Tenable Network Security maintains a focused vulnerability footprint centered on its flagship vulnerability-management and security-monitoring products, including Nessus, Tenable.sc, and the Nessus Agent, which are widely deployed across enterprise and government environments as core components of security operations. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity and a moderate tendency toward public exploit availability. The exposure recurs through weakness classes including insufficient information in CVE metadata, cross-site scripting in web-facing interfaces, integer overflow, out-of-bounds reads, and improper input validation—patterns typical of large, network-facing security tools that parse diverse data formats and accept user-supplied configuration. Defenders should prioritize patching these products in environments where they have internet accessibility or accept untrusted input, since compromise of the security monitoring layer can compromise visibility across a network. Current exploitation activity, exposure counts, and severity breakdowns are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Tenable Network Security, Inc. over time
Of all the CVEs published by Tenable Network Security, Inc. as a CNA, 15.1% affect products that Tenable Network Security, Inc. develops as a vendor.
Of all the CVEs published that affect products developed by Tenable Network Security, Inc., 49.7% are self-published by Tenable Network Security, Inc. as a CNA.
Signals from CVEs in this vendor scope (171 CVEs).
171 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-11043CRITICAL In PHP versions 7.1.x below 7.1.33, 7.2.x below 7.2.24 and 7.3.x below 7.3.11 in certain configurations of FPM setup it is possible to cause FPM module to write past allocated buff | Oct 28, 2019 | 9.8 | 98 | YES | YES |
CVE-2021-40438CRITICAL A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user. This issue affects Apache HTTP Server 2.4.48 and earlier. | Sep 16, 2021 | 9.0 | 97 | YES | YES |
CVE-2020-11023MEDIUM In jQuery versions greater than or equal to 1.0.3 and before 3.5.0, passing HTML containing <option> elements from untrusted sources - even after sanitizing it - to one of jQuery's | Apr 29, 2020 | 6.1 | 95 | YES | YES |
CVE-2021-44790CRITICAL A carefully crafted request body can cause a buffer overflow in the mod_lua multipart parser (r:parsebody() called from Lua scripts). The Apache httpd team is not aware of an explo | Dec 20, 2021 | 9.8 | 88 | NO | YES |
CVE-2020-11022MEDIUM In jQuery starting with 1.12.0 and before 3.5.0, passing HTML from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. .html(), .append | Apr 29, 2020 | 6.1 | 83 | NO | YES |
CVE-2021-3711CRITICAL In order to decrypt SM2 encrypted data an application is expected to call the API function EVP_PKEY_decrypt(). Typically an application will call this function twice. The first tim | Aug 24, 2021 | 9.8 | 79 | NO | NO |
CVE-2021-44224HIGH A crafted URI sent to httpd configured as a forward proxy (ProxyRequests on) can cause a crash (NULL pointer dereference) or, for configurations mixing forward and reverse proxy de | Dec 20, 2021 | 8.2 | 72 | NO | NO |
CVE-2022-0778HIGH The BN_mod_sqrt() function, which computes a modular square root, contains a bug that can cause it to loop forever for non-prime moduli. Internally this function is used when parsi | Mar 15, 2022 | 7.5 | 65 | NO | NO |
CVE-2021-34798HIGH Malformed requests may cause the server to dereference a NULL pointer. This issue affects Apache HTTP Server 2.4.48 and earlier. | Sep 16, 2021 | 7.5 | 61 | NO | NO |
CVE-2021-3449MEDIUM An OpenSSL TLS server may crash if sent a maliciously crafted renegotiation ClientHello message from a client. If a TLSv1.2 renegotiation ClientHello omits the signature_algorithms | Mar 25, 2021 | 5.9 | 57 | NO | NO |
Signals from CVEs in this vendor scope (171 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Tenable Network Security, Inc..
Media articles that mention a CVE ID that affects a product developed by Tenable Network Security, Inc. — matched by CVE ID, not by vendor name.