Known vulnerabilities in Tenable Nessus - page 3

Software CPE: cpe:2.3:a:tenable_network_security:tenable_nessus:*:*:*:*:*:*:*:*
Total vulnerabilities: 104
Public exploits: 12
Known exploited (KEV): 1
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting Tenable Nessus Tenable Nessus is affected by 104 known vulnerabilities: 29 high, 45 medium, 30 low Critical High Medium Low

Vulnerabilities (104)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU71999 - NULL Pointer Dereference
CVE-2023-0401
CWE-476 Medium
No
No
10.4.3, 10.5.0 07.02.2023 SB2023020742
SB2023020748
SB2023020774
and 52 more
#VU71998 - NULL Pointer Dereference
CVE-2023-0217
CWE-476 Medium
No
No
10.4.3, 10.5.0 07.02.2023 SB2023020742
SB2023020748
SB2023020774
and 49 more
#VU71997 - Release of invalid pointer or reference
CVE-2023-0216
CWE-763 Medium
No
No
10.4.3, 10.5.0 07.02.2023 SB2023020742
SB2023020748
SB2023020774
and 50 more
#VU71994 - Out-of-bounds read
CVE-2022-4203
CWE-125 Medium
No
No
10.4.3, 10.5.0 07.02.2023 SB2023020742
SB2023020748
SB2023020774
and 47 more
#VU71333 - Improper input validation
CVE-2023-0101
CWE-20 Medium
No
No
8.15.8, 10.4.2 18.01.2023 SB20230118101
#VU68896 - Memory corruption
CVE-2022-3786
CWE-119 Medium
Available
No
10.3.2, 10.4.1 01.11.2022 SB2022110132
SB2022110133
SB2022110144
and 44 more
#VU68895 - Memory corruption
CVE-2022-3602
CWE-119 High
Available
No
10.3.2, 10.4.1 01.11.2022 SB2022110132
SB2022110133
SB2022110144
and 45 more
#VU68718 - Use After Free
CVE-2022-43680
CWE-416 Medium
No
No
8.15.7, 10.3.2, 10.4.1 25.10.2022 SB2022102560
SB2022102566
SB2022103010
and 99 more
#VU67532 - Use After Free
CVE-2022-40674
CWE-416 High
No
No
8.15.7, 10.3.1 21.09.2022 SB2022092118
SB2022092119
SB2022092317
and 111 more
#VU67178 - Improperly Controlled Modification of Object Prototype Attributes (\'Prototype Pollution\')
CVE-2020-28458
CWE-1321 Medium
Available
No
10.3.1, 10.5.0 12.09.2022 SB2022091209
SB2022102678
SB2023030252
and 2 more
#VU66813 - NULL Pointer Dereference
CVE-2022-2309
CWE-476 Medium
No
No
8.15.7, 10.3.1 29.08.2022 SB2022082928
SB2022082929
SB2022082930
and 28 more
#VU66153 - Heap-based Buffer Overflow
CVE-2022-37434
CWE-122 High
Available
No
8.15.7, 10.3.1 07.08.2022 SB2022080705
SB2022081833
SB2022081851
and 154 more
#VU65835 - Incorrect Regular Expression
CVE-2022-31129
CWE-185 Medium
No
No
10.3.1 27.07.2022 SB2022072729
SB2022072901
SB2022081048
and 102 more
#VU62765 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2022-1292
CWE-78 Medium
Available
No
8.15.9 03.05.2022 SB2022050315
SB2022050436
SB2022050503
and 141 more
#VU62463 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2022-24785
CWE-22 Medium
No
No
10.3.1 20.04.2022 SB2022042016
SB2022042017
SB2022060317
and 65 more
#VU60922 - Use After Free
CVE-2022-23308
CWE-416 High
No
No
8.15.7, 10.3.1 01.03.2022 SB2022030109
SB2022030110
SB2022031503
and 59 more
#VU60621 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2021-23445
CWE-79 Low
No
No
10.3.1, 10.5.0 15.02.2022 SB2021092717
SB2022021511
SB2022080802
and 11 more
#VU28228 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2020-7656
CWE-79 Medium
No
No
10.5.0 25.05.2020 SB2020052520
SB2020100907
SB2022072056
and 14 more
#VU27519 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2020-11023
CWE-79 Low
Available
Exploited
10.5.0 05.05.2020 SB2020042126
SB2020052033
SB2020052103
and 180 more
#VU18092 - Improperly Controlled Modification of Object Prototype Attributes (\'Prototype Pollution\')
CVE-2019-11358
CWE-1321 Low
Available
No
10.5.0 28.03.2019 SB2019032804
SB2019041026
SB2019041801
and 155 more


Showing elements 41 - 60 out of 104