlier were found to contain a privilege escalation vulnerability which could allow a Nessus administrator user to upload a specially crafted file that could lead to gaining administrator privileges on the Nessus host.
local
low complexity
tenable
6.5
2021-06-29 CVE-2021-20079 Unspecified vulnerability in Tenable Nessus
Nessus versions 8.13.2 and earlier were found to contain a privilege escalation vulnerability which could allow a Nessus administrator user to upload a specially crafted file that could lead to gaining administrator privileges on the Nessus host.
local
low complexity
tenable
6.7
2021-06-28 CVE-2021-20099 Unspecified vulnerability in Tenable Nessus
Nessus Agent 8.2.4 and earlier for Windows were found to contain multiple local privilege escalation vulnerabilities which could allow an authenticated, local administrator to run specific Windows executables as the Nessus host.
local
low complexity
tenable
6.7
2021-06-28 CVE-2021-20100 Unspecified vulnerability in Tenable Nessus
Nessus Agent 8.2.4 and earlier for Windows were found to contain multiple local privilege escalation vulnerabilities which could allow an authenticated, local administrator to run specific Windows executables as the Nessus host.
local
low complexity
tenable
6.7
2021-03-25 CVE-2021-3449 NULL Pointer Dereference vulnerability in multiple products
An OpenSSL TLS server may crash if sent a maliciously crafted renegotiation ClientHello message from a client.
5.9
2020-07-15 CVE-2020-5765 Cross-site Scripting vulnerability in Tenable Nessus
Nessus 8.10.0 and earlier were found to contain a Stored XSS vulnerability due to improper validation of input during scan configuration.
network
low complexity
tenable CWE-79
5.4
2019-12-27 CVE-2016-1000029 Cross-site Scripting vulnerability in Tenable Nessus
Tenable Nessus before 6.8 has a stored XSS issue that requires admin-level authentication to the Nessus UI, and would potentially impact other admins (Tenable IDs 5218 and 5269).
network
low complexity
tenable CWE-79
4.8
2019-12-27 CVE-2016-1000028 Cross-site Scripting vulnerability in Tenable Nessus
Tenable Nessus before 6.8 has a stored XSS issue that requires admin-level authentication to the Nessus UI, and would only potentially impact other admins.
network
low complexity
tenable CWE-79
4.8