CVE Tools

Tenable.sc

46 CVEs tracked. 2 of them are in CISA KEV.

This hub aggregates every CVE we track for Tenable.sc, a product in the security products space. Use it to gauge the current risk picture and drill into individual advisories.

Tenable.sc CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Tenable.sc CVEs per month
MonthCVEs
2024-100
2024-110
2024-120
2025-010
2025-020
2025-030
2025-040
2025-050
2025-060
2025-070
2025-080
2025-090
2025-100
2025-110
2025-120
2026-010
2026-020
2026-030
2026-040
2026-050
2026-060
2026-070
2026-080
2026-090

Severity

How the 46 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical613%
  • High1737%
  • Medium2248%
  • Low12%

Latest CVEs

The 15 most recently published vulnerabilities affecting Tenable.sc.

  1. CVE-2023-0524As part of our Security Development Lifecycle, a potential privilege escalation issue was identified internally. This could allow a malicious actor with sufficient permissions to modify environment...8.8
  2. CVE-2023-24495A Server Side Request Forgery (SSRF) vulnerability exists in Tenable.sc due to improper validation of session & user-accessible input data. A privileged, authenticated remote attacker could interac...6.5
  3. CVE-2023-24493A formula injection vulnerability exists in Tenable.sc due to improper validation of user-supplied input before returning it to users. An authenticated attacker could leverage the reporting system ...5.7
  4. CVE-2023-24494A stored cross-site scripting (XSS) vulnerability exists in Tenable.sc due to improper validation of user-supplied input before returning it to users. An authenticated, remote attacker can exploit ...5.4
  5. CVE-2023-0476A LDAP injection vulnerability exists in Tenable.sc due to improper validation of user-supplied input before returning it to users. An authenticated attacker could generate data in Active Directory...6.5
  6. CVE-2022-24828Missing input validation can lead to command execution in composer8.3
  7. CVE-2022-24785Path Traversal in Moment.js7.5
  8. CVE-2022-0130Tenable.sc versions 5.14.0 through 5.19.1 were found to contain a remote code execution vulnerability which could allow a remote, unauthenticated attacker to execute code under special circumstance...8.1
  9. CVE-2021-44224Possible NULL dereference or SSRF in forward proxy configurations in Apache HTTP Server 2.4.51 and earlier8.2
  10. CVE-2021-44790Possible buffer overflow when parsing multipart content in mod_lua of Apache HTTP Server 2.4.51 and earlier9.8
  11. CVE-2021-21707Special characters break path parsing in XML functions5.3
  12. CVE-2021-41184XSS in the `of` option of the `.position()` util6.5
  13. CVE-2021-41183XSS in `*Text` options of the Datepicker widget6.5
  14. CVE-2021-41182XSS in the `altField` option of the Datepicker widget6.5
  15. CVE-2021-41116Command injection in composer on Windows8.2

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store