Securitycenter
Vendor:
First CVE: Sep 24, 2013 · Active for 12 years
19
Total CVEs
More Total CVEs than 93% of tracked products
2.4
Avg CVEs / Year
Higher CVE frequency than 74% of tracked products
6.6
Avg CVSS
Higher Avg CVSS than 33% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Securitycenter over time
Volume of CVEsAvg CVSS Base Score
First CVE
Sep 24, 2013
12 years ago
Most Recent CVE
Feb 23, 2026
151 days ago
CVE Severity & Scoring
Securitycenter19 CVEs
53%
37%
All CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network17 (89.5%)
Unknown1 (5.3%)
Physical0 (0.0%)
Adjacent Network1 (5.3%)
Attack Complexity
Low17 (89.5%)
High1 (5.3%)
Unknown1 (5.3%)
User Interaction
None15 (78.9%)
Unknown1 (5.3%)
Required3 (15.8%)
Privileges Required
Low9 (47.4%)
High3 (15.8%)
None6 (31.6%)
Unknown1 (5.3%)
Top CVEs
Signals from CVEs in this product scope (19 CVEs).
19 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-11049CRITICAL In PHP versions 7.3.x below 7.3.13 and 7.4.0 on Windows, when supplying custom headers to mail() function, due to mistake introduced in commit 78f4b4a2dcf92ddbccea1bb95f8390a18ac33 | Dec 23, 2019 | 9.8 | 32 | NO | NO |
CVE-2026-2630HIGH A Command Injection vulnerability exists where an authenticated, remote attacker could execute arbitrary code on the underlying server where Tenable Security Center is hosted. | Feb 17, 2026 | 8.8 | 31 | NO | NO |
CVE-2026-2697HIGH An Indirect Object Reference (IDOR) in Security Center allows an authenticated remote attacker to escalate privileges via the 'owner' parameter. | Feb 23, 2026 | 8.8 | 27 | NO | NO |
CVE-2023-2005HIGH Vulnerability in Tenable Tenable.Io, Tenable Nessus, Tenable Security Center.This issue affects Tenable.Io: before Plugin Feed ID #202306261202 ; Nessus: before Plugin Feed ID #202 | Jun 26, 2023 | 8.8 | 27 | NO | NO |
CVE-2018-1154HIGH In SecurityCenter versions prior to 5.7.0, a username enumeration issue could allow an unauthenticated attacker to automate the discovery of username aliases via brute force, ultim | Aug 2, 2018 | 8.8 | 27 | NO | NO |
CVE-2019-11044HIGH In PHP versions 7.2.x below 7.2.26, 7.3.x below 7.3.13 and 7.4.0 on Windows, PHP link() function accepts filenames with embedded \0 byte and treats them as terminating at that byte | Dec 23, 2019 | 7.5 | 26 | NO | NO |
CVE-2017-11508HIGH SecurityCenter versions 5.5.0, 5.5.1 and 5.5.2 contain a SQL Injection vulnerability that could be exploited by an authenticated user with sufficient privileges to run diagnostic s | Nov 2, 2017 | 8.8 | 26 | NO | NO |
CVE-2019-11050MEDIUM When PHP EXIF extension is parsing EXIF information from an image, e.g. via exif_read_data() function, in PHP versions 7.2.x below 7.2.26, 7.3.x below 7.3.13 and 7.4.0 it is possib | Dec 23, 2019 | 6.5 | 25 | NO | NO |
CVE-2019-11045MEDIUM In PHP versions 7.2.x below 7.2.26, 7.3.x below 7.3.13 and 7.4.0, PHP DirectoryIterator class accepts filenames with embedded \0 byte and treats them as terminating at that byte. T | Dec 23, 2019 | 5.9 | 25 | NO | NO |
CVE-2024-1367HIGH
A command injection vulnerability exists where an authenticated, remote attacker with administrator privileges on the Security Center application could modify Logging parameters, | Feb 14, 2024 | 7.2 | 23 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (19 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (19 CVEs).
Media Mentions
Signals from CVEs in this product scope (19 CVEs).
Top CNAs Publishing CVEs For Securitycenter
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 5.5.2 | 1 | 8.8 | 1.2% | 0 | 0 |
| 5.5.1 | 1 | 8.8 | 1.2% | 0 | 0 |
| 5.5.0 | 1 | 8.8 | 1.2% | 0 | 0 |
| 4.7 | 1 | 4.3 | 0.9% | 0 | 0 |
| 4.6 | 1 | 4.3 | 0.9% | 0 | 0 |