As information about new vulnerabilities is discovered and released into the general public domain, Tenable Research designs programs to detect them. These programs are named plugins and are written in the Nessus Attack Scripting Language (NASL). The plugins contain vulnerability information, a simplified set of remediation actions and the algorithm to test for the presence of the security issue. Tenable Research has published 424418 plugins, covering 144054 CVE IDs and 32952 Bugtraq IDs.
| ID | Name | Product | Family | Severity |
|---|---|---|---|---|
| 445519 | SCA: security update for @anephenix/hub (GHSA-g5vv-q72c-7j78) | Tenable Cloud Security | SCA Checks | high |
| 445519 | SCA: security update for @anephenix/hub (GHSA-g5vv-q72c-7j78) | Tenable Self-Hosted Container Security | SCA Checks | high |
| 445518 | SCA: security update for oxid-esales/oxideshop-ce, oxid-esales/oxideshop-metapackage-ce, oxid-esales/smarty-component (GHSA-qqcr-9jfc-35c4) | Tenable Cloud Security | SCA Checks | medium |
| 445518 | SCA: security update for oxid-esales/oxideshop-ce, oxid-esales/oxideshop-metapackage-ce, oxid-esales/smarty-component (GHSA-qqcr-9jfc-35c4) | Tenable Self-Hosted Container Security | SCA Checks | medium |
| 445517 | SCA: security update for @aws-amplify/codegen-ui-react (GHSA-hf3j-86p7-mfw8) | Tenable Cloud Security | SCA Checks | critical |
| 445517 | SCA: security update for @aws-amplify/codegen-ui-react (GHSA-hf3j-86p7-mfw8) | Tenable Self-Hosted Container Security | SCA Checks | critical |
| 331337 | JetBrains PyCharm < 2026.1.4 / 2026.2 Arbitrary Code Execution | Nessus | Misc. | high |
| 331336 | Linux Distros Unpatched Vulnerability : CVE-2026-9672 | Nessus | Misc. | critical |
| 331335 | Progress MOVEit Transfer < 2025.1.5 / 2026.0.x < 2026.0.3 Multiple Vulnerabilities (July 2026) | Nessus | Windows | high |
| 331334 | Atlassian Confluence 9.0.1 / 9.1.x / 9.2.x < 9.2.17 / 9.3.1 / 9.4.x / 9.5.1 / 10.0.2 / 10.1.x / 10.2.x < 10.2.7 (CONFSERVER-104334) | Nessus | CGI abuses | high |
| 331333 | HCL Traveler for Microsoft Outlook < 3.0.16 DLL Hijacking (CVE-2026-21770) | Nessus | Windows | medium |
| 331332 | MiracleLinux 9 : python3.14-3.14.5-1.el9_8 (AXSA:2026-1397:02) | Nessus | Miracle Linux Local Security Checks | high |
| 331331 | MiracleLinux 8 : compat-libtiff3-3.9.4-16.el8_10 (AXSA:2026-1400:02) | Nessus | Miracle Linux Local Security Checks | high |
| 331330 | MiracleLinux 9 : firefox-140.12.0-1.el9_8.ML.1 (AXSA:2026-1396:18) | Nessus | Miracle Linux Local Security Checks | high |
| 331329 | MiracleLinux 8 : libtiff-4.0.9-38.el8_10 (AXSA:2026-1394:08) | Nessus | Miracle Linux Local Security Checks | high |
| 331328 | MiracleLinux 9 : skopeo-1.22.2-6.el9_8 (AXSA:2026-1395:03) | Nessus | Miracle Linux Local Security Checks | high |
| 331327 | MiracleLinux 9 : libtasn1-4.16.0-10.el9_8 (AXSA:2026-1398:03) | Nessus | Miracle Linux Local Security Checks | high |
| 331326 | Oracle Linux 9 : vim (ELSA-2026-47982) | Nessus | Oracle Linux Local Security Checks | high |
| 331325 | Oracle Linux 9 : firefox (ELSA-2026-47104) | Nessus | Oracle Linux Local Security Checks | critical |
| 331324 | Oracle Linux 9 : kernel (ELSA-2026-45192) | Nessus | Oracle Linux Local Security Checks | high |
| 331323 | Slackware Linux 15.0 / current php82 Multiple Vulnerabilities (SSA:2026-211-01) | Nessus | Slackware Local Security Checks | critical |
| 331322 | Debian dla-4707 : gsasl - security update | Nessus | Debian Local Security Checks | medium |
| 331321 | FreeBSD : chromium -- security fixes (20683bca-e344-4348-a033-db862123615d) | Nessus | FreeBSD Local Security Checks | critical |
| 331320 | FreeBSD : NetBird -- Local Privilege Escalation via Unauthenticated IPC Socket (ef71114e-8c1c-11f1-a221-3c7c3fba4204) | Nessus | FreeBSD Local Security Checks | high |
| 331319 | FreeBSD : Weechat -- Multiple vulnerabilities (0d5b4884-8c2b-11f1-8144-8447094a420f) | Nessus | FreeBSD Local Security Checks | high |
| 331318 | FreeBSD : Gitlab -- vulnerabilities (661d3db5-8bd9-11f1-9c40-2cf05da270f3) | Nessus | FreeBSD Local Security Checks | high |
| 505896 | B&R Automation X20EDS410 Multiple Releases of Same Resource or Handle (CVE-2026-43494) | Tenable OT Security | Tenable.ot | high |
| 505895 | B&R Automation X20EDS410 Out-of-bounds Write (CVE-2026-46300) | Tenable OT Security | Tenable.ot | high |
| 505894 | B&R Automation X20EDS410 Incorrect Resource Transfer Between Spheres (CVE-2026-31431) | Tenable OT Security | Tenable.ot | high |
| 505893 | Siemens SIMATIC Observable Discrepancy (CVE-2023-37482) | Tenable OT Security | Tenable.ot | medium |
| 505892 | B&R Automation X20EDS410 Improper Privilege Management (CVE-2026-46333) | Tenable OT Security | Tenable.ot | high |
| 505891 | Siemens Interniche IP-Stack Improper Verification of Source of a Communication Channel (CVE-2025-40820) | Tenable OT Security | Tenable.ot | high |
| 505890 | B&R Automation X20EDS410 Write-what-where Condition (CVE-2026-43284) | Tenable OT Security | Tenable.ot | high |
| 445515 | SCA: security update for org.springframework:spring-webflux (GHSA-83f7-v6px-pp3h) | Tenable Cloud Security | SCA Checks | medium |
| 445515 | SCA: security update for org.springframework:spring-webflux (GHSA-83f7-v6px-pp3h) | Tenable Self-Hosted Container Security | SCA Checks | medium |
| 445514 | SCA: security update for org.springframework:spring-webmvc (GHSA-3chg-m5w7-qfv5) | Tenable Cloud Security | SCA Checks | medium |
| 445514 | SCA: security update for org.springframework:spring-webmvc (GHSA-3chg-m5w7-qfv5) | Tenable Self-Hosted Container Security | SCA Checks | medium |
| 445513 | SCA: security update for org.springframework:spring-webflux, org.springframework:spring-webmvc (GHSA-h3qp-gqrc-q736) | Tenable Cloud Security | SCA Checks | medium |
| 445513 | SCA: security update for org.springframework:spring-webflux, org.springframework:spring-webmvc (GHSA-h3qp-gqrc-q736) | Tenable Self-Hosted Container Security | SCA Checks | medium |
| 445512 | SCA: security update for org.springframework:spring-expression (GHSA-9f52-rjqv-25qv) | Tenable Cloud Security | SCA Checks | medium |
| 445512 | SCA: security update for org.springframework:spring-expression (GHSA-9f52-rjqv-25qv) | Tenable Self-Hosted Container Security | SCA Checks | medium |
| 445511 | SCA: security update for degit (GHSA-77c7-pq4r-6mcq) | Tenable Cloud Security | SCA Checks | high |
| 445511 | SCA: security update for degit (GHSA-77c7-pq4r-6mcq) | Tenable Self-Hosted Container Security | SCA Checks | high |
| 445510 | SCA: security update for github.com/OliveTin/OliveTin (GHSA-xc5w-4v5w-7x65) | Tenable Cloud Security | SCA Checks | medium |
| 445510 | SCA: security update for github.com/OliveTin/OliveTin (GHSA-xc5w-4v5w-7x65) | Tenable Self-Hosted Container Security | SCA Checks | medium |
| 445509 | SCA: security update for flyto-core (GHSA-c9hr-64h3-gxpc) | Tenable Cloud Security | SCA Checks | high |
| 445509 | SCA: security update for flyto-core (GHSA-c9hr-64h3-gxpc) | Tenable Self-Hosted Container Security | SCA Checks | high |
| 445508 | SCA: security update for dssrf (GHSA-cg4g-m8jx-vjv2) | Tenable Cloud Security | SCA Checks | high |
| 445508 | SCA: security update for dssrf (GHSA-cg4g-m8jx-vjv2) | Tenable Self-Hosted Container Security | SCA Checks | high |
| 445507 | SCA: security update for org.springframework:spring-webflux, org.springframework:spring-webmvc (GHSA-mq64-j8f9-9gcj) | Tenable Cloud Security | SCA Checks | medium |
| ID | Name | Product | Family | Severity |
|---|---|---|---|---|
| 505896 | B&R Automation X20EDS410 Multiple Releases of Same Resource or Handle (CVE-2026-43494) | Tenable OT Security | Tenable.ot | high |
| 505895 | B&R Automation X20EDS410 Out-of-bounds Write (CVE-2026-46300) | Tenable OT Security | Tenable.ot | high |
| 505893 | Siemens SIMATIC Observable Discrepancy (CVE-2023-37482) | Tenable OT Security | Tenable.ot | medium |
| 505892 | B&R Automation X20EDS410 Improper Privilege Management (CVE-2026-46333) | Tenable OT Security | Tenable.ot | high |
| 505891 | Siemens Interniche IP-Stack Improper Verification of Source of a Communication Channel (CVE-2025-40820) | Tenable OT Security | Tenable.ot | high |
| 505890 | B&R Automation X20EDS410 Write-what-where Condition (CVE-2026-43284) | Tenable OT Security | Tenable.ot | high |
| 505880 | Siemens SIMATIC S7-1500 CPU 1518 MFP Improper Input Validation (CVE-2025-68803) | Tenable OT Security | Tenable.ot | high |
| 505854 | Siemens SIMATIC S7-1500 CPU 1518 MFP Improper Handling of Missing Special Element (CVE-2025-68206) | Tenable OT Security | Tenable.ot | high |
| 505807 | Siemens SIMATIC S7-1500 CPU 1518 MFP Incorrect Privilege Assignment (CVE-2025-68764) | Tenable OT Security | Tenable.ot | high |
| 505792 | Siemens SIMATIC S7-1500 CPU 1518 MFP Expired Pointer Dereference (CVE-2025-40135) | Tenable OT Security | Tenable.ot | high |
| 505768 | Siemens SIMATIC S7-1500 CPU 1518 MFP Expired Pointer Dereference (CVE-2025-68265) | Tenable OT Security | Tenable.ot | high |
| 505759 | Siemens SIMATIC S7-1500 CPU 1518 MFP Expired Pointer Dereference (CVE-2025-39978) | Tenable OT Security | Tenable.ot | high |
| 505745 | Siemens SIMATIC S7-1500 CPU 1518 MFP Time-of-check Time-of-use (TOCTOU) Race Condition (CVE-2025-68261) | Tenable OT Security | Tenable.ot | high |
| 505735 | Siemens SIMATIC S7-1500 CPU 1518 MFP Integer Overflow or Wraparound (CVE-2025-68724) | Tenable OT Security | Tenable.ot | high |
| 505670 | Siemens SIMATIC S7-1500 CPU 1518 MFP Improper Input Validation (CVE-2025-68782) | Tenable OT Security | Tenable.ot | high |
| 505669 | Siemens SIMATIC S7-1500 CPU 1518 MFP Improper Input Validation (CVE-2025-68337) | Tenable OT Security | Tenable.ot | high |
| 505614 | Siemens SIMATIC S7-1500 CPU 1518 MFP Improper Input Validation (CVE-2025-40105) | Tenable OT Security | Tenable.ot | high |
| 505608 | Siemens SIMATIC S7-1500 CPU 1518 MFP NULL Pointer Dereference (CVE-2025-68818) | Tenable OT Security | Tenable.ot | high |
| 445508 | SCA: security update for dssrf (GHSA-cg4g-m8jx-vjv2) | Tenable Cloud Security | SCA Checks | high |
| 445508 | SCA: security update for dssrf (GHSA-cg4g-m8jx-vjv2) | Tenable Self-Hosted Container Security | SCA Checks | high |
| 445252 | SCA: security update for github.com/getkin/kin-openapi (GHSA-r277-6w6q-xmqw) | Tenable Cloud Security | SCA Checks | high |
| 445252 | SCA: security update for github.com/getkin/kin-openapi (GHSA-r277-6w6q-xmqw) | Tenable Self-Hosted Container Security | SCA Checks | high |
| 443575 | SCA: security update for nokogiri (GHSA-wjv4-x9w8-wm3h) | Tenable Cloud Security | SCA Checks | high |
| 443575 | SCA: security update for nokogiri (GHSA-wjv4-x9w8-wm3h) | Tenable Self-Hosted Container Security | SCA Checks | high |
| 409343 | SCA: security update for d3-color (GHSA-36jr-mh4h-2g58) | Tenable Cloud Security | SCA Checks | high |
| 409343 | SCA: security update for d3-color (GHSA-36jr-mh4h-2g58) | Tenable Self-Hosted Container Security | SCA Checks | high |
| 331306 | Linux Distros Unpatched Vulnerability : CVE-2026-68563 | Nessus | Misc. | medium |
| 331304 | Linux Distros Unpatched Vulnerability : CVE-2026-68562 | Nessus | Misc. | medium |
| 331273 | Linux Distros Unpatched Vulnerability : CVE-2026-17817 | Nessus | Misc. | medium |
| 331271 | Linux Distros Unpatched Vulnerability : CVE-2026-17866 | Nessus | Misc. | medium |
| 331267 | Linux Distros Unpatched Vulnerability : CVE-2026-17906 | Nessus | Misc. | medium |
| 331260 | Linux Distros Unpatched Vulnerability : CVE-2026-17910 | Nessus | Misc. | medium |
| 331258 | Linux Distros Unpatched Vulnerability : CVE-2026-17893 | Nessus | Misc. | medium |
| 331254 | Linux Distros Unpatched Vulnerability : CVE-2026-17870 | Nessus | Misc. | medium |
| 331244 | Linux Distros Unpatched Vulnerability : CVE-2026-17908 | Nessus | Misc. | medium |
| 331243 | Linux Distros Unpatched Vulnerability : CVE-2026-17897 | Nessus | Misc. | medium |
| 331238 | Linux Distros Unpatched Vulnerability : CVE-2026-17741 | Nessus | Misc. | high |
| 331237 | Linux Distros Unpatched Vulnerability : CVE-2026-17980 | Nessus | Misc. | low |
| 331227 | Linux Distros Unpatched Vulnerability : CVE-2026-17997 | Nessus | Misc. | low |
| 331221 | Linux Distros Unpatched Vulnerability : CVE-2026-17734 | Nessus | Misc. | medium |
| 331217 | MongoDB 8.3.x < 8.3.7 Aggregation Framework Memory Exhaustion (SERVER-128584) | Nessus | Databases | high |
| 331216 | MongoDB 8.0.x < 8.0.28 / 8.3.x < 8.3.7 Multiple Vulnerabilities (SERVER-124355) | Nessus | Databases | high |
| 331215 | MongoDB 7.0.x < 7.0.39 / 8.0.x < 8.0.28 / 8.2.x < 8.2.12 / 8.3.x < 8.3.7 Multiple Vulnerabilities (SERVER-128433) | Nessus | Databases | critical |
| 331214 | MongoDB 8.2.x < 8.2.12 / 8.3.x < 8.3.7 Multiple Vulnerabilities (SERVER-128316) | Nessus | Databases | high |
| 331213 | MongoDB 8.0.x < 8.0.28 Aggregation Command Invariant Assertion Failure (SERVER-128512) | Nessus | Databases | medium |
| 331212 | MongoDB 8.0.x < 8.0.28 / 8.2.x < 8.2.12 / 8.3.x < 8.3.7 Multiple Vulnerabilities (SERVER-125872) | Nessus | Databases | high |
| 331211 | MongoDB 7.0.x < 7.0.39 / 8.0.x < 8.0.28 / 8.3.x < 8.3.7 Improper Access Control (SERVER-127689) | Nessus | Databases | medium |
| 331204 | Linux Distros Unpatched Vulnerability : CVE-2026-17953 | Nessus | Misc. | medium |
| 331202 | Linux Distros Unpatched Vulnerability : CVE-2026-17833 | Nessus | Misc. | medium |
| 331196 | Linux Distros Unpatched Vulnerability : CVE-2026-17843 | Nessus | Misc. | medium |