📦

tenable.sc

Vendor: tenable

Actively Exploited 2 CISA KEV List
PoC / Exploits 6 Code Available
Total RCEs 8 Remote Access
Total CVEs 48 Total Indexed
Avg. EPSS 10.82% Exploit Prob.
Latest CVE CVE-2023-0524 Feb 01

Security Vulnerability Index

Page 5 / 5
9.8 CVSS

pragma.c in SQLite through 3.30.1 mishandles NOT NULL in an integrity_check PRAGMA command in certain cases of generated columns.

EPSS: 9.46%
5.5 CVSS

alter.c in SQLite through 3.30.1 allows attackers to trigger infinite recursion via certain types of self-referential views in conjunction with ALTER TABLE statements.

EPSS: 0.40%
Critical Target
8.7 CVSS
CVE-2019-11043
RCE Exploit Found

In PHP versions 7.1.x below 7.1.33, 7.2.x below 7.2.24 and 7.3.x below 7.3.11 in certain configurations of FPM setup it is possible to cause FPM module to write past allocated buffers into the space reserved for FCGI protocol data, thus opening the possibility of remote code execution.

EPSS: 94.05%
7.1 CVSS

When PHP EXIF extension is parsing EXIF information from an image, e.g. via exif_read_data() function, in PHP versions 7.1.x below 7.1.31, 7.2.x below 7.2.21 and 7.3.x below 7.3.8 it is possible to supply it with data what will cause it to read past the allocated buffer. This may lead to information disclosure or crash.

EPSS: 3.81%
7.1 CVSS

When PHP EXIF extension is parsing EXIF information from an image, e.g. via exif_read_data() function, in PHP versions 7.1.x below 7.1.31, 7.2.x below 7.2.21 and 7.3.x below 7.3.8 it is possible to supply it with data what will cause it to read past the allocated buffer. This may lead to information disclosure or crash.

EPSS: 3.21%
6.1 CVSS

In Bootstrap before 3.4.1 and 4.3.x before 4.3.1, XSS is possible in the tooltip or popover data-template attribute.

EPSS: 1.67%