Tenable kayıtları
tenable üreticisine ait 185 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 3 · %1,6
- Silahlaştırılmış
- 5 · %2,7
- Pre-auth RCE
- 7
- Düzeltme kaydı olan
- %54,6
- Yayından KEV’e ortanca
- 879 gün
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')26
- CWE-190 Integer Overflow or Wraparound11
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')11
- CWE-125 Out-of-bounds Read10
- CWE-20 Improper Input Validation9
- CWE-269 Improper Privilege Management9
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWEBug bounty kapsamı
Ürünün üreticisi herkese açık bir programda görünüyor. Eşleşme ad üzerinden yapıldı; kapsam metnini programda doğrulayın.
Tüm kayıtlar
185 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
99Hemen | CVE-2019-11043Silahlaştırılmış | Underflow in PHP-FPM can lead to RCEphp · php · CWE-120 | Kritik9,8 | KEV | %99,8 | 28 Eki 2019 |
96Hemen | CVE-2021-40438Silahlaştırılmış | A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user.resf · rocky linux · CWE-918 | Kritik9,0 | KEV | %100,0 | 16 Eyl 2021 |
79Bu hafta | CVE-2020-11023Silahlaştırılmış | Potential XSS vulnerability in jQueryjquery · jquery · CWE-79 | Orta6,1 | KEV | %84,9 | 29 Nis 2020 |
68Bu hafta | CVE-2021-44790Kavram kanıtı | Possible buffer overflow when parsing multipart content in mod_lua of Apache HTTP Server 2.4.51 and earlierapache · http server · CWE-787 | Kritik9,8 | — | %96,8 | 20 Ara 2021 |
65Bu hafta | CVE-2021-3711İstismar yok | SM2 Decryption Buffer Overflowopenssl · openssl · CWE-120 | Kritik9,8 | — | %87,8 | 24 Ağu 2021 |
57Planlayın | CVE-2021-44224İstismar yok | Possible NULL dereference or SSRF in forward proxy configurations in Apache HTTP Server 2.4.51 and earlierapache · http server · CWE-476 | Yüksek8,2 | — | %82,3 | 20 Ara 2021 |
54Planlayın | CVE-2020-11022Kavram kanıtı | jQuery has a potential XSS vulnerabilityjquery · jquery · CWE-79 | Orta6,1 | — | %99,2 | 29 Nis 2020 |
52Planlayın | CVE-2022-0778Kavram kanıtı | Infinite loop in BN_mod_sqrt() reachable when parsing certificatesopenssl · openssl · CWE-835 | Yüksek7,5 | — | %73,2 | 15 Mar 2022 |
49Planlayın | CVE-2021-34798İstismar yok | NULL pointer dereference in httpd coreapache · http server · CWE-476 | Yüksek7,5 | — | %64,5 | 16 Eyl 2021 |
46Planlayın | CVE-2020-1967Kavram kanıtı | Segmentation fault in SSL_check_chainopenssl · openssl · CWE-476 | Yüksek7,5 | — | %53,3 | 21 Nis 2020 |
45Planlayın | CVE-2021-23840Kavram kanıtı | Integer overflow in CipherUpdateopenssl · openssl · CWE-190 | Yüksek7,5 | — | %50,7 | 16 Şub 2021 |
44Planlayın | CVE-2021-3712Kavram kanıtı | Read buffer overruns processing ASN.1 stringsopenssl · openssl · CWE-125 | Yüksek7,4 | — | %50,4 | 24 Ağu 2021 |
44Planlayın | CVE-2021-33193İstismar yok | Request splitting via HTTP/2 method injection and mod_proxydebian · debian linux | Yüksek7,5 | — | %46,2 | 16 Ağu 2021 |
44Planlayın | CVE-2017-8051Kavram kanıtı | Tenable Appliance 3.5 - 4.4.0, and possibly prior versions, contains a flaw in the simpleupload.py script in the Web UI.tenable · appliance · CWE-78 | Kritik9,8 | — | %16,5 | 21 Nis 2017 |
42Planlayın | CVE-2021-3449Kavram kanıtı | NULL pointer deref in signature_algorithms processingopenssl · openssl · CWE-476 | Orta5,9 | — | %63,5 | 25 Mar 2021 |
41Planlayın | CVE-2020-11656İstismar yok | In SQLite through 3.31.1, the ALTER TABLE implementation has a use-after-free, as demonstrated by an ORDER BY clause that belongs to a composqlite · sqlite · CWE-416 | Kritik9,8 | — | %7,6 | 8 Nis 2020 |
41Planlayın | CVE-2019-19919Kavram kanıtı | Versions of handlebars prior to 4.3.0 are vulnerable to Prototype Pollution leading to Remote Code Execution.handlebars.js project · handlebars.js · CWE-1321 | Kritik9,8 | — | %7,1 | 20 Ara 2019 |
41Planlayın | CVE-2016-4448İstismar yok | Format string vulnerability in libxml2 before 2.9.4 allows attackers to have unspecified impact via format string specifiers in unknown vecthp · icewall federation agent · CWE-134 | Kritik9,8 | — | %7,0 | 9 Haz 2016 |
41Planlayın | CVE-2019-19646İstismar yok | pragma.c in SQLite through 3.30.1 mishandles NOT NULL in an integrity_check PRAGMA command in certain cases of generated columns.sqlite · sqlite · CWE-754 | Kritik9,8 | — | %5,4 | 9 Ara 2019 |
40Planlayın | CVE-2026-19681Silahlaştırılmış | An authenticated command injection vulnerability exists in Security Center related to file upload processing.tenable · security center · CWE-78 | Kritik9,4 | — | %9,9 | 14 Ağu 2026 |
40Planlayın | CVE-2022-22822Kavram kanıtı | addBinding in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow.libexpat project · libexpat · CWE-190 | Kritik9,8 | — | %4,8 | 10 Oca 2022 |
40Planlayın | CVE-2022-23852Kavram kanıtı | Expat (aka libexpat) before 2.4.4 has a signed integer overflow in XML_GetBuffer, for configurations with a nonzero XML_CONTEXT_BYTES.libexpat project · libexpat · CWE-190 | Kritik9,8 | — | %4,6 | 23 Oca 2022 |
40Planlayın | CVE-2019-11049İstismar yok | mail() may release string with refcount==1 twicephp · php · CWE-415 | Kritik9,8 | — | %4,2 | 22 Ara 2019 |
40Planlayın | CVE-2022-22823İstismar yok | build_model in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow.libexpat project · libexpat · CWE-190 | Kritik9,8 | — | %3,4 | 10 Oca 2022 |
40Planlayın | CVE-2022-22824İstismar yok | defineAttribute in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow.libexpat project · libexpat · CWE-190 | Kritik9,8 | — | %3,4 | 10 Oca 2022 |
- CVE-2019-1104399Hemen
Underflow in PHP-FPM can lead to RCE
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100php · php28 Eki 2019
- CVE-2021-4043896Hemen
A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user.
KritikCVSS 9,0KEVSilahlaştırılmışEPSS %100resf · rocky linux16 Eyl 2021
- CVE-2020-1102379Bu hafta
Potential XSS vulnerability in jQuery
OrtaCVSS 6,1KEVSilahlaştırılmışEPSS %85jquery · jquery29 Nis 2020
- CVE-2021-4479068Bu hafta
Possible buffer overflow when parsing multipart content in mod_lua of Apache HTTP Server 2.4.51 and earlier
KritikCVSS 9,8Kavram kanıtıEPSS %97apache · http server20 Ara 2021
- CVE-2021-371165Bu hafta
SM2 Decryption Buffer Overflow
KritikCVSS 9,8İstismar yokEPSS %88openssl · openssl24 Ağu 2021
- CVE-2021-4422457Planlayın
Possible NULL dereference or SSRF in forward proxy configurations in Apache HTTP Server 2.4.51 and earlier
YüksekCVSS 8,2İstismar yokEPSS %82apache · http server20 Ara 2021
- CVE-2020-1102254Planlayın
jQuery has a potential XSS vulnerability
OrtaCVSS 6,1Kavram kanıtıEPSS %99jquery · jquery29 Nis 2020
- CVE-2022-077852Planlayın
Infinite loop in BN_mod_sqrt() reachable when parsing certificates
YüksekCVSS 7,5Kavram kanıtıEPSS %73openssl · openssl15 Mar 2022
- CVE-2021-3479849Planlayın
NULL pointer dereference in httpd core
YüksekCVSS 7,5İstismar yokEPSS %65apache · http server16 Eyl 2021
- CVE-2020-196746Planlayın
Segmentation fault in SSL_check_chain
YüksekCVSS 7,5Kavram kanıtıEPSS %53openssl · openssl21 Nis 2020
- CVE-2021-2384045Planlayın
Integer overflow in CipherUpdate
YüksekCVSS 7,5Kavram kanıtıEPSS %51openssl · openssl16 Şub 2021
- CVE-2021-371244Planlayın
Read buffer overruns processing ASN.1 strings
YüksekCVSS 7,4Kavram kanıtıEPSS %50openssl · openssl24 Ağu 2021
- CVE-2021-3319344Planlayın
Request splitting via HTTP/2 method injection and mod_proxy
YüksekCVSS 7,5İstismar yokEPSS %46debian · debian linux16 Ağu 2021
- CVE-2017-805144Planlayın
Tenable Appliance 3.5 - 4.4.0, and possibly prior versions, contains a flaw in the simpleupload.py script in the Web UI.
KritikCVSS 9,8Kavram kanıtıEPSS %16tenable · appliance21 Nis 2017
- CVE-2021-344942Planlayın
NULL pointer deref in signature_algorithms processing
OrtaCVSS 5,9Kavram kanıtıEPSS %64openssl · openssl25 Mar 2021
- CVE-2020-1165641Planlayın
In SQLite through 3.31.1, the ALTER TABLE implementation has a use-after-free, as demonstrated by an ORDER BY clause that belongs to a compo
KritikCVSS 9,8İstismar yokEPSS %8sqlite · sqlite8 Nis 2020
- CVE-2019-1991941Planlayın
Versions of handlebars prior to 4.3.0 are vulnerable to Prototype Pollution leading to Remote Code Execution.
KritikCVSS 9,8Kavram kanıtıEPSS %7handlebars.js project · handlebars.js20 Ara 2019
- CVE-2016-444841Planlayın
Format string vulnerability in libxml2 before 2.9.4 allows attackers to have unspecified impact via format string specifiers in unknown vect
KritikCVSS 9,8İstismar yokEPSS %7hp · icewall federation agent9 Haz 2016
- CVE-2019-1964641Planlayın
pragma.c in SQLite through 3.30.1 mishandles NOT NULL in an integrity_check PRAGMA command in certain cases of generated columns.
KritikCVSS 9,8İstismar yokEPSS %5sqlite · sqlite9 Ara 2019
- CVE-2026-1968140Planlayın
An authenticated command injection vulnerability exists in Security Center related to file upload processing.
KritikCVSS 9,4SilahlaştırılmışEPSS %10tenable · security center14 Ağu 2026
- CVE-2022-2282240Planlayın
addBinding in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow.
KritikCVSS 9,8Kavram kanıtıEPSS %5libexpat project · libexpat10 Oca 2022
- CVE-2022-2385240Planlayın
Expat (aka libexpat) before 2.4.4 has a signed integer overflow in XML_GetBuffer, for configurations with a nonzero XML_CONTEXT_BYTES.
KritikCVSS 9,8Kavram kanıtıEPSS %5libexpat project · libexpat23 Oca 2022
- CVE-2019-1104940Planlayın
mail() may release string with refcount==1 twice
KritikCVSS 9,8İstismar yokEPSS %4php · php22 Ara 2019
- CVE-2022-2282340Planlayın
build_model in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow.
KritikCVSS 9,8İstismar yokEPSS %3libexpat project · libexpat10 Oca 2022
- CVE-2022-2282440Planlayın
defineAttribute in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow.
KritikCVSS 9,8İstismar yokEPSS %3libexpat project · libexpat10 Oca 2022