
CVE-2025-36630 – Local Privilege Escalation
https://notcve.org/view.php?id=CVE-2025-36630
01 Jul 2025 — In Tenable Nessus versions prior to 10.8.5 on a Windows host, it was found that a non-administrative user could overwrite arbitrary local system files with log content at SYSTEM privilege. En versiones de Tenable Nessus anteriores a 10.8.5 en un host Windows, se descubrió que un usuario no administrativo podía sobrescribir archivos arbitrarios del sistema local con contenido de registro con privilegio SYSTEM. • https://www.tenable.com/security/tns-2025-13 • CWE-269: Improper Privilege Management •

CVE-2025-36625 – Log Poisoning in Nessus
https://notcve.org/view.php?id=CVE-2025-36625
18 Apr 2025 — In Nessus versions prior to 10.8.4, a non-authenticated attacker could alter Nessus logging entries by manipulating http requests to the application. En versiones de Nessus anteriores a 10.8.4, un atacante no autenticado podría alterar las entradas de registro de Nessus manipulando las solicitudes http a la aplicación. • https://www.tenable.com/security/tns-2025-05 • CWE-117: Improper Output Neutralization for Logs •

CVE-2025-24914 – Local Priviledge Escalation
https://notcve.org/view.php?id=CVE-2025-24914
18 Apr 2025 — When installing Nessus to a non-default location on a Windows host, Nessus versions prior to 10.8.4 did not enforce secure permissions for sub-directories. This could allow for local privilege escalation if users had not secured the directories in the non-default installation location. - CVE-2025-24914 Al instalar Nessus en una ubicación no predeterminada en un host Windows, las versiones de Nessus anteriores a la 10.8.4 no aplicaban permisos seguros a los subdirectorios. Esto podía permitir la escalada de ... • https://www.tenable.com/security/tns-2025-05 • CWE-276: Incorrect Default Permissions •

CVE-2025-24915
https://notcve.org/view.php?id=CVE-2025-24915
21 Mar 2025 — When installing Nessus Agent to a non-default location on a Windows host, Nessus Agent versions prior to 10.8.3 did not enforce secure permissions for sub-directories. This could allow for local privilege escalation if users had not secured the directories in the non-default installation location. • https://www.tenable.com/security/tns-2025-02 • CWE-276: Incorrect Default Permissions •

CVE-2024-9158 – XSS
https://notcve.org/view.php?id=CVE-2024-9158
30 Sep 2024 — A stored cross site scripting vulnerability exists in Nessus Network Monitor where an authenticated, privileged local attacker could inject arbitrary code into the NNM UI via the local CLI. • https://www.tenable.com/security/tns-2024-17 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2024-3292 – Race Condition
https://notcve.org/view.php?id=CVE-2024-3292
17 May 2024 — A race condition vulnerability exists where an authenticated, local attacker on a Windows Nessus Agent host could modify installation parameters at installation time, which could lead to the execution of arbitrary code on the Nessus host. - CVE-2024-3292 Existe una vulnerabilidad de condición de ejecución donde un atacante local autenticado en un host de Nessus Agent de Windows podría modificar los parámetros de instalación en el momento de la instalación, lo que podría conducir a la ejecución de código arb... • https://www.tenable.com/security/tns-2024-09 • CWE-367: Time-of-check Time-of-use (TOCTOU) Race Condition •

CVE-2024-3291 – Privilege Escalation
https://notcve.org/view.php?id=CVE-2024-3291
17 May 2024 — When installing Nessus Agent to a directory outside of the default location on a Windows host, Nessus Agent versions prior to 10.6.4 did not enforce secure permissions for sub-directories. This could allow for local privilege escalation if users had not secured the directories in the non-default installation location. Al instalar Nessus Agent en un directorio fuera de la ubicación predeterminada en un host de Windows, las versiones de Nessus Agent anteriores a la 10.6.4 no aplicaban permisos seguros para lo... • https://www.tenable.com/security/tns-2024-09 • CWE-281: Improper Preservation of Permissions •

CVE-2024-3290 – Race Condition
https://notcve.org/view.php?id=CVE-2024-3290
17 May 2024 — A race condition vulnerability exists where an authenticated, local attacker on a Windows Nessus host could modify installation parameters at installation time, which could lead to the execution of arbitrary code on the Nessus host Existe una vulnerabilidad de condición de ejecución donde un atacante local autenticado en un host Nessus de Windows podría modificar los parámetros de instalación en el momento de la instalación, lo que podría llevar a la ejecución de código arbitrario en el host Nessus. • https://www.tenable.com/security/tns-2024-08 • CWE-367: Time-of-check Time-of-use (TOCTOU) Race Condition •

CVE-2024-3289
https://notcve.org/view.php?id=CVE-2024-3289
17 May 2024 — When installing Nessus to a directory outside of the default location on a Windows host, Nessus versions prior to 10.7.3 did not enforce secure permissions for sub-directories. This could allow for local privilege escalation if users had not secured the directories in the non-default installation location. Al instalar Nessus en un directorio fuera de la ubicación predeterminada en un host de Windows, las versiones de Nessus anteriores a la 10.7.3 no aplicaban permisos seguros para los subdirectorios. Esto p... • https://www.tenable.com/security/tns-2024-08 • CWE-281: Improper Preservation of Permissions •

CVE-2024-2390 – Local Privilege Escalation
https://notcve.org/view.php?id=CVE-2024-2390
18 Mar 2024 — As a part of Tenable’s vulnerability disclosure program, a vulnerability in a Nessus plugin was identified and reported. This vulnerability could allow a malicious actor with sufficient permissions on a scan target to place a binary in a specific filesystem location, and abuse the impacted plugin in order to escalate privileges. Como parte del programa de divulgación de vulnerabilidades de Tenable, se identificó y reportó una vulnerabilidad en un complemento de Nessus. Esta vulnerabilidad podría permitir qu... • https://www.tenable.com/security/tns-2024-05 • CWE-269: Improper Privilege Management •