Tenable Network Security, Inc.

First CVE: Aug 9, 2017Active for: 9 years
562
CVEs Published
More CVEs Published than 87% of tracked CNAs
56.2
Avg CVEs / Year
More Avg CVEs / Year than 85% of tracked CNAs
7.5
Avg CVSS Score
Higher Avg CVSS Score than 70% of tracked CNAs
1.4%
In CISA KEV
Higher KEV Rate than 89% of tracked CNAs

Self-Reporting Analysis

Of all the CVEs published by Tenable Network Security, Inc. as a CNA, 15.1% affect products that Tenable Network Security, Inc. develops as a vendor.

15.1%
84.9%
Self-reported: 85Third-party: 477

Of all the CVEs published that affect products developed by Tenable Network Security, Inc., 49.7% are self-published by Tenable Network Security, Inc. as a CNA.

49.7%
50.3%
Self-published: 85Published by other CNAs: 86

Trends Over Time

The number and severity of CVEs published by Tenable Network Security, Inc. over time

Volume of CVEsAvg CVSS Base Score
First CVE
Aug 9, 2017
8 years ago
Most Recent CVE
Jul 21, 2026
3 days ago

Top CVEs

All CVEs published by Tenable Network Security, Inc. as a CNA, regardless of affected vendor or product.

562 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
The Crestron AM-100 firmware 1.6.0.2, Crestron AM-101 firmware 2.7.0.1, Barco wePresent WiPG-1000P firmware 2.3.0.10, Barco wePresent WiPG-1600W before firmware 2.4.1.19, Extron Sh
Apr 30, 20199.899YESYES
TP-Link Archer AX21 (AX1800) firmware versions before 1.1.4 Build 20230219 contained a command injection vulnerability in the country form of the /cgi-bin/luci;stok=/locale endpoin
Mar 15, 20238.898YESYES
A path traversal vulnerability in the web interfaces of Buffalo WSR-2533DHPL2 firmware version <= 1.02 and WSR-2533DHP3 firmware version <= 1.24 could allow unauthenticated remote
Apr 29, 20219.898YESYES
The HTTP interface of the Grandstream UCM6200 series is vulnerable to an unauthenticated remote SQL injection via crafted HTTP request. An attacker can use this vulnerability to ex
Mar 23, 20209.898YESYES
A local file inclusion vulnerability exists in Draytek VigorConnect 1.6.0-B3 in the file download functionality of the DownloadFileServlet endpoint. An unauthenticated attacker cou
Oct 13, 20217.594YESYES
Deserialization of Untrusted Data in Plex Media Server on Windows allows a remote, authenticated attacker to execute arbitrary Python code.
May 8, 20207.294YESYES
The Paid Memberships Pro WordPress Plugin, version < 2.9.8, is affected by an unauthenticated SQL injection vulnerability in the 'code' parameter of the '/pmpro/v1/order' REST rout
Jan 20, 20239.893NOYES
A local file inclusion vulnerability exists in Draytek VigorConnect 1.6.0-B3 in the file download functionality of the WebServlet endpoint. An unauthenticated attacker could levera
Oct 13, 20217.593YESYES
Snoopy 1.0 in Nagios XI 5.5.6 allows remote unauthenticated attackers to execute arbitrary commands via a crafted HTTP request.
Nov 14, 20189.890NOYES
Amcrest cameras and NVR are vulnerable to a stack-based buffer overflow over port 37777. An authenticated remote attacker can abuse this issue to crash the device and possibly exec
Apr 8, 20208.888YESYES

CVE Severity & Scoring

Severity distribution of CVEs published by this CNA562 CVEs
Severity distribution among all CVEs352,231 CVEs
LowMediumHighCritical
Attack Vector
Local71 (12.6%)
Network452 (80.4%)
Unknown0 (0.0%)
Physical13 (2.3%)
Adjacent Network26 (4.6%)
Attack Complexity
Low537 (95.6%)
High25 (4.4%)
Unknown0 (0.0%)
User Interaction
None445 (79.2%)
Unknown0 (0.0%)
Required114 (20.3%)
Privileges Required
Low202 (35.9%)
High47 (8.4%)
None313 (55.7%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this cna scope (562 CVEs).

CISA KEV
8 CVEs
1.4% of CVEs· 89th percentile
Metasploit
15 CVEs
2.7% of CVEs· 93rd percentile
Nuclei
52 CVEs
9.3% of CVEs· 95th percentile
ExploitDB
21 CVEs
3.7% of CVEs· 93rd percentile

Social Chatter

An overview of all social media posts that mention a CVE ID published by Tenable Network Security, Inc. as a CNA.

Media Mentions

Media articles that mention a CVE ID published by Tenable Network Security, Inc. as a CNA — matched by CVE ID, not by organization name.

Top Affected Vendors

Top Affected Products

Top CWEs