| CVE-2026-19682 | 9.9 | — | — | — | tenable / security center | A command injection vulnerability exists in Security Center where a remote, unauthenticated attacker could exploit | 22d ago |
| CVE-2026-19681 | 9.9 | — | — | — | tenable / security center | An authenticated command injection vulnerability exists in Security Center related to file upload processing. | 22d ago |
| CVE-2026-19626 | 9.9 | — | — | — | tenable / security center | A remote code execution vulnerability exists in Tenable Security Center's report generation functionality. | 22d ago |
| CVE-2026-64879 | 9.9 | — | — | — | tenable / security center | A filename supplied during file upload is not properly sanitized before being used in system command execution, al | 46d ago |
| CVE-2026-64878 | 9.9 | — | — | — | tenable / security center | Unvalidated input in asset filter parameters allows shell metacharacters to escape command argument handling, resu | 46d ago |
| CVE-2026-15265 | 9.1 | — | — | — | tenable / nessus agent | A path traversal vulnerability in Tenable Agent 11.2.0 and 11.1.3 and lower allows a privileged attacker to write | 53d ago |
| CVE-2026-19679 | 8.8 | — | — | — | tenable / security center | An input validation vulnerability exists in Security Center's file upload handling, where insufficient sanitizatio | 22d ago |
| CVE-2026-19635 | 8.8 | — | — | — | tenable / security center | A local privilege escalation vulnerability exists in Security Center. | 22d ago |
| CVE-2026-64881 | 8.8 | — | — | — | tenable / security center | The audit file upload handler does not sanitize filenames, allowing shell metacharacters to flow into system comma | 46d ago |
| CVE-2026-64877 | 8.4 | — | — | — | tenable / security center | An authenticated non-admin user can exploit a SQL injection flaw in the ticketing REST API to access sensitive dat | 46d ago |
| CVE-2026-19629 | 8.1 | — | — | — | tenable / security center | A privilege escalation vulnerability exists in Tenable Security Center that allows a user with "Security Manager" | 22d ago |
| CVE-2026-13007 | 7.5 | — | — | — | tenable / identity exposure | Tenable Identity Exposure contains multiple unauthenticated API endpoints under /w/api/* that expose sensitive app | 74d ago |
| CVE-2026-47358 | 7.5 | — | — | — | tenable / terrascan | Terrascan v1.18.3 and prior are vulnerable to Server-Side Request Forgery (SSRF) via external URL resolution in up | 109d ago |
| CVE-2026-47357 | 7.5 | — | — | — | tenable / terrascan | Terrascan v1.18.3 and prior are vulnerable to Server-Side Request Forgery (SSRF) via the remote_url parameter in t | 109d ago |
| CVE-2026-47356 | 7.5 | — | — | — | tenable / terrascan | Terrascan v1.18.3 and prior are vulnerable to Server-Side Request Forgery (SSRF) via the webhook_url parameter in | 109d ago |
| CVE-2026-19628 | 7.2 | — | — | — | tenable / security center | A command injection vulnerability exists in Tenable Security Center. | 22d ago |
| CVE-2026-19680 | 7.1 | — | — | — | tenable / security center | A SQL injection vulnerability exists in Security Center that could allow an attacker to access unauthorized data f | 22d ago |
| CVE-2026-64880 | 7.1 | — | — | — | tenable / security center | Unsanitized user-supplied input in report filtering parameters is concatenated directly into SQL queries without p | 46d ago |