Skip to content
Noroxi

Tenable records

185 published records for vendor tenable.

Bug bounty scope

The product’s vendor appears in a public program. Matched by name; verify the scope text in the program.

All records

185 records
  • Underflow in PHP-FPM can lead to RCE

    CriticalCVSS 9.8KEVWeaponizedEPSS 100%

    php · phpOct 28, 2019

  • A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user.

    CriticalCVSS 9.0KEVWeaponizedEPSS 100%

    resf · rocky linuxSep 16, 2021

  • CVE-2020-11023
    79This week

    Potential XSS vulnerability in jQuery

    MediumCVSS 6.1KEVWeaponizedEPSS 85%

    jquery · jqueryApr 29, 2020

  • CVE-2021-44790
    68This week

    Possible buffer overflow when parsing multipart content in mod_lua of Apache HTTP Server 2.4.51 and earlier

    CriticalCVSS 9.8Proof of conceptEPSS 97%

    apache · http serverDec 20, 2021

  • CVE-2021-3711
    65This week

    SM2 Decryption Buffer Overflow

    CriticalCVSS 9.8No exploitEPSS 88%

    openssl · opensslAug 24, 2021

  • Possible NULL dereference or SSRF in forward proxy configurations in Apache HTTP Server 2.4.51 and earlier

    HighCVSS 8.2No exploitEPSS 82%

    apache · http serverDec 20, 2021

  • jQuery has a potential XSS vulnerability

    MediumCVSS 6.1Proof of conceptEPSS 99%

    jquery · jqueryApr 29, 2020

  • Infinite loop in BN_mod_sqrt() reachable when parsing certificates

    HighCVSS 7.5Proof of conceptEPSS 73%

    openssl · opensslMar 15, 2022

  • NULL pointer dereference in httpd core

    HighCVSS 7.5No exploitEPSS 65%

    apache · http serverSep 16, 2021

  • Segmentation fault in SSL_check_chain

    HighCVSS 7.5Proof of conceptEPSS 53%

    openssl · opensslApr 21, 2020

  • Integer overflow in CipherUpdate

    HighCVSS 7.5Proof of conceptEPSS 51%

    openssl · opensslFeb 16, 2021

  • Read buffer overruns processing ASN.1 strings

    HighCVSS 7.4Proof of conceptEPSS 50%

    openssl · opensslAug 24, 2021

  • Request splitting via HTTP/2 method injection and mod_proxy

    HighCVSS 7.5No exploitEPSS 46%

    debian · debian linuxAug 16, 2021

  • Tenable Appliance 3.5 - 4.4.0, and possibly prior versions, contains a flaw in the simpleupload.py script in the Web UI.

    CriticalCVSS 9.8Proof of conceptEPSS 16%

    tenable · applianceApr 21, 2017

  • NULL pointer deref in signature_algorithms processing

    MediumCVSS 5.9Proof of conceptEPSS 64%

    openssl · opensslMar 25, 2021

  • In SQLite through 3.31.1, the ALTER TABLE implementation has a use-after-free, as demonstrated by an ORDER BY clause that belongs to a compo

    CriticalCVSS 9.8No exploitEPSS 8%

    sqlite · sqliteApr 8, 2020

  • Versions of handlebars prior to 4.3.0 are vulnerable to Prototype Pollution leading to Remote Code Execution.

    CriticalCVSS 9.8Proof of conceptEPSS 7%

    handlebars.js project · handlebars.jsDec 20, 2019

  • Format string vulnerability in libxml2 before 2.9.4 allows attackers to have unspecified impact via format string specifiers in unknown vect

    CriticalCVSS 9.8No exploitEPSS 7%

    hp · icewall federation agentJun 9, 2016

  • pragma.c in SQLite through 3.30.1 mishandles NOT NULL in an integrity_check PRAGMA command in certain cases of generated columns.

    CriticalCVSS 9.8No exploitEPSS 5%

    sqlite · sqliteDec 9, 2019

  • An authenticated command injection vulnerability exists in Security Center related to file upload processing.

    CriticalCVSS 9.4WeaponizedEPSS 10%

    tenable · security centerAug 14, 2026

  • addBinding in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow.

    CriticalCVSS 9.8Proof of conceptEPSS 5%

    libexpat project · libexpatJan 10, 2022

  • Expat (aka libexpat) before 2.4.4 has a signed integer overflow in XML_GetBuffer, for configurations with a nonzero XML_CONTEXT_BYTES.

    CriticalCVSS 9.8Proof of conceptEPSS 5%

    libexpat project · libexpatJan 23, 2022

  • mail() may release string with refcount==1 twice

    CriticalCVSS 9.8No exploitEPSS 4%

    php · phpDec 22, 2019

  • build_model in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow.

    CriticalCVSS 9.8No exploitEPSS 3%

    libexpat project · libexpatJan 10, 2022

  • defineAttribute in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow.

    CriticalCVSS 9.8No exploitEPSS 3%

    libexpat project · libexpatJan 10, 2022