Tenable records
185 published records for vendor tenable.
Researcher profile
- Entered KEV
- 3 · 1.6%
- Weaponized
- 5 · 2.7%
- Pre-auth RCE
- 7
- With a fix record
- 54.6%
- Median publish → KEV
- 879 days
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')26
- CWE-190 Integer Overflow or Wraparound11
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')11
- CWE-125 Out-of-bounds Read10
- CWE-20 Improper Input Validation9
- CWE-269 Improper Privilege Management9
The weakness classes this vendor ships most often: where to look.
CWEBug bounty scope
The product’s vendor appears in a public program. Matched by name; verify the scope text in the program.
All records
185 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
99Now | CVE-2019-11043Weaponized | Underflow in PHP-FPM can lead to RCEphp · php · CWE-120 | Critical9.8 | KEV | 99.8% | Oct 28, 2019 |
96Now | CVE-2021-40438Weaponized | A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user.resf · rocky linux · CWE-918 | Critical9.0 | KEV | 100.0% | Sep 16, 2021 |
79This week | CVE-2020-11023Weaponized | Potential XSS vulnerability in jQueryjquery · jquery · CWE-79 | Medium6.1 | KEV | 84.9% | Apr 29, 2020 |
68This week | CVE-2021-44790Proof of concept | Possible buffer overflow when parsing multipart content in mod_lua of Apache HTTP Server 2.4.51 and earlierapache · http server · CWE-787 | Critical9.8 | — | 96.8% | Dec 20, 2021 |
65This week | CVE-2021-3711No exploit | SM2 Decryption Buffer Overflowopenssl · openssl · CWE-120 | Critical9.8 | — | 87.8% | Aug 24, 2021 |
57Plan | CVE-2021-44224No exploit | Possible NULL dereference or SSRF in forward proxy configurations in Apache HTTP Server 2.4.51 and earlierapache · http server · CWE-476 | High8.2 | — | 82.3% | Dec 20, 2021 |
54Plan | CVE-2020-11022Proof of concept | jQuery has a potential XSS vulnerabilityjquery · jquery · CWE-79 | Medium6.1 | — | 99.2% | Apr 29, 2020 |
52Plan | CVE-2022-0778Proof of concept | Infinite loop in BN_mod_sqrt() reachable when parsing certificatesopenssl · openssl · CWE-835 | High7.5 | — | 73.2% | Mar 15, 2022 |
49Plan | CVE-2021-34798No exploit | NULL pointer dereference in httpd coreapache · http server · CWE-476 | High7.5 | — | 64.5% | Sep 16, 2021 |
46Plan | CVE-2020-1967Proof of concept | Segmentation fault in SSL_check_chainopenssl · openssl · CWE-476 | High7.5 | — | 53.3% | Apr 21, 2020 |
45Plan | CVE-2021-23840Proof of concept | Integer overflow in CipherUpdateopenssl · openssl · CWE-190 | High7.5 | — | 50.7% | Feb 16, 2021 |
44Plan | CVE-2021-3712Proof of concept | Read buffer overruns processing ASN.1 stringsopenssl · openssl · CWE-125 | High7.4 | — | 50.4% | Aug 24, 2021 |
44Plan | CVE-2021-33193No exploit | Request splitting via HTTP/2 method injection and mod_proxydebian · debian linux | High7.5 | — | 46.2% | Aug 16, 2021 |
44Plan | CVE-2017-8051Proof of concept | Tenable Appliance 3.5 - 4.4.0, and possibly prior versions, contains a flaw in the simpleupload.py script in the Web UI.tenable · appliance · CWE-78 | Critical9.8 | — | 16.5% | Apr 21, 2017 |
42Plan | CVE-2021-3449Proof of concept | NULL pointer deref in signature_algorithms processingopenssl · openssl · CWE-476 | Medium5.9 | — | 63.5% | Mar 25, 2021 |
41Plan | CVE-2020-11656No exploit | In SQLite through 3.31.1, the ALTER TABLE implementation has a use-after-free, as demonstrated by an ORDER BY clause that belongs to a composqlite · sqlite · CWE-416 | Critical9.8 | — | 7.6% | Apr 8, 2020 |
41Plan | CVE-2019-19919Proof of concept | Versions of handlebars prior to 4.3.0 are vulnerable to Prototype Pollution leading to Remote Code Execution.handlebars.js project · handlebars.js · CWE-1321 | Critical9.8 | — | 7.1% | Dec 20, 2019 |
41Plan | CVE-2016-4448No exploit | Format string vulnerability in libxml2 before 2.9.4 allows attackers to have unspecified impact via format string specifiers in unknown vecthp · icewall federation agent · CWE-134 | Critical9.8 | — | 7.0% | Jun 9, 2016 |
41Plan | CVE-2019-19646No exploit | pragma.c in SQLite through 3.30.1 mishandles NOT NULL in an integrity_check PRAGMA command in certain cases of generated columns.sqlite · sqlite · CWE-754 | Critical9.8 | — | 5.4% | Dec 9, 2019 |
40Plan | CVE-2026-19681Weaponized | An authenticated command injection vulnerability exists in Security Center related to file upload processing.tenable · security center · CWE-78 | Critical9.4 | — | 9.9% | Aug 14, 2026 |
40Plan | CVE-2022-22822Proof of concept | addBinding in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow.libexpat project · libexpat · CWE-190 | Critical9.8 | — | 4.8% | Jan 10, 2022 |
40Plan | CVE-2022-23852Proof of concept | Expat (aka libexpat) before 2.4.4 has a signed integer overflow in XML_GetBuffer, for configurations with a nonzero XML_CONTEXT_BYTES.libexpat project · libexpat · CWE-190 | Critical9.8 | — | 4.6% | Jan 23, 2022 |
40Plan | CVE-2019-11049No exploit | mail() may release string with refcount==1 twicephp · php · CWE-415 | Critical9.8 | — | 4.2% | Dec 22, 2019 |
40Plan | CVE-2022-22823No exploit | build_model in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow.libexpat project · libexpat · CWE-190 | Critical9.8 | — | 3.4% | Jan 10, 2022 |
40Plan | CVE-2022-22824No exploit | defineAttribute in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow.libexpat project · libexpat · CWE-190 | Critical9.8 | — | 3.4% | Jan 10, 2022 |
- CVE-2019-1104399Now
Underflow in PHP-FPM can lead to RCE
CriticalCVSS 9.8KEVWeaponizedEPSS 100%php · phpOct 28, 2019
- CVE-2021-4043896Now
A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user.
CriticalCVSS 9.0KEVWeaponizedEPSS 100%resf · rocky linuxSep 16, 2021
- CVE-2020-1102379This week
Potential XSS vulnerability in jQuery
MediumCVSS 6.1KEVWeaponizedEPSS 85%jquery · jqueryApr 29, 2020
- CVE-2021-4479068This week
Possible buffer overflow when parsing multipart content in mod_lua of Apache HTTP Server 2.4.51 and earlier
CriticalCVSS 9.8Proof of conceptEPSS 97%apache · http serverDec 20, 2021
- CVE-2021-371165This week
SM2 Decryption Buffer Overflow
CriticalCVSS 9.8No exploitEPSS 88%openssl · opensslAug 24, 2021
- CVE-2021-4422457Plan
Possible NULL dereference or SSRF in forward proxy configurations in Apache HTTP Server 2.4.51 and earlier
HighCVSS 8.2No exploitEPSS 82%apache · http serverDec 20, 2021
- CVE-2020-1102254Plan
jQuery has a potential XSS vulnerability
MediumCVSS 6.1Proof of conceptEPSS 99%jquery · jqueryApr 29, 2020
- CVE-2022-077852Plan
Infinite loop in BN_mod_sqrt() reachable when parsing certificates
HighCVSS 7.5Proof of conceptEPSS 73%openssl · opensslMar 15, 2022
- CVE-2021-3479849Plan
NULL pointer dereference in httpd core
HighCVSS 7.5No exploitEPSS 65%apache · http serverSep 16, 2021
- CVE-2020-196746Plan
Segmentation fault in SSL_check_chain
HighCVSS 7.5Proof of conceptEPSS 53%openssl · opensslApr 21, 2020
- CVE-2021-2384045Plan
Integer overflow in CipherUpdate
HighCVSS 7.5Proof of conceptEPSS 51%openssl · opensslFeb 16, 2021
- CVE-2021-371244Plan
Read buffer overruns processing ASN.1 strings
HighCVSS 7.4Proof of conceptEPSS 50%openssl · opensslAug 24, 2021
- CVE-2021-3319344Plan
Request splitting via HTTP/2 method injection and mod_proxy
HighCVSS 7.5No exploitEPSS 46%debian · debian linuxAug 16, 2021
- CVE-2017-805144Plan
Tenable Appliance 3.5 - 4.4.0, and possibly prior versions, contains a flaw in the simpleupload.py script in the Web UI.
CriticalCVSS 9.8Proof of conceptEPSS 16%tenable · applianceApr 21, 2017
- CVE-2021-344942Plan
NULL pointer deref in signature_algorithms processing
MediumCVSS 5.9Proof of conceptEPSS 64%openssl · opensslMar 25, 2021
- CVE-2020-1165641Plan
In SQLite through 3.31.1, the ALTER TABLE implementation has a use-after-free, as demonstrated by an ORDER BY clause that belongs to a compo
CriticalCVSS 9.8No exploitEPSS 8%sqlite · sqliteApr 8, 2020
- CVE-2019-1991941Plan
Versions of handlebars prior to 4.3.0 are vulnerable to Prototype Pollution leading to Remote Code Execution.
CriticalCVSS 9.8Proof of conceptEPSS 7%handlebars.js project · handlebars.jsDec 20, 2019
- CVE-2016-444841Plan
Format string vulnerability in libxml2 before 2.9.4 allows attackers to have unspecified impact via format string specifiers in unknown vect
CriticalCVSS 9.8No exploitEPSS 7%hp · icewall federation agentJun 9, 2016
- CVE-2019-1964641Plan
pragma.c in SQLite through 3.30.1 mishandles NOT NULL in an integrity_check PRAGMA command in certain cases of generated columns.
CriticalCVSS 9.8No exploitEPSS 5%sqlite · sqliteDec 9, 2019
- CVE-2026-1968140Plan
An authenticated command injection vulnerability exists in Security Center related to file upload processing.
CriticalCVSS 9.4WeaponizedEPSS 10%tenable · security centerAug 14, 2026
- CVE-2022-2282240Plan
addBinding in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow.
CriticalCVSS 9.8Proof of conceptEPSS 5%libexpat project · libexpatJan 10, 2022
- CVE-2022-2385240Plan
Expat (aka libexpat) before 2.4.4 has a signed integer overflow in XML_GetBuffer, for configurations with a nonzero XML_CONTEXT_BYTES.
CriticalCVSS 9.8Proof of conceptEPSS 5%libexpat project · libexpatJan 23, 2022
- CVE-2019-1104940Plan
mail() may release string with refcount==1 twice
CriticalCVSS 9.8No exploitEPSS 4%php · phpDec 22, 2019
- CVE-2022-2282340Plan
build_model in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow.
CriticalCVSS 9.8No exploitEPSS 3%libexpat project · libexpatJan 10, 2022
- CVE-2022-2282440Plan
defineAttribute in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow.
CriticalCVSS 9.8No exploitEPSS 3%libexpat project · libexpatJan 10, 2022