
CVE-2025-0760 – Stored Credential Disclosure Vulnerability
https://notcve.org/view.php?id=CVE-2025-0760
25 Feb 2025 — A Credential Disclosure vulnerability exists where an administrator could extract the stored SMTP account credentials due to lack of encryption. • https://www.tenable.com/security/tns-2025-01 • CWE-522: Insufficiently Protected Credentials •

CVE-2025-1091 – Broken Authorization Schema
https://notcve.org/view.php?id=CVE-2025-1091
25 Feb 2025 — A Broken Authorization schema exists where any authenticated user could download IOA script and configuration files if the URL is known. • https://www.tenable.com/security/tns-2025-01 • CWE-862: Missing Authorization •

CVE-2024-3232 – Formula Injection Vulnerability
https://notcve.org/view.php?id=CVE-2024-3232
16 Jul 2024 — A formula injection vulnerability exists in Tenable Identity Exposure where an authenticated remote attacker with administrative privileges could manipulate application form fields in order to trick another administrator into executing CSV payloads. - CVE-2024-3232 • https://www.tenable.com/security/tns-2024-04 • CWE-1236: Improper Neutralization of Formula Elements in a CSV File •