As information about new vulnerabilities is discovered and released into the general public domain, Tenable Research designs programs to detect them. These programs are named plugins and are written in the Nessus Attack Scripting Language (NASL). The plugins contain vulnerability information, a simplified set of remediation actions and the algorithm to test for the presence of the security issue. Tenable Research has published 424476 plugins, covering 144108 CVE IDs and 32952 Bugtraq IDs.
| ID | Name | Product | Family | Severity |
|---|---|---|---|---|
| 505912 | Mitsubishi Electric MELSEC iQ-F Series FX5-EIP EtherNet/IP Module Improper Resource Shutdown or Release (CVE-2026-1875) | Tenable OT Security | Tenable.ot | high |
| 505911 | Qnap QTS and QuTS hero Path Traversal (CVE-2026-24717) | Tenable OT Security | Tenable.ot | medium |
| 505910 | Qnap QTS and QuTS hero Stack-based Buffer Overflow (CVE-2025-62858) | Tenable OT Security | Tenable.ot | medium |
| 505909 | Qnap QTS and QuTS hero Cross-site Scripting (CVE-2026-41539) | Tenable OT Security | Tenable.ot | medium |
| 505908 | Brother MFC-9970CDW Printers Cross-site Scripting (CVE-2013-2507) | Tenable OT Security | Tenable.ot | medium |
| 505907 | Brother MFC-9970CDW Printers Cross-site Scripting (CVE-2013-2670) | Tenable OT Security | Tenable.ot | medium |
| 505906 | Brother MFC-9970CDW Printers Cross-site Scripting (CVE-2013-2671) | Tenable OT Security | Tenable.ot | medium |
| 505905 | Lexmark Printers Improper Restriction of Operations within the Bounds of a Memory Buffer (CVE-2018-15520) | Tenable OT Security | Tenable.ot | critical |
| 505904 | Qnap QTS and QuTS hero OS Command Injection (CVE-2026-22893) | Tenable OT Security | Tenable.ot | high |
| 505903 | Qnap QTS and QuTS hero OS Command Injection (CVE-2025-66279) | Tenable OT Security | Tenable.ot | high |
| 505902 | Qnap QTS and QuTS hero NULL Pointer Dereference (CVE-2025-66281) | Tenable OT Security | Tenable.ot | high |
| 505901 | Qnap QTS and QuTS hero Stack-based Buffer Overflow (CVE-2025-66280) | Tenable OT Security | Tenable.ot | high |
| 505900 | Qnap QTS and QuTS hero OS Command Injection (CVE-2025-66273) | Tenable OT Security | Tenable.ot | high |
| 505899 | Qnap QTS and QuTS hero NULL Pointer Dereference (CVE-2026-24716) | Tenable OT Security | Tenable.ot | high |
| 505898 | Qnap QuTS hero NULL Pointer Dereference (CVE-2025-62850) | Tenable OT Security | Tenable.ot | high |
| 505897 | Mitsubishi Electric MELSEC iQ-F Series FX5-ENET/IP Ethernet Module Improper Resource Shutdown or Release (CVE-2026-1876) | Tenable OT Security | Tenable.ot | high |
| 445519 | SCA: security update for @anephenix/hub (GHSA-g5vv-q72c-7j78) | Tenable Cloud Security | SCA Checks | high |
| 445519 | SCA: security update for @anephenix/hub (GHSA-g5vv-q72c-7j78) | Tenable Self-Hosted Container Security | SCA Checks | high |
| 445518 | SCA: security update for oxid-esales/oxideshop-ce, oxid-esales/oxideshop-metapackage-ce, oxid-esales/smarty-component (GHSA-qqcr-9jfc-35c4) | Tenable Cloud Security | SCA Checks | medium |
| 445518 | SCA: security update for oxid-esales/oxideshop-ce, oxid-esales/oxideshop-metapackage-ce, oxid-esales/smarty-component (GHSA-qqcr-9jfc-35c4) | Tenable Self-Hosted Container Security | SCA Checks | medium |
| 445517 | SCA: security update for @aws-amplify/codegen-ui-react (GHSA-hf3j-86p7-mfw8) | Tenable Cloud Security | SCA Checks | critical |
| 445517 | SCA: security update for @aws-amplify/codegen-ui-react (GHSA-hf3j-86p7-mfw8) | Tenable Self-Hosted Container Security | SCA Checks | critical |
| 331379 | RockyLinux 8 : python-pillow (RLSA-2026:48021) | Nessus | Rocky Linux Local Security Checks | high |
| 331378 | AlmaLinux 10 : kernel (ALSA-2026:45114) | Nessus | Alma Linux Local Security Checks | high |
| 331377 | AlmaLinux 10 : pipewire (ALSA-2026:47083) | Nessus | Alma Linux Local Security Checks | high |
| 331376 | AlmaLinux 10 : fence-agents (ALSA-2026:48585) | Nessus | Alma Linux Local Security Checks | high |
| 331375 | Oracle PeopleSoft PeopleTools Multiple Vulnerabilities (CSPU Jun 2026) | Nessus | Misc. | critical |
| 331374 | Oracle PeopleSoft PeopleTools Installed (Windows) | Nessus | Windows | info |
| 331373 | ManageEngine Endpoint Central < 11.4.2528.34 / 11.5.x < 11.5.2600.13 Cleartext Transmission of Sensitive Information | Nessus | Windows | medium |
| 331372 | Oracle Linux 8 : kernel (ELSA-2026-45115) | Nessus | Oracle Linux Local Security Checks | high |
| 331371 | Oracle Linux 8 : gstreamer1-plugins-bad-free (ELSA-2026-47731) | Nessus | Oracle Linux Local Security Checks | high |
| 331370 | Oracle Linux 8 : libgcrypt (ELSA-2026-47117) | Nessus | Oracle Linux Local Security Checks | medium |
| 331369 | Oracle Linux 8 : sssd (ELSA-2026-46990) | Nessus | Oracle Linux Local Security Checks | high |
| 331368 | Oracle Linux 8 : python-pillow (ELSA-2026-48021) | Nessus | Oracle Linux Local Security Checks | high |
| 331367 | Oracle Linux 8 : fence-agents (ELSA-2026-47736) | Nessus | Oracle Linux Local Security Checks | high |
| 331366 | Oracle Linux 7 : gimp (ELSA-2026-26168) | Nessus | Oracle Linux Local Security Checks | high |
| 331365 | Oracle Linux 7 : PackageKit (ELSA-2026-22146) | Nessus | Oracle Linux Local Security Checks | high |
| 331364 | Oracle Linux 8 : grafana (ELSA-2026-46391) | Nessus | Oracle Linux Local Security Checks | medium |
| 331363 | Oracle Linux 8 : vim (ELSA-2026-48703) | Nessus | Oracle Linux Local Security Checks | high |
| 331362 | JetBrains PhpStorm Installed (Windows) | Nessus | Windows | info |
| 331361 | Cisco IOS XE Software for Catalyst 9000 Series Switches DHCP Snooping DoS (cisco-sa-bootp-WuBhNBxA) | Nessus | CISCO | high |
| 331360 | Adobe Bridge < 15.1.7 / 16.x < 16.0.6 Multiple Vulnerabilities (APSB26-89) | Nessus | MacOS X Local Security Checks | high |
| 331359 | Adobe Bridge < 15.1.7 / 16.x < 16.0.6 Multiple Vulnerabilities (APSB26-89) | Nessus | Windows | high |
| 331358 | Redis < 8.8.0 RCE via RESTORE Double Free (CVE-2026-66373) | Nessus | Misc. | high |
| 331357 | Fedora 43 : pack (2026-e6e0368149) | Nessus | Fedora Local Security Checks | high |
| 331356 | Cisco IOS XE Software IKEv2 Multiple Vulnerabilities (cisco-sa-asa-ftd-ios-dos-DOESHWHy) | Nessus | CISCO | high |
| 331355 | Cisco Firepower Threat Defense (FTD) Software IKEv2 Multiple Vulnerabilities (cisco-sa-asa-ftd-ios-dos-DOESHWHy) | Nessus | CISCO | high |
| 331354 | Cisco IOS Software IKEv2 Multiple Vulnerabilities (cisco-sa-asa-ftd-ios-dos-DOESHWHy) | Nessus | CISCO | high |
| 331353 | Cisco Adaptive Security Appliance (ASA) Software IKEv2 Multiple Vulnerabilities (cisco-sa-asa-ftd-ios-dos-DOESHWHy) | Nessus | CISCO | high |
| 331352 | JFrog Artifactory < 7.111.18 / 7.117.x < 7.117.25 / 7.125.x < 7.125.18 / 7.133.x < 7.133.27 / 7.146.x < 7.146.34 / 7.161.x < 7.161.15 Multiple Vulnerabilities | Nessus | Misc. | high |
| ID | Name | Product | Family | Severity |
|---|---|---|---|---|
| 505896 | B&R Automation X20EDS410 Multiple Releases of Same Resource or Handle (CVE-2026-43494) | Tenable OT Security | Tenable.ot | high |
| 505895 | B&R Automation X20EDS410 Out-of-bounds Write (CVE-2026-46300) | Tenable OT Security | Tenable.ot | high |
| 505893 | Siemens SIMATIC Observable Discrepancy (CVE-2023-37482) | Tenable OT Security | Tenable.ot | medium |
| 505892 | B&R Automation X20EDS410 Improper Privilege Management (CVE-2026-46333) | Tenable OT Security | Tenable.ot | high |
| 505891 | Siemens Interniche IP-Stack Improper Verification of Source of a Communication Channel (CVE-2025-40820) | Tenable OT Security | Tenable.ot | high |
| 505890 | B&R Automation X20EDS410 Write-what-where Condition (CVE-2026-43284) | Tenable OT Security | Tenable.ot | high |
| 505889 | Rockwell Automation ControlLogix, CompactLogix, GuardLogix, and 1756-EN4TR Improper Check for Certificate Revocation (CVE-2026-9636) | Tenable OT Security | Tenable.ot | high |
| 505887 | Rockwell Automation ControlLogix Ethernet Modules Insecure Default Initialization of Resource (CVE-2025-7353) | Tenable OT Security | Tenable.ot | critical |
| 505885 | Rockwell Automation Micro850/870 Dependency on Vulnerable Third-Party Component (CVE-2025-13823) | Tenable OT Security | Tenable.ot | high |
| 505883 | Veeder-Root TLS4B Command Injection (CVE-2025-58428) | Tenable OT Security | Tenable.ot | critical |
| 505882 | Veeder-Root TLS4B Integer Overflow or Wraparound (CVE-2025-55067) | Tenable OT Security | Tenable.ot | high |
| 505880 | Siemens SIMATIC S7-1500 CPU 1518 MFP Improper Input Validation (CVE-2025-68803) | Tenable OT Security | Tenable.ot | high |
| 505854 | Siemens SIMATIC S7-1500 CPU 1518 MFP Improper Handling of Missing Special Element (CVE-2025-68206) | Tenable OT Security | Tenable.ot | high |
| 505807 | Siemens SIMATIC S7-1500 CPU 1518 MFP Incorrect Privilege Assignment (CVE-2025-68764) | Tenable OT Security | Tenable.ot | high |
| 505792 | Siemens SIMATIC S7-1500 CPU 1518 MFP Expired Pointer Dereference (CVE-2025-40135) | Tenable OT Security | Tenable.ot | high |
| 505768 | Siemens SIMATIC S7-1500 CPU 1518 MFP Expired Pointer Dereference (CVE-2025-68265) | Tenable OT Security | Tenable.ot | high |
| 505759 | Siemens SIMATIC S7-1500 CPU 1518 MFP Expired Pointer Dereference (CVE-2025-39978) | Tenable OT Security | Tenable.ot | high |
| 505745 | Siemens SIMATIC S7-1500 CPU 1518 MFP Time-of-check Time-of-use (TOCTOU) Race Condition (CVE-2025-68261) | Tenable OT Security | Tenable.ot | high |
| 505735 | Siemens SIMATIC S7-1500 CPU 1518 MFP Integer Overflow or Wraparound (CVE-2025-68724) | Tenable OT Security | Tenable.ot | high |
| 505670 | Siemens SIMATIC S7-1500 CPU 1518 MFP Improper Input Validation (CVE-2025-68782) | Tenable OT Security | Tenable.ot | high |
| 505669 | Siemens SIMATIC S7-1500 CPU 1518 MFP Improper Input Validation (CVE-2025-68337) | Tenable OT Security | Tenable.ot | high |
| 505614 | Siemens SIMATIC S7-1500 CPU 1518 MFP Improper Input Validation (CVE-2025-40105) | Tenable OT Security | Tenable.ot | high |
| 505608 | Siemens SIMATIC S7-1500 CPU 1518 MFP NULL Pointer Dereference (CVE-2025-68818) | Tenable OT Security | Tenable.ot | high |
| 503064 | Siemens Industrial Products LLDP Buffer Overflow (CVE-2015-8011) | Tenable OT Security | Tenable.ot | critical |
| 501104 | Siemens Industrial Products LLDP Uncontrolled Resource Consumption (CVE-2020-27827) | Tenable OT Security | Tenable.ot | high |
| 445511 | SCA: security update for degit (GHSA-77c7-pq4r-6mcq) | Tenable Cloud Security | SCA Checks | high |
| 445511 | SCA: security update for degit (GHSA-77c7-pq4r-6mcq) | Tenable Self-Hosted Container Security | SCA Checks | high |
| 445508 | SCA: security update for dssrf (GHSA-cg4g-m8jx-vjv2) | Tenable Cloud Security | SCA Checks | high |
| 445508 | SCA: security update for dssrf (GHSA-cg4g-m8jx-vjv2) | Tenable Self-Hosted Container Security | SCA Checks | high |
| 445493 | SCA: security update for msgpack (GHSA-4mrv-5p47-p938) | Tenable Cloud Security | SCA Checks | low |
| 445493 | SCA: security update for msgpack (GHSA-4mrv-5p47-p938) | Tenable Self-Hosted Container Security | SCA Checks | low |
| 445492 | SCA: security update for activestorage (GHSA-xr9x-r78c-5hrm) | Tenable Cloud Security | SCA Checks | critical |
| 445492 | SCA: security update for activestorage (GHSA-xr9x-r78c-5hrm) | Tenable Self-Hosted Container Security | SCA Checks | critical |
| 445481 | Alpine: multiple nodejs packages: security update to 22.23.2-r0 | Tenable Cloud Security | Alpine Linux Local Security Checks | high |
| 445481 | Alpine: multiple nodejs packages: security update to 22.23.2-r0 | Tenable Self-Hosted Container Security | Alpine Linux Local Security Checks | high |
| 445480 | Alpine: multiple nodejs packages: security update to 24.18.1-r0 | Tenable Cloud Security | Alpine Linux Local Security Checks | high |
| 445480 | Alpine: multiple nodejs packages: security update to 24.18.1-r0 | Tenable Self-Hosted Container Security | Alpine Linux Local Security Checks | high |
| 445367 | SCA: security update for github.com/cloudreve/Cloudreve/v4 (GHSA-g9j2-8w95-3vwv) | Tenable Cloud Security | SCA Checks | medium |
| 445367 | SCA: security update for github.com/cloudreve/Cloudreve/v4 (GHSA-g9j2-8w95-3vwv) | Tenable Self-Hosted Container Security | SCA Checks | medium |
| 445252 | SCA: security update for github.com/getkin/kin-openapi (GHSA-r277-6w6q-xmqw) | Tenable Cloud Security | SCA Checks | high |
| 445252 | SCA: security update for github.com/getkin/kin-openapi (GHSA-r277-6w6q-xmqw) | Tenable Self-Hosted Container Security | SCA Checks | high |
| 445206 | SCA: security update for io.netty:netty-codec-haproxy (GHSA-q6cq-mhr2-jmr5) | Tenable Cloud Security | SCA Checks | high |
| 445206 | SCA: security update for io.netty:netty-codec-haproxy (GHSA-q6cq-mhr2-jmr5) | Tenable Self-Hosted Container Security | SCA Checks | high |
| 445203 | SCA: security update for io.netty:netty-codec-http2 (GHSA-c69g-56f8-xwqj) | Tenable Cloud Security | SCA Checks | medium |
| 445203 | SCA: security update for io.netty:netty-codec-http2 (GHSA-c69g-56f8-xwqj) | Tenable Self-Hosted Container Security | SCA Checks | medium |
| 445181 | SCA: security update for io.netty:netty-codec-xml (GHSA-4qhr-g3c6-fcfx) | Tenable Cloud Security | SCA Checks | high |
| 445181 | SCA: security update for io.netty:netty-codec-xml (GHSA-4qhr-g3c6-fcfx) | Tenable Self-Hosted Container Security | SCA Checks | high |
| 445056 | SCA: security update for code.gitea.io/gitea (GHSA-f75j-4cw6-rmx4) | Tenable Cloud Security | SCA Checks | critical |
| 445056 | SCA: security update for code.gitea.io/gitea (GHSA-f75j-4cw6-rmx4) | Tenable Self-Hosted Container Security | SCA Checks | critical |
| 444654 | Alpine: multiple openvpn packages: security update to 2.7.5-r0 | Tenable Cloud Security | Alpine Linux Local Security Checks | high |