Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Nessus

First CVE: Jun 16, 2003Active for: 23 yearsTotal CVEs: 13
32.2
VTI Score
Medium

Nessus is a widely deployed vulnerability-scanning platform whose focused product line concentrates on the scanner itself and associated plugins and components. The vendor's disclosures reflect the attack surface of web-connected scanning infrastructure, with recurring weaknesses in path traversal, information exposure, cross-site scripting, and buffer-boundary handling that are typical of applications parsing untrusted input and managing privileged access. Public exploit code has a notable tendency to emerge for this vendor's vulnerabilities, making patching cycles operationally important for organizations relying on the scanner for security assessment. Live severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
13
Total CVEs
More Total CVEs than 94% of tracked vendors
0.7
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 10% of tracked vendors
5.2
Avg CVSS Score
Higher Avg CVSS Score than 14% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Nessus over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jun 16, 2003
23 years ago
Most Recent CVE
Aug 10, 2010
5,826 days ago

Products(4 total)

Top CVEs

Signals from CVEs in this vendor scope (13 CVEs).

13 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2007-4061HIGH
Directory traversal vulnerability in a certain ActiveX control in Nessus Vulnerability Scanner 3.0.6 allows remote attackers to create or overwrite arbitrary files via a .. (dot do
Jul 30, 20079.338NOYES
CVE-2007-4031HIGH
Directory traversal vulnerability in a certain ActiveX control in Nessus Vulnerability Scanner 3.0.6 allows remote attackers to delete arbitrary files via a .. (dot dot) in the arg
Jul 27, 20077.831NOYES
CVE-2007-4062HIGH
The SCANCTRL.ScanCtrlCtrl.1 ActiveX control in scan.dll in Nessus Vulnerability Scanner 3.0.6 allows remote attackers to delete arbitrary files via unspecified vectors involving th
Jul 30, 20077.829NOYES
CVE-2003-0372MEDIUM
Signed integer vulnerability in libnasl in Nessus before 2.0.6 allows local users with plugin upload privileges to cause a denial of service (core dump) and possibly execute arbitr
Jun 16, 20034.626NOYES
CVE-2003-0374HIGH
Multiple unknown vulnerabilities in Nessus before 2.0.6, in libnessus and possibly libnasl, a different set of vulnerabilities than those identified by CVE-2003-0372 and CVE-2003-0
Jun 16, 200310.025NONO
CVE-2010-2989MEDIUM
nessusd_www_server.nbin in the Nessus Web Server plugin 1.2.4 for Nessus allows remote attackers to obtain sensitive information via a request to the /feed method, which reveals th
Aug 10, 20105.018NONO
CVE-2010-2914MEDIUM
Cross-site scripting (XSS) vulnerability in nessusd_www_server.nbin in the Nessus Web Server plugin 1.2.4 for Nessus allows remote attackers to inject arbitrary web script or HTML
Jul 30, 20104.315NONO
CVE-2007-3546MEDIUM
Cross-site scripting (XSS) vulnerability in the Windows GUI in Nessus Vulnerability Scanner before 3.0.6 allows remote attackers to inject arbitrary web script or HTML via unspecif
Jul 3, 20074.314NONO
CVE-2003-0373MEDIUM
Multiple buffer overflows in libnasl in Nessus before 2.0.6 allow local users with plugin upload privileges to cause a denial of service (core dump) and possibly execute arbitrary
Jun 16, 20034.414NONO
CVE-2004-1445LOW
A race condition in nessus-adduser in Nessus 2.0.11 and possibly earlier versions, if the TMPDIR environment variable is not set, allows local users to gain privileges.
Dec 31, 20043.713NONO
View all 13 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products13 CVEs
31%
38%
31%
Severity distribution among all CVEs352,101 CVEs
45%
40%
11%
LowMediumHigh
Attack Vector
Local0 (0.0%)
Network0 (0.0%)
Unknown13 (100.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low0 (0.0%)
High0 (0.0%)
Unknown13 (100.0%)
User Interaction
None0 (0.0%)
Unknown13 (100.0%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None0 (0.0%)
Unknown13 (100.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (13 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
4 CVEs
30.8% of CVEs· 79th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Nessus.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Nessus — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Nessus's Products

View all 1 CNAs →

Top CWEs