📦 Nessus

by Tenable

🔍 What is Nessus?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2022-23852

CRITICAL CVSS 9.8 Jan 24, 2022

CVE-2022-23852 is a signed integer overflow vulnerability in Expat (libexpat) XML parser that can lead to buffer overflow. When XML_CONTEXT_BYTES is configured to a nonzero value, XML_GetBuffer can ov...

CVE-2022-22822

CRITICAL CVSS 9.8 Jan 10, 2022

CVE-2022-22822 is an integer overflow vulnerability in Expat's XML parser that can lead to heap buffer overflow. This allows attackers to execute arbitrary code or cause denial of service by processin...

CVE-2022-22824

CRITICAL CVSS 9.8 Jan 10, 2022

CVE-2022-22824 is an integer overflow vulnerability in Expat's defineAttribute function in xmlparse.c. This allows attackers to cause heap-based buffer overflows, potentially leading to arbitrary code...

CVE-2022-4313

HIGH CVSS 8.8 Mar 15, 2023

This vulnerability allows authenticated users with Scan Policy Configuration roles in Tenable products to manipulate audit policy variables and execute arbitrary commands on credentialed scan targets....

CVE-2022-32973

HIGH CVSS 8.8 Jun 21, 2022

CVE-2022-32973 allows authenticated attackers to bypass PowerShell cmdlet security checks by creating specially crafted audit files, enabling execution of arbitrary commands with administrator privile...

CVE-2022-0778

HIGH CVSS 7.5 Mar 15, 2022

CVE-2022-0778 is a denial-of-service vulnerability in OpenSSL's BN_mod_sqrt() function that can cause infinite loops when parsing specially crafted certificates or private keys containing invalid elli...

CVE-2022-23990

HIGH CVSS 7.5 Jan 26, 2022

CVE-2022-23990 is an integer overflow vulnerability in Expat (libexpat) XML parser library that can lead to denial of service or arbitrary code execution. Any application using vulnerable versions of ...

CVE-2022-22826

HIGH CVSS 8.8 Jan 10, 2022

CVE-2022-22826 is an integer overflow vulnerability in Expat's XML parser that can lead to heap memory corruption. Attackers can exploit this by providing specially crafted XML input, potentially caus...

CVE-2021-46143

HIGH CVSS 8.1 Jan 6, 2022

CVE-2021-46143 is an integer overflow vulnerability in Expat's XML parser that can lead to heap memory corruption. Attackers can exploit this by providing specially crafted XML input, potentially caus...

CVE-2021-3450

HIGH CVSS 7.4 Mar 25, 2021

This OpenSSL vulnerability allows certificate chain validation to be bypassed when the X509_V_FLAG_X509_STRICT flag is explicitly set. It affects applications using OpenSSL 1.1.1h-1.1.1j that enable s...