Записи Tenable
185 опубликованных записей вендора tenable.
Профиль для исследователя
- Попали в KEV
- 3 · 1,6 %
- С эксплойтом
- 5 · 2,7 %
- Pre-auth RCE
- 7
- С записью об исправлении
- 54,6 %
- Медиана: публикация → KEV
- 879 дн.
Повторяющиеся классы
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')26
- CWE-190 Integer Overflow or Wraparound11
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')11
- CWE-125 Out-of-bounds Read10
- CWE-20 Improper Input Validation9
- CWE-269 Improper Privilege Management9
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEОхват bug bounty
Вендор продукта присутствует в публичной программе. Сопоставление по имени; проверьте текст scope в программе.
Все записи
185 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
99Срочно | CVE-2019-11043Готовый эксплойт | Underflow in PHP-FPM can lead to RCEphp · php · CWE-120 | Критическая9,8 | KEV | 99,8 % | 28 окт. 2019 г. |
96Срочно | CVE-2021-40438Готовый эксплойт | A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user.resf · rocky linux · CWE-918 | Критическая9,0 | KEV | 100,0 % | 16 сент. 2021 г. |
79На этой неделе | CVE-2020-11023Готовый эксплойт | Potential XSS vulnerability in jQueryjquery · jquery · CWE-79 | Средняя6,1 | KEV | 84,9 % | 29 апр. 2020 г. |
68На этой неделе | CVE-2021-44790Proof of concept | Possible buffer overflow when parsing multipart content in mod_lua of Apache HTTP Server 2.4.51 and earlierapache · http server · CWE-787 | Критическая9,8 | — | 96,8 % | 20 дек. 2021 г. |
65На этой неделе | CVE-2021-3711Эксплойта нет | SM2 Decryption Buffer Overflowopenssl · openssl · CWE-120 | Критическая9,8 | — | 87,8 % | 24 авг. 2021 г. |
57В плане | CVE-2021-44224Эксплойта нет | Possible NULL dereference or SSRF in forward proxy configurations in Apache HTTP Server 2.4.51 and earlierapache · http server · CWE-476 | Высокая8,2 | — | 82,3 % | 20 дек. 2021 г. |
54В плане | CVE-2020-11022Proof of concept | jQuery has a potential XSS vulnerabilityjquery · jquery · CWE-79 | Средняя6,1 | — | 99,2 % | 29 апр. 2020 г. |
52В плане | CVE-2022-0778Proof of concept | Infinite loop in BN_mod_sqrt() reachable when parsing certificatesopenssl · openssl · CWE-835 | Высокая7,5 | — | 73,2 % | 15 мар. 2022 г. |
49В плане | CVE-2021-34798Эксплойта нет | NULL pointer dereference in httpd coreapache · http server · CWE-476 | Высокая7,5 | — | 64,5 % | 16 сент. 2021 г. |
46В плане | CVE-2020-1967Proof of concept | Segmentation fault in SSL_check_chainopenssl · openssl · CWE-476 | Высокая7,5 | — | 53,3 % | 21 апр. 2020 г. |
45В плане | CVE-2021-23840Proof of concept | Integer overflow in CipherUpdateopenssl · openssl · CWE-190 | Высокая7,5 | — | 50,7 % | 16 февр. 2021 г. |
44В плане | CVE-2021-3712Proof of concept | Read buffer overruns processing ASN.1 stringsopenssl · openssl · CWE-125 | Высокая7,4 | — | 50,4 % | 24 авг. 2021 г. |
44В плане | CVE-2021-33193Эксплойта нет | Request splitting via HTTP/2 method injection and mod_proxydebian · debian linux | Высокая7,5 | — | 46,2 % | 16 авг. 2021 г. |
44В плане | CVE-2017-8051Proof of concept | Tenable Appliance 3.5 - 4.4.0, and possibly prior versions, contains a flaw in the simpleupload.py script in the Web UI.tenable · appliance · CWE-78 | Критическая9,8 | — | 16,5 % | 21 апр. 2017 г. |
42В плане | CVE-2021-3449Proof of concept | NULL pointer deref in signature_algorithms processingopenssl · openssl · CWE-476 | Средняя5,9 | — | 63,5 % | 25 мар. 2021 г. |
41В плане | CVE-2020-11656Эксплойта нет | In SQLite through 3.31.1, the ALTER TABLE implementation has a use-after-free, as demonstrated by an ORDER BY clause that belongs to a composqlite · sqlite · CWE-416 | Критическая9,8 | — | 7,6 % | 8 апр. 2020 г. |
41В плане | CVE-2019-19919Proof of concept | Versions of handlebars prior to 4.3.0 are vulnerable to Prototype Pollution leading to Remote Code Execution.handlebars.js project · handlebars.js · CWE-1321 | Критическая9,8 | — | 7,1 % | 20 дек. 2019 г. |
41В плане | CVE-2016-4448Эксплойта нет | Format string vulnerability in libxml2 before 2.9.4 allows attackers to have unspecified impact via format string specifiers in unknown vecthp · icewall federation agent · CWE-134 | Критическая9,8 | — | 7,0 % | 9 июн. 2016 г. |
41В плане | CVE-2019-19646Эксплойта нет | pragma.c in SQLite through 3.30.1 mishandles NOT NULL in an integrity_check PRAGMA command in certain cases of generated columns.sqlite · sqlite · CWE-754 | Критическая9,8 | — | 5,4 % | 9 дек. 2019 г. |
40В плане | CVE-2026-19681Готовый эксплойт | An authenticated command injection vulnerability exists in Security Center related to file upload processing.tenable · security center · CWE-78 | Критическая9,4 | — | 9,9 % | 14 авг. 2026 г. |
40В плане | CVE-2022-22822Proof of concept | addBinding in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow.libexpat project · libexpat · CWE-190 | Критическая9,8 | — | 4,8 % | 10 янв. 2022 г. |
40В плане | CVE-2022-23852Proof of concept | Expat (aka libexpat) before 2.4.4 has a signed integer overflow in XML_GetBuffer, for configurations with a nonzero XML_CONTEXT_BYTES.libexpat project · libexpat · CWE-190 | Критическая9,8 | — | 4,6 % | 23 янв. 2022 г. |
40В плане | CVE-2019-11049Эксплойта нет | mail() may release string with refcount==1 twicephp · php · CWE-415 | Критическая9,8 | — | 4,2 % | 22 дек. 2019 г. |
40В плане | CVE-2022-22823Эксплойта нет | build_model in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow.libexpat project · libexpat · CWE-190 | Критическая9,8 | — | 3,4 % | 10 янв. 2022 г. |
40В плане | CVE-2022-22824Эксплойта нет | defineAttribute in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow.libexpat project · libexpat · CWE-190 | Критическая9,8 | — | 3,4 % | 10 янв. 2022 г. |
- CVE-2019-1104399Срочно
Underflow in PHP-FPM can lead to RCE
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %php · php28 окт. 2019 г.
- CVE-2021-4043896Срочно
A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user.
КритическаяCVSS 9,0KEVГотовый эксплойтEPSS 100 %resf · rocky linux16 сент. 2021 г.
- CVE-2020-1102379На этой неделе
Potential XSS vulnerability in jQuery
СредняяCVSS 6,1KEVГотовый эксплойтEPSS 85 %jquery · jquery29 апр. 2020 г.
- CVE-2021-4479068На этой неделе
Possible buffer overflow when parsing multipart content in mod_lua of Apache HTTP Server 2.4.51 and earlier
КритическаяCVSS 9,8Proof of conceptEPSS 97 %apache · http server20 дек. 2021 г.
- CVE-2021-371165На этой неделе
SM2 Decryption Buffer Overflow
КритическаяCVSS 9,8Эксплойта нетEPSS 88 %openssl · openssl24 авг. 2021 г.
- CVE-2021-4422457В плане
Possible NULL dereference or SSRF in forward proxy configurations in Apache HTTP Server 2.4.51 and earlier
ВысокаяCVSS 8,2Эксплойта нетEPSS 82 %apache · http server20 дек. 2021 г.
- CVE-2020-1102254В плане
jQuery has a potential XSS vulnerability
СредняяCVSS 6,1Proof of conceptEPSS 99 %jquery · jquery29 апр. 2020 г.
- CVE-2022-077852В плане
Infinite loop in BN_mod_sqrt() reachable when parsing certificates
ВысокаяCVSS 7,5Proof of conceptEPSS 73 %openssl · openssl15 мар. 2022 г.
- CVE-2021-3479849В плане
NULL pointer dereference in httpd core
ВысокаяCVSS 7,5Эксплойта нетEPSS 65 %apache · http server16 сент. 2021 г.
- CVE-2020-196746В плане
Segmentation fault in SSL_check_chain
ВысокаяCVSS 7,5Proof of conceptEPSS 53 %openssl · openssl21 апр. 2020 г.
- CVE-2021-2384045В плане
Integer overflow in CipherUpdate
ВысокаяCVSS 7,5Proof of conceptEPSS 51 %openssl · openssl16 февр. 2021 г.
- CVE-2021-371244В плане
Read buffer overruns processing ASN.1 strings
ВысокаяCVSS 7,4Proof of conceptEPSS 50 %openssl · openssl24 авг. 2021 г.
- CVE-2021-3319344В плане
Request splitting via HTTP/2 method injection and mod_proxy
ВысокаяCVSS 7,5Эксплойта нетEPSS 46 %debian · debian linux16 авг. 2021 г.
- CVE-2017-805144В плане
Tenable Appliance 3.5 - 4.4.0, and possibly prior versions, contains a flaw in the simpleupload.py script in the Web UI.
КритическаяCVSS 9,8Proof of conceptEPSS 16 %tenable · appliance21 апр. 2017 г.
- CVE-2021-344942В плане
NULL pointer deref in signature_algorithms processing
СредняяCVSS 5,9Proof of conceptEPSS 64 %openssl · openssl25 мар. 2021 г.
- CVE-2020-1165641В плане
In SQLite through 3.31.1, the ALTER TABLE implementation has a use-after-free, as demonstrated by an ORDER BY clause that belongs to a compo
КритическаяCVSS 9,8Эксплойта нетEPSS 8 %sqlite · sqlite8 апр. 2020 г.
- CVE-2019-1991941В плане
Versions of handlebars prior to 4.3.0 are vulnerable to Prototype Pollution leading to Remote Code Execution.
КритическаяCVSS 9,8Proof of conceptEPSS 7 %handlebars.js project · handlebars.js20 дек. 2019 г.
- CVE-2016-444841В плане
Format string vulnerability in libxml2 before 2.9.4 allows attackers to have unspecified impact via format string specifiers in unknown vect
КритическаяCVSS 9,8Эксплойта нетEPSS 7 %hp · icewall federation agent9 июн. 2016 г.
- CVE-2019-1964641В плане
pragma.c in SQLite through 3.30.1 mishandles NOT NULL in an integrity_check PRAGMA command in certain cases of generated columns.
КритическаяCVSS 9,8Эксплойта нетEPSS 5 %sqlite · sqlite9 дек. 2019 г.
- CVE-2026-1968140В плане
An authenticated command injection vulnerability exists in Security Center related to file upload processing.
КритическаяCVSS 9,4Готовый эксплойтEPSS 10 %tenable · security center14 авг. 2026 г.
- CVE-2022-2282240В плане
addBinding in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow.
КритическаяCVSS 9,8Proof of conceptEPSS 5 %libexpat project · libexpat10 янв. 2022 г.
- CVE-2022-2385240В плане
Expat (aka libexpat) before 2.4.4 has a signed integer overflow in XML_GetBuffer, for configurations with a nonzero XML_CONTEXT_BYTES.
КритическаяCVSS 9,8Proof of conceptEPSS 5 %libexpat project · libexpat23 янв. 2022 г.
- CVE-2019-1104940В плане
mail() may release string with refcount==1 twice
КритическаяCVSS 9,8Эксплойта нетEPSS 4 %php · php22 дек. 2019 г.
- CVE-2022-2282340В плане
build_model in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow.
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %libexpat project · libexpat10 янв. 2022 г.
- CVE-2022-2282440В плане
defineAttribute in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow.
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %libexpat project · libexpat10 янв. 2022 г.