Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Tenable Network Security, Inc.

First CVE: Sep 24, 2013Active for: 13 yearsTotal CVEs: 171
61.6
VTI Score
TOP TARGET

Tenable Network Security maintains a focused vulnerability footprint centered on its flagship vulnerability-management and security-monitoring products, including Nessus, Tenable.sc, and the Nessus Agent, which are widely deployed across enterprise and government environments as core components of security operations. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity and a moderate tendency toward public exploit availability. The exposure recurs through weakness classes including insufficient information in CVE metadata, cross-site scripting in web-facing interfaces, integer overflow, out-of-bounds reads, and improper input validation—patterns typical of large, network-facing security tools that parse diverse data formats and accept user-supplied configuration. Defenders should prioritize patching these products in environments where they have internet accessibility or accept untrusted input, since compromise of the security monitoring layer can compromise visibility across a network. Current exploitation activity, exposure counts, and severity breakdowns are shown alongside this summary.

FAUCET AI Generated
171
Total CVEs
More Total CVEs than 100% of tracked vendors
0.8
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 12% of tracked vendors
7.0
Avg CVSS Score
Higher Avg CVSS Score than 50% of tracked vendors
1.8%
In CISA KEV
Higher KEV Rate than 99% of tracked vendors

Trends Over Time

The number and severity of CVEs published that impact products developed by Tenable Network Security, Inc. over time

Volume of CVEsAvg CVSS Base Score
First CVE
Sep 24, 2013
12 years ago
Most Recent CVE
Jun 25, 2026
29 days ago

Self-Reporting Analysis

Of all the CVEs published by Tenable Network Security, Inc. as a CNA, 15.1% affect products that Tenable Network Security, Inc. develops as a vendor.

15.1%
84.9%
Self-reported: 85 (15.1%)
Third-party: 477 (84.9%)

Of all the CVEs published that affect products developed by Tenable Network Security, Inc., 49.7% are self-published by Tenable Network Security, Inc. as a CNA.

49.7%
50.3%
Self-published: 85 (49.7%)
Other CNAs: 86 (50.3%)

Products(16 total)

Top CVEs

Signals from CVEs in this vendor scope (171 CVEs).

171 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2019-11043CRITICAL
In PHP versions 7.1.x below 7.1.33, 7.2.x below 7.2.24 and 7.3.x below 7.3.11 in certain configurations of FPM setup it is possible to cause FPM module to write past allocated buff
Oct 28, 20199.898YESYES
CVE-2021-40438CRITICAL
A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user. This issue affects Apache HTTP Server 2.4.48 and earlier.
Sep 16, 20219.097YESYES
CVE-2020-11023MEDIUM
In jQuery versions greater than or equal to 1.0.3 and before 3.5.0, passing HTML containing <option> elements from untrusted sources - even after sanitizing it - to one of jQuery's
Apr 29, 20206.195YESYES
CVE-2021-44790CRITICAL
A carefully crafted request body can cause a buffer overflow in the mod_lua multipart parser (r:parsebody() called from Lua scripts). The Apache httpd team is not aware of an explo
Dec 20, 20219.888NOYES
CVE-2020-11022MEDIUM
In jQuery starting with 1.12.0 and before 3.5.0, passing HTML from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. .html(), .append
Apr 29, 20206.183NOYES
CVE-2021-3711CRITICAL
In order to decrypt SM2 encrypted data an application is expected to call the API function EVP_PKEY_decrypt(). Typically an application will call this function twice. The first tim
Aug 24, 20219.879NONO
CVE-2021-44224HIGH
A crafted URI sent to httpd configured as a forward proxy (ProxyRequests on) can cause a crash (NULL pointer dereference) or, for configurations mixing forward and reverse proxy de
Dec 20, 20218.272NONO
CVE-2022-0778HIGH
The BN_mod_sqrt() function, which computes a modular square root, contains a bug that can cause it to loop forever for non-prime moduli. Internally this function is used when parsi
Mar 15, 20227.565NONO
CVE-2021-34798HIGH
Malformed requests may cause the server to dereference a NULL pointer. This issue affects Apache HTTP Server 2.4.48 and earlier.
Sep 16, 20217.561NONO
CVE-2021-3449MEDIUM
An OpenSSL TLS server may crash if sent a maliciously crafted renegotiation ClientHello message from a client. If a TLSv1.2 renegotiation ClientHello omits the signature_algorithms
Mar 25, 20215.957NONO
View all 171 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products171 CVEs
46%
41%
11%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local41 (24.0%)
Network125 (73.1%)
Unknown4 (2.3%)
Physical0 (0.0%)
Adjacent Network1 (0.6%)
Attack Complexity
Low153 (89.5%)
High14 (8.2%)
Unknown4 (2.3%)
User Interaction
None120 (70.2%)
Unknown4 (2.3%)
Required47 (27.5%)
Privileges Required
Low69 (40.4%)
High21 (12.3%)
None77 (45.0%)
Unknown4 (2.3%)

Exploit Exposure

Signals from CVEs in this vendor scope (171 CVEs).

CISA KEV
3 CVEs
1.8% of CVEs· 99th percentile
Metasploit
1 CVE
0.6% of CVEs· 97th percentile
Nuclei
1 CVE
0.6% of CVEs· 95th percentile
ExploitDB
8 CVEs
4.7% of CVEs· 75th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Tenable Network Security, Inc..

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Tenable Network Security, Inc. — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Tenable Network Security, Inc.'s Products

View all 11 CNAs →

Top CWEs