Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Nessus — Vulnerabilities & Security Advisories 23

All 23 CVE vulnerabilities found in Nessus, with AI-generated Chinese analysis, references, and POCs.

This page documents vulnerabilities associated with Nessus, a vulnerability scanner developed by Tenable, focusing on common weakness enumerations. It aggregates reports detailing various security flaws, ranging from authentication bypasses and privilege escalation issues to cross-site scripting and information disclosure vulnerabilities affecting the software and its plugins. The data covers incidents reported from 2015 through 2024, providing a comprehensive historical perspective on the product's security landscape. Users can utilize this resource to track vendor advisories issued by Tenable for Nessus, allowing security teams to monitor patch cycles and response times effectively. Additionally, the page helps in understanding specific weakness classes by mapping them to concrete implementation failures within the scanner environment. Readers can also look up a product's vulnerability history to identify recurring patterns or persistent issues that may indicate deeper architectural flaws. This aggregation serves as a neutral reference for security analysts, auditors, and developers seeking to assess the risk profile of Nessus deployments. By consolidating disparate reports into a single view, it facilitates better decision-making regarding vulnerability management and prioritization. The content excludes marketing language to ensure an objective overview of the security posture. It aims to support informed risk assessments by providing clear, factual data on the types of exploits and their impact on Nessus functionality. This resource is essential for organizations relying on Nessus for network security, helping them stay informed about known defects and their remediation status over time.

Vendor: Tenable

CVE IDTitleCVSSSeverityPublished
CVE-2026-57588 SQL Injection in Nessus via Malicious Scan Result File Import CWE-89 3.3 Low2026-06-25
CVE-2026-57587 SQL Injection in Nessus via Reverse DNS Lookup CWE-89 5.3 Medium2026-06-25
CVE-2025-36630 Local Privilege Escalation CWE-269 8.4 High2025-07-01
CVE-2025-36625 Log Poisoning in Nessus CWE-117 4.3 Medium2025-04-18
CVE-2025-24914 Local Priviledge Escalation CWE-276 7.8 High2025-04-18
CVE-2024-3290 Race Condition CWE-367 8.2 High2024-05-17
CVE-2024-3289 Tenable Network Security Nessus 安全漏洞 CWE-281 7.8 High2024-05-17
CVE-2024-0971 Nessus SQL注入漏洞 CWE-89 6.5 Medium2024-02-06
CVE-2024-0955 Stored XSS vulnerability CWE-20 4.8 Medium2024-02-06
CVE-2023-6062 Arbitrary File Write 6.8 Medium2023-11-20
CVE-2023-5847 Tenable Network Security Nessus 安全漏洞 CWE-269 6.7 Medium2023-11-01
CVE-2023-3253 Improper authorization in Nessus 4.3 Medium2023-08-29
CVE-2023-3252 Arbitrary File Write 6.8 Medium2023-08-29
CVE-2023-3251 Pass-back vulnerability in Nessus CWE-522 4.1 Medium2023-08-29
CVE-2023-0101 Nessus 安全漏洞 8.8 -2023-01-20
CVE-2022-32974 Tenable Network Security Nessus 输入验证错误漏洞 6.5 -2022-06-21
CVE-2022-32973 Tenable Network Security Nessus操作系统命令注入漏洞 8.8 -2022-06-21
CVE-2021-20135 Tenable Network Security Nessus 权限许可和访问控制问题漏洞 6.7 -2021-11-02
CVE-2021-20079 Tenable Network Security Nessus 安全漏洞 6.7 -2021-06-29
CVE-2019-3962 Tenable Network Security Nessus 跨站脚本漏洞 3.3 -2019-07-01
CVE-2018-1141 Tenable Network Security Nessus 安全漏洞 7.0 -2018-03-20
CVE-2017-11506 Tenable Network Security Nessus 安全漏洞 7.4 -2017-08-09
CVE-2017-2122 Tenable Network Security Nessus 跨站脚本漏洞 5.4 -2017-05-12

All 23 known CVE vulnerabilities affecting Nessus with full Chinese analysis, references, and POCs where available.