Tenable Security Center — known CVE vulnerabilities
Every CVE whose affected-product data names Tenable Security Center, ordered by CVSS severity, with EPSS exploit prediction and CISA KEV status.
CVEs (32)
CVE-2026-19626 — CVSS 9.9 (critical): A remote code execution vulnerability exists in Tenable Security Center's report generation functionality. An authenticated…
CVE-2026-64879 — CVSS 9.9 (critical): A filename supplied during file upload is not properly sanitized before being used in system command execution, allowing an attacker to…
CVE-2026-64878 — CVSS 9.9 (critical): Unvalidated input in asset filter parameters allows shell metacharacters to escape command argument handling, resulting in remote code…
CVE-2026-19682 — CVSS 9.9 (critical): A command injection vulnerability exists in Security Center where a remote, unauthenticated attacker could exploit this issue to execute…
CVE-2026-19681 — CVSS 9.9 (critical): An authenticated command injection vulnerability exists in Security Center related to file upload processing. An attacker could exploit…
CVE-2026-19635 — CVSS 8.8 (high): A local privilege escalation vulnerability exists in Security Center. An attacker with write access to a specific configuration file could…
CVE-2017-11508 — CVSS 8.8 (high): SecurityCenter versions 5.5.0, 5.5.1 and 5.5.2 contain a SQL Injection vulnerability that could be exploited by an authenticated user with…
CVE-2018-1154 — CVSS 8.8 (high): In SecurityCenter versions prior to 5.7.0, a username enumeration issue could allow an unauthenticated attacker to automate the discovery…
CVE-2026-64881 — CVSS 8.8 (high): The audit file upload handler does not sanitize filenames, allowing shell metacharacters to flow into system command execution. This input…
CVE-2026-19679 — CVSS 8.8 (high): An input validation vulnerability exists in Security Center's file upload handling, where insufficient sanitization of uploaded filenames…
CVE-2026-64877 — CVSS 8.4 (high): An authenticated non-admin user can exploit a SQL injection flaw in the ticketing REST API to access sensitive data stored in the appliance…
CVE-2026-19629 — CVSS 8.1 (high): A privilege escalation vulnerability exists in Tenable Security Center that allows a user with "Security Manager" role and "manage user"…
CVE-2024-1367 — CVSS 7.2 (high): A command injection vulnerability exists where an authenticated, remote attacker with administrator privileges on the Security Center…
CVE-2026-19628 — CVSS 7.2 (high): A command injection vulnerability exists in Tenable Security Center. An authenticated administrator could modify application configuration…
CVE-2026-64880 — CVSS 7.1 (high): Unsanitized user-supplied input in report filtering parameters is concatenated directly into SQL queries without proper escaping or…
CVE-2026-19680 — CVSS 7.1 (high): A SQL injection vulnerability exists in Security Center that could allow an attacker to access unauthorized data from the application's…
CVE-2019-11049 — CVSS 6.5 (medium): In PHP versions 7.3.x below 7.3.13 and 7.4.0 on Windows, when supplying custom headers to mail() function, due to mistake introduced in…
CVE-2026-2698 — CVSS 6.5 (medium): An improper access control vulnerability exists where an authenticated user could access areas outside of their authorized scope.
CVE-2026-2697 — CVSS 6.3 (medium): An Indirect Object Reference (IDOR) in Security Center allows an authenticated remote attacker to escalate privileges via the 'owner'…
CVE-2024-1471 — CVSS 5.9 (medium): An HTML injection vulnerability exists where an authenticated, remote attacker with administrator privileges on the Security Center…
CVE-2018-1155 — CVSS 5.4 (medium): In SecurityCenter versions prior to 5.7.0, a cross-site scripting (XSS) issue could allow an authenticated attacker to inject JavaScript…
CVE-2024-5759 — CVSS 5.4 (medium): An improper privilege management vulnerability exists in Tenable Security Center where an authenticated, remote attacker could view…
CVE-2026-19636 — CVSS 5.3 (medium): An issue was identified in which CSRF tokens were generated using a predictable method, potentially reducing their effectiveness as a…
CVE-2026-19631 — CVSS 4.9 (medium): A SQL injection vulnerability exists in Security Center that could allow an authenticated administrator to execute arbitrary SQL queries…
CVE-2019-11050 — CVSS 4.8 (medium): When PHP EXIF extension is parsing EXIF information from an image, e.g. via exif_read_data() function, in PHP versions 7.2.x below 7.2.26…
CVE-2026-19639 — CVSS 4.3 (medium): An improper access control vulnerability exists where an authenticated non-administrative application user could potentially view settings…
CVE-2013-5911 — CVSS 4.3 (medium): Cross-site scripting (XSS) vulnerability in devform.php in Tenable SecurityCenter 4.6 through 4.7 allows remote attackers to inject…
CVE-2019-11046 — CVSS 3.7 (low): In PHP versions 7.2.x below 7.2.26, 7.3.x below 7.3.13 and 7.4.0, PHP bcmath extension functions on some systems, including Windows, can be…
CVE-2019-11045 — CVSS 3.7 (low): In PHP versions 7.2.x below 7.2.26, 7.3.x below 7.3.13 and 7.4.0, PHP DirectoryIterator class accepts filenames with embedded \0 byte and…
CVE-2019-11044 — CVSS 3.7 (low): In PHP versions 7.2.x below 7.2.26, 7.3.x below 7.3.13 and 7.4.0 on Windows, PHP link() function accepts filenames with embedded \0 byte…
CVE-2024-1891 — CVSS 3.5 (low): A stored cross site scripting vulnerability exists in Tenable Security Center where an authenticated, remote attacker could inject HTML…