nessus CVE Vulnerabilities & CVE List (13)

Products (CPE): — CVEs: 13

nessus vulnerability overview

Aggregates CVE and security vulnerability intelligence across all nessus-related products, including CVSS, EPSS, publication dates, and vulnerability intelligence data.

Common weakness patterns include vendor risk path handling, vendor risk cross-site scripting, and vendor risk buffer overflow, with potential vendor impact file overwrite across vendor surface software deployment use cases.

Vulnerability distribution trend (last 24 months)

Showing 113 of 13 CVEs
«« First « Prev Page 1 / 1 Next »
CVE Summary Source Max CVSS EPSS % Published Updated
CVE-2010-2989 nessusd_www_server.nbin in the Nessus Web Server plugin 1.2.4 for Nessus allows remote attackers to obtain sensitive information via a request to the /feed method, which reveals the version in a response. [email protected] 5.0 0.23% 2010-08-10 2026-04-29
CVE-2010-2914 Cross-site scripting (XSS) vulnerability in nessusd_www_server.nbin in the Nessus Web Server plugin 1.2.4 for Nessus allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. [email protected] 4.3 0.26% 2010-07-30 2026-04-29
CVE-2007-4062 The SCANCTRL.ScanCtrlCtrl.1 ActiveX control in scan.dll in Nessus Vulnerability Scanner 3.0.6 allows remote attackers to delete arbitrary files via unspecified vectors involving the deleteNessusRC method, probably a directory traversal vulnerability. [email protected] 7.8 4.41% 2007-07-30 2026-04-23
CVE-2007-4061 Directory traversal vulnerability in a certain ActiveX control in Nessus Vulnerability Scanner 3.0.6 allows remote attackers to create or overwrite arbitrary files via a .. (dot dot) in the argument to the saveNessusRC method, which writes text specified by the addsetConfig method, possibly related to the SCANCTRL.ScanCtrlCtrl.1 ActiveX control in scan.dll. NOTE: this can be leveraged for code execution by writing to a Startup folder. [email protected] 9.3 11.00% 2007-07-30 2026-04-23
CVE-2007-4031 Directory traversal vulnerability in a certain ActiveX control in Nessus Vulnerability Scanner 3.0.6 allows remote attackers to delete arbitrary files via a .. (dot dot) in the argument to the deleteReport method, probably related to the SCANCTRL.ScanCtrlCtrl.1 ActiveX control in scan.dll. [email protected] 7.8 7.58% 2007-07-27 2026-04-23
CVE-2007-3546 Cross-site scripting (XSS) vulnerability in the Windows GUI in Nessus Vulnerability Scanner before 3.0.6 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. [email protected] 4.3 0.77% 2007-07-03 2026-04-23
CVE-2006-2093 Nessus before 2.2.8, and 3.x before 3.0.3, allows user-assisted attackers to cause a denial of service (memory consumption) via a NASL script that calls split with an invalid sep parameter. NOTE: a design goal of the NASL language is to facilitate sharing of security tests by guaranteeing that a script "can not do anything nasty." This issue is appropriate for CVE only if Nessus users have an expectation that a split statement will not use excessive memory. [email protected] 2.6 1.11% 2006-04-29 2026-04-16
CVE-2004-2723 NessusWX 1.4.4 stores account passwords in plaintext in .session files, which allows local users to obtain passwords. [email protected] 2.1 0.07% 2004-12-31 2026-04-16
CVE-2004-2722 Nessus 2.0.10a stores account passwords in plaintext in .nessusrc files, which allows local users to obtain passwords. NOTE: the original researcher reports that the vendor has disputed this issue [email protected] 2.1 0.15% 2004-12-31 2026-04-16
CVE-2004-1445 A race condition in nessus-adduser in Nessus 2.0.11 and possibly earlier versions, if the TMPDIR environment variable is not set, allows local users to gain privileges. [email protected] 3.7 0.07% 2004-12-31 2026-04-16
CVE-2003-0374 Multiple unknown vulnerabilities in Nessus before 2.0.6, in libnessus and possibly libnasl, a different set of vulnerabilities than those identified by CVE-2003-0372 and CVE-2003-0373, aka "similar issues in other nasl functions as well as in libnessus." [email protected] 10.0 0.47% 2003-06-16 2026-04-16
CVE-2003-0373 Multiple buffer overflows in libnasl in Nessus before 2.0.6 allow local users with plugin upload privileges to cause a denial of service (core dump) and possibly execute arbitrary code via (1) a long proto argument to the scanner_add_port function, (2) a long user argument to the ftp_log_in function, (3) a long pass argument to the ftp_log_in function. [email protected] 4.4 0.09% 2003-06-16 2026-04-16
CVE-2003-0372 Signed integer vulnerability in libnasl in Nessus before 2.0.6 allows local users with plugin upload privileges to cause a denial of service (core dump) and possibly execute arbitrary code by causing a negative argument to be provided to the insstr function as used in a NASL script. [email protected] 4.6 0.19% 2003-06-16 2026-04-16
«« First « Prev Page 1 / 1 Next »
cvelogic Threat Intelligence