Home/Product/tenable nessus agent
Product

tenable nessus agent

11 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2026-2026
< 11.0.4
A vulnerability has been identified where weak file permissions in the Nessus Agent directory on Windows hosts could allow unautho
6.1MEDIUM
CVE-2025-36632
< 10.8.5
In Tenable Agent versions prior to 10.8.5 on a Windows host, it was found that a non-administrative user could execute code with S
7.8HIGH
CVE-2025-36633
< 10.8.5
In Tenable Agent versions prior to 10.8.5 on a Windows host, it was found that a non-administrative user could arbitrarily delete
8.8HIGH
CVE-2025-36631
< 10.8.5
In Tenable Agent versions prior to 10.8.5 on a Windows host, it was found that a non-administrative user could overwrite arbitrary
8.4HIGH
CVE-2023-5847
< 10.4.3
Under certain conditions, a low privileged attacker could load a specially crafted file during installation or upgrade to escalate
6.7MEDIUM
CVE-2021-20118
<= 8.3.0
Nessus Agent 8.3.0 and earlier was found to contain a local privilege escalation vulnerability which could allow an authenticated,
6.7MEDIUM
CVE-2021-20117
<= 8.3.0
Nessus Agent 8.3.0 and earlier was found to contain a local privilege escalation vulnerability which could allow an authenticated,
6.7MEDIUM
CVE-2021-3450
>= 8.2.1 and <= 8.2.3
The X509_V_FLAG_X509_STRICT flag enables additional security checks of the certificates present in a certificate chain. It is not
7.4HIGH
CVE-2021-20077
>= 7.2.0 and < 8.2.3
Nessus Agent versions 7.2.0 through 8.2.2 were found to inadvertently capture the IAM role security token on the local host during
6.7MEDIUM
CVE-2020-5793
all versions
A vulnerability in Nessus versions 8.9.0 through 8.12.0 for Windows & Nessus Agent 8.0.0 and 8.1.0 for Windows could allow an auth
7.8HIGH
CVE-2019-16168
<= 8.2.3
In SQLite through 3.29.0, whereLoopAddBtreeIndex in sqlite3.c can crash a browser or other application because of missing validati
6.5MEDIUM
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin