Tenable Network Security, Inc.
Self-Reporting Analysis
Of all the CVEs published by Tenable Network Security, Inc. as a CNA, 15.1% affect products that Tenable Network Security, Inc. develops as a vendor.
Of all the CVEs published that affect products developed by Tenable Network Security, Inc., 49.7% are self-published by Tenable Network Security, Inc. as a CNA.
Trends Over Time
The number and severity of CVEs published by Tenable Network Security, Inc. over time
Top CVEs
All CVEs published by Tenable Network Security, Inc. as a CNA, regardless of affected vendor or product.
562 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-3929CRITICAL The Crestron AM-100 firmware 1.6.0.2, Crestron AM-101 firmware 2.7.0.1, Barco wePresent WiPG-1000P firmware 2.3.0.10, Barco wePresent WiPG-1600W before firmware 2.4.1.19, Extron Sh | Apr 30, 2019 | 9.8 | 99 | YES | YES |
CVE-2023-1389HIGH TP-Link Archer AX21 (AX1800) firmware versions before 1.1.4 Build 20230219 contained a command injection vulnerability in the country form of the /cgi-bin/luci;stok=/locale endpoin | Mar 15, 2023 | 8.8 | 98 | YES | YES |
CVE-2021-20090CRITICAL A path traversal vulnerability in the web interfaces of Buffalo WSR-2533DHPL2 firmware version <= 1.02 and WSR-2533DHP3 firmware version <= 1.24 could allow unauthenticated remote | Apr 29, 2021 | 9.8 | 98 | YES | YES |
CVE-2020-5722CRITICAL The HTTP interface of the Grandstream UCM6200 series is vulnerable to an unauthenticated remote SQL injection via crafted HTTP request. An attacker can use this vulnerability to ex | Mar 23, 2020 | 9.8 | 98 | YES | YES |
CVE-2021-20123HIGH A local file inclusion vulnerability exists in Draytek VigorConnect 1.6.0-B3 in the file download functionality of the DownloadFileServlet endpoint. An unauthenticated attacker cou | Oct 13, 2021 | 7.5 | 94 | YES | YES |
CVE-2020-5741HIGH Deserialization of Untrusted Data in Plex Media Server on Windows allows a remote, authenticated attacker to execute arbitrary Python code. | May 8, 2020 | 7.2 | 94 | YES | YES |
CVE-2023-23488CRITICAL The Paid Memberships Pro WordPress Plugin, version < 2.9.8, is affected by an unauthenticated SQL injection vulnerability in the 'code' parameter of the '/pmpro/v1/order' REST rout | Jan 20, 2023 | 9.8 | 93 | NO | YES |
CVE-2021-20124HIGH A local file inclusion vulnerability exists in Draytek VigorConnect 1.6.0-B3 in the file download functionality of the WebServlet endpoint. An unauthenticated attacker could levera | Oct 13, 2021 | 7.5 | 93 | YES | YES |
CVE-2018-15708CRITICAL Snoopy 1.0 in Nagios XI 5.5.6 allows remote unauthenticated attackers to execute arbitrary commands via a crafted HTTP request. | Nov 14, 2018 | 9.8 | 90 | NO | YES |
CVE-2020-5735HIGH Amcrest cameras and NVR are vulnerable to a stack-based buffer overflow over port 37777. An authenticated remote attacker can abuse this issue to crash the device and possibly exec | Apr 8, 2020 | 8.8 | 88 | YES | YES |
CVE Severity & Scoring
Exploit Exposure
Signals from CVEs in this cna scope (562 CVEs).
Social Chatter
An overview of all social media posts that mention a CVE ID published by Tenable Network Security, Inc. as a CNA.
Media Mentions
Media articles that mention a CVE ID published by Tenable Network Security, Inc. as a CNA — matched by CVE ID, not by organization name.