
CVE-2025-36625 – Log Poisoning in Nessus
https://notcve.org/view.php?id=CVE-2025-36625
18 Apr 2025 — In Nessus versions prior to 10.8.4, a non-authenticated attacker could alter Nessus logging entries by manipulating http requests to the application. En versiones de Nessus anteriores a 10.8.4, un atacante no autenticado podría alterar las entradas de registro de Nessus manipulando las solicitudes http a la aplicación. • https://www.tenable.com/security/tns-2025-05 • CWE-117: Improper Output Neutralization for Logs •

CVE-2025-24914 – Local Priviledge Escalation
https://notcve.org/view.php?id=CVE-2025-24914
18 Apr 2025 — When installing Nessus to a non-default location on a Windows host, Nessus versions prior to 10.8.4 did not enforce secure permissions for sub-directories. This could allow for local privilege escalation if users had not secured the directories in the non-default installation location. - CVE-2025-24914 Al instalar Nessus en una ubicación no predeterminada en un host Windows, las versiones de Nessus anteriores a la 10.8.4 no aplicaban permisos seguros a los subdirectorios. Esto podía permitir la escalada de ... • https://www.tenable.com/security/tns-2025-05 • CWE-276: Incorrect Default Permissions •

CVE-2025-24915
https://notcve.org/view.php?id=CVE-2025-24915
21 Mar 2025 — When installing Nessus Agent to a non-default location on a Windows host, Nessus Agent versions prior to 10.8.3 did not enforce secure permissions for sub-directories. This could allow for local privilege escalation if users had not secured the directories in the non-default installation location. • https://www.tenable.com/security/tns-2025-02 • CWE-276: Incorrect Default Permissions •

CVE-2025-0760 – Stored Credential Disclosure Vulnerability
https://notcve.org/view.php?id=CVE-2025-0760
25 Feb 2025 — A Credential Disclosure vulnerability exists where an administrator could extract the stored SMTP account credentials due to lack of encryption. • https://www.tenable.com/security/tns-2025-01 • CWE-522: Insufficiently Protected Credentials •

CVE-2025-1091 – Broken Authorization Schema
https://notcve.org/view.php?id=CVE-2025-1091
25 Feb 2025 — A Broken Authorization schema exists where any authenticated user could download IOA script and configuration files if the URL is known. • https://www.tenable.com/security/tns-2025-01 • CWE-862: Missing Authorization •

CVE-2024-12174
https://notcve.org/view.php?id=CVE-2024-12174
09 Dec 2024 — An Improper Certificate Validation vulnerability exists in Tenable Security Center where an authenticated, privileged attacker could intercept email messages sent from Security Center via a rogue SMTP server. • https://www.tenable.com/security/tns-2024-19 • CWE-295: Improper Certificate Validation •

CVE-2024-9158 – XSS
https://notcve.org/view.php?id=CVE-2024-9158
30 Sep 2024 — A stored cross site scripting vulnerability exists in Nessus Network Monitor where an authenticated, privileged local attacker could inject arbitrary code into the NNM UI via the local CLI. • https://www.tenable.com/security/tns-2024-17 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2024-3232 – Formula Injection Vulnerability
https://notcve.org/view.php?id=CVE-2024-3232
16 Jul 2024 — A formula injection vulnerability exists in Tenable Identity Exposure where an authenticated remote attacker with administrative privileges could manipulate application form fields in order to trick another administrator into executing CSV payloads. - CVE-2024-3232 • https://www.tenable.com/security/tns-2024-04 • CWE-1236: Improper Neutralization of Formula Elements in a CSV File •

CVE-2024-5759 – Improper privilege management
https://notcve.org/view.php?id=CVE-2024-5759
12 Jun 2024 — An improper privilege management vulnerability exists in Tenable Security Center where an authenticated, remote attacker could view unauthorized objects and launch scans without having the required privileges Existe una vulnerabilidad de administración de privilegios inadecuada en Tenable Security Center donde un atacante remoto autenticado podría ver objetos no autorizados e iniciar análisis sin tener los privilegios necesarios. • https://www.tenable.com/security/tns-2024-10 • CWE-269: Improper Privilege Management •

CVE-2024-1891 – Stored Cross Site Scripting
https://notcve.org/view.php?id=CVE-2024-1891
12 Jun 2024 — A stored cross site scripting vulnerability exists in Tenable Security Center where an authenticated, remote attacker could inject HTML code into a web application scan result page. Existe una vulnerabilidad de cross-site scripting almacenado en Tenable Security Center donde un atacante remoto autenticado podría inyectar código HTML en la página de resultados del análisis de una aplicación web. • https://www.tenable.com/security/tns-2024-10 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •