As information about new vulnerabilities is discovered and released into the general public domain, Tenable Research designs programs to detect them. These programs are named plugins and are written in the Nessus Attack Scripting Language (NASL). The plugins contain vulnerability information, a simplified set of remediation actions and the algorithm to test for the presence of the security issue. Tenable Research has published 337359 plugins, covering 124146 CVE IDs and 30933 Bugtraq IDs.
| ID | Name | Product | Family | Severity |
|---|---|---|---|---|
| 505525 | Tridium Niagara Use of GET Request Method With Sensitive Query Strings (CVE-2025-3943) | Tenable OT Security | Tenable.ot | medium |
| 505524 | Tridium Niagara Incorrect Permission Assignment for Critical Resource (CVE-2025-3944) | Tenable OT Security | Tenable.ot | high |
| 505523 | Tridium Niagara Improper Encoding or Escaping of Output (CVE-2025-3942) | Tenable OT Security | Tenable.ot | medium |
| 505522 | Tridium Niagara Use of Incorrectly-Resolved Name or Reference (CVE-2025-3941) | Tenable OT Security | Tenable.ot | medium |
| 505521 | Tridium Niagara Use of a Broken or Risky Cryptographic Algorithm (CVE-2025-3938) | Tenable OT Security | Tenable.ot | medium |
| 505520 | Tridium Niagara Use of Password Hash With Insufficient Computational Effort (CVE-2025-3937) | Tenable OT Security | Tenable.ot | high |
| 505519 | Tridium Niagara Observable Discrepancy (CVE-2025-3939) | Tenable OT Security | Tenable.ot | medium |
| 505518 | Tridium Niagara Incorrect Permission Assignment for Critical Resource (CVE-2025-3936) | Tenable OT Security | Tenable.ot | medium |
| 505517 | Tridium Niagara Argument Injection (CVE-2025-3945) | Tenable OT Security | Tenable.ot | high |
| 505516 | Tridium Niagara Improper Use of Validation Framework (CVE-2025-3940) | Tenable OT Security | Tenable.ot | medium |
| 322750 | GitLab 19.1 < 19.1.1 (CVE-2026-12053) | Nessus | CGI abuses | high |
| 322749 | GitLab 16.4 < 18.11.6 / 19.0 < 19.0.3 / 19.1 < 19.1.1 (CVE-2026-10086) | Nessus | CGI abuses | high |
| 322748 | GitLab 18.6 < 18.11.6 / 19.0 < 19.0.3 / 19.1 < 19.1.1 (CVE-2026-5309) | Nessus | CGI abuses | medium |
| 322747 | GitLab 17.9 < 18.11.6 / 19.0 < 19.0.3 / 19.1 < 19.1.1 (CVE-2026-0934) | Nessus | CGI abuses | low |
| 322746 | GitLab 14.8 < 18.11.6 / 19.0 < 19.0.3 / 19.1 < 19.1.1 (CVE-2026-1606) | Nessus | CGI abuses | medium |
| 322745 | GitLab 8.3 < 18.11.6 / 19.0 < 19.0.3 / 19.1 < 19.1.1 (CVE-2026-12635) | Nessus | CGI abuses | critical |
| 322744 | GitLab 13.6 < 18.11.6 / 19.0 < 19.0.3 / 19.1 < 19.1.1 (CVE-2026-5796) | Nessus | CGI abuses | medium |
| 322743 | GitLab 9.3 < 18.11.6 / 19.0 < 19.0.3 / 19.1 < 19.1.1 (CVE-2026-8330) | Nessus | CGI abuses | medium |
| 322742 | GitLab 17.5 < 18.11.6 / 19.0 < 19.0.3 / 19.1 < 19.1.1 (CVE-2026-2238) | Nessus | CGI abuses | medium |
| 322741 | GitLab 18.6 < 18.11.6 / 19.0 < 19.0.3 / 19.1 < 19.1.1 (CVE-2026-3176) | Nessus | CGI abuses | low |
| 322740 | GitLab 17.11 < 18.11.6 / 19.0 < 19.0.3 / 19.1 < 19.1.1 (CVE-2026-5952) | Nessus | CGI abuses | medium |
| 322739 | GitLab 13.11 < 18.11.6 / 19.0 < 19.0.3 / 19.1 < 19.1.1 (CVE-2026-11379) | Nessus | CGI abuses | medium |
| 322738 | GitLab 18.10 < 18.11.6 / 19.0 < 19.0.3 / 19.1 < 19.1.1 (CVE-2026-10712) | Nessus | CGI abuses | high |
| 322737 | Oracle Linux 8 : mysql:8.0 (ELSA-2026-25919) | Nessus | Oracle Linux Local Security Checks | medium |
| 322736 | Oracle Linux 9 : fence-agents (ELSA-2026-26206) | Nessus | Oracle Linux Local Security Checks | high |
| 322735 | Oracle Linux 9 : post (ELSA-2026-26205) | Nessus | Oracle Linux Local Security Checks | high |
| 322734 | Oracle Linux 9 : webkit2gtk3 (ELSA-2026-25927) | Nessus | Oracle Linux Local Security Checks | high |
| 322733 | Oracle Linux 8 : evince (ELSA-2026-28998) | Nessus | Oracle Linux Local Security Checks | high |
| 322732 | RockyLinux 8 : libreoffice (RLSA-2026:28922) | Nessus | Rocky Linux Local Security Checks | medium |
| 322731 | RockyLinux 9 : python3.14 (RLSA-2026:28247) | Nessus | Rocky Linux Local Security Checks | high |
| 322730 | RockyLinux 9 : libxml2 (RLSA-2026:28254) | Nessus | Rocky Linux Local Security Checks | high |
| 322729 | RockyLinux 8 : kernel-rt (RLSA-2026:27812) | Nessus | Rocky Linux Local Security Checks | high |
| 322728 | RockyLinux 8 : firefox (RLSA-2026:27717) | Nessus | Rocky Linux Local Security Checks | critical |
| 322727 | RockyLinux 8 : evince (RLSA-2026:28998) | Nessus | Rocky Linux Local Security Checks | high |
| 322726 | RockyLinux 8 : vim (RLSA-2026:28553) | Nessus | Rocky Linux Local Security Checks | medium |
| 322725 | RockyLinux 8 : kernel (RLSA-2026:27811) | Nessus | Rocky Linux Local Security Checks | high |
| 322724 | RockyLinux 8 : tigervnc (RLSA-2026:28923) | Nessus | Rocky Linux Local Security Checks | high |
| 322723 | ByteDance Trae Extensions Installed (Linux) | Nessus | Artificial Intelligence | info |
| 322722 | Linux Distros Unpatched Vulnerability : CVE-2026-53082 | Nessus | Misc. | critical |
| 322721 | Linux Distros Unpatched Vulnerability : CVE-2026-52955 | Nessus | Misc. | critical |
| 322720 | Linux Distros Unpatched Vulnerability : CVE-2026-53102 | Nessus | Misc. | critical |
| 322719 | Linux Distros Unpatched Vulnerability : CVE-2026-53041 | Nessus | Misc. | critical |
| 322718 | Linux Distros Unpatched Vulnerability : CVE-2026-53000 | Nessus | Misc. | critical |
| 322717 | Linux Distros Unpatched Vulnerability : CVE-2026-53065 | Nessus | Misc. | critical |
| 322716 | Linux Distros Unpatched Vulnerability : CVE-2026-56368 | Nessus | Misc. | medium |
| 322715 | Linux Distros Unpatched Vulnerability : CVE-2026-52999 | Nessus | Misc. | critical |
| 322714 | Linux Distros Unpatched Vulnerability : CVE-2026-52991 | Nessus | Misc. | critical |
| 322713 | Linux Distros Unpatched Vulnerability : CVE-2026-53018 | Nessus | Misc. | critical |
| 322712 | Linux Distros Unpatched Vulnerability : CVE-2026-53101 | Nessus | Misc. | critical |
| 322711 | Linux Distros Unpatched Vulnerability : CVE-2026-53109 | Nessus | Misc. | critical |
| ID | Name | Product | Family | Severity |
|---|---|---|---|---|
| 505515 | Schneider Electric Modicon M241, M251, and M262 Improper Resource Shutdown or Release (CVE-2025-13901) | Tenable OT Security | Tenable.ot | medium |
| 505514 | Automated Logic WebCTRL Cross-site Scripting (CVE-2024-5540) | Tenable OT Security | Tenable.ot | medium |
| 505513 | Vertiv Liebert SiteScan Cross-site Scripting (CVE-2024-5540) | Tenable OT Security | Tenable.ot | medium |
| 505512 | Automated Logic WebCTRL Storing Passwords in a Recoverable Format (CVE-2025-14295) | Tenable OT Security | Tenable.ot | high |
| 505511 | Carrier Corporation i-VU Improper Validation of Array Index (CVE-2025-0657) | Tenable OT Security | Tenable.ot | high |
| 505510 | Automated Logic WebCTRL Improper Validation of Array Index (CVE-2025-0657) | Tenable OT Security | Tenable.ot | high |
| 505509 | Vertiv Liebert SiteScan Improper Validation of Array Index (CVE-2025-0657) | Tenable OT Security | Tenable.ot | high |
| 505508 | Carrier Corporation i-VU Incorrect Authorization (CVE-2024-5539) | Tenable OT Security | Tenable.ot | critical |
| 505507 | Vertiv Liebert SiteScan Incorrect Authorization (CVE-2024-5539) | Tenable OT Security | Tenable.ot | critical |
| 505506 | Carrier Corporation i-VU Cross-site Scripting (CVE-2024-5540) | Tenable OT Security | Tenable.ot | medium |
| 505505 | Automated Logic WebCTRL Premium Server Improper Neutralization of Input During Web Page Generation (CVE-2024-8528) | Tenable OT Security | Tenable.ot | medium |
| 505504 | Automated Logic WebCTRL Premium Server Improper Neutralization of Input During Web Page Generation (CVE-2024-8528) | Tenable OT Security | Tenable.ot | medium |
| 505503 | Carrier Corporation i-VU Storing Passwords in a Recoverable Format (CVE-2025-14295) | Tenable OT Security | Tenable.ot | high |
| 505502 | Automated Logic WebCTRL Premium Server Improper Neutralization of Input During Web Page Generation (CVE-2024-8528) | Tenable OT Security | Tenable.ot | medium |
| 505501 | Automated Logic WebCTRL Incorrect Authorization (CVE-2024-5539) | Tenable OT Security | Tenable.ot | critical |
| 505500 | Automated Logic WebCTRL Premium Server URL Redirection to Untrusted Site (CVE-2024-8527) | Tenable OT Security | Tenable.ot | high |
| 505499 | Automated Logic WebCTRL Premium Server URL Redirection to Untrusted Site (CVE-2024-8527) | Tenable OT Security | Tenable.ot | high |
| 505498 | Automated Logic WebCTRL Premium Server URL Redirection to Untrusted Site (CVE-2024-8527) | Tenable OT Security | Tenable.ot | high |
| 322560 | Oracle Linux 9 : nginx:1.24 (ELSA-2026-19371) | Nessus | Oracle Linux Local Security Checks | critical |
| 322540 | RockyLinux 8 : postgresql:12 (RLSA-2026:28999) | Nessus | Rocky Linux Local Security Checks | high |
| 322536 | Linux Distros Unpatched Vulnerability : CVE-2026-52923 | Nessus | Misc. | medium |
| 322533 | Linux Distros Unpatched Vulnerability : CVE-2026-52927 | Nessus | Misc. | high |
| 322527 | Linux Distros Unpatched Vulnerability : CVE-2026-52930 | Nessus | Misc. | high |
| 322524 | Linux Distros Unpatched Vulnerability : CVE-2026-52929 | Nessus | Misc. | medium |
| 322520 | Linux Distros Unpatched Vulnerability : CVE-2026-52912 | Nessus | Misc. | high |
| 322515 | Linux Distros Unpatched Vulnerability : CVE-2026-52924 | Nessus | Misc. | medium |
| 322511 | Linux Distros Unpatched Vulnerability : CVE-2026-52925 | Nessus | Misc. | high |
| 322507 | Linux Distros Unpatched Vulnerability : CVE-2026-52928 | Nessus | Misc. | medium |
| 322483 | Tenable Identity Exposure < 3.93.5 Multiple Vulnerabilities (TNS-2026-16) | Nessus | Misc. | high |
| 322479 | Ubuntu 22.04 LTS / 24.04 LTS : libxml2 vulnerability (USN-8456-1) | Nessus | Ubuntu Local Security Checks | high |
| 322472 | Linux Distros Unpatched Vulnerability : CVE-2025-71382 | Nessus | Misc. | medium |
| 322466 | Linux Distros Unpatched Vulnerability : CVE-2026-9595 | Nessus | Misc. | medium |
| 322456 | Linux Distros Unpatched Vulnerability : CVE-2025-55639 | Nessus | Misc. | medium |
| 322421 | pgAdmin < 9.16 HTML Injection (CVE-2026-12047) | Nessus | Databases | medium |
| 322420 | pgAdmin < 9.16 Multiple SQL Injections | Nessus | Databases | high |
| 322419 | pgAdmin < 9.16 Stored XSS / Open Redirect | Nessus | Databases | critical |
| 322418 | pgAdmin 9.x < 9.16 Read-Only Transaction Bypass (CVE-2026-12045) | Nessus | Databases | critical |
| 322417 | pgAdmin < 9.16 Missing Authentication (CVE-2026-12046) | Nessus | Databases | critical |
| 322415 | JetBrains GoLand < 2026.1.3 RCE | Nessus | Misc. | high |
| 322412 | Adobe ColdFusion < 2023.x < 2023u20 / 2025.x < 2025u9 Multiple Vulnerabilities (APSB26-64) | Nessus | Windows | critical |
| 322411 | Zimbra Collaboration Server < 8.8.15 Patch 7 Server-Side Request Forgery Vulnerability | Nessus | CGI abuses | critical |
| 322410 | Node.js Module Undici 8.1.x < 8.5.0 DoS (CVE-2026-9675) | Nessus | Misc. | high |
| 322409 | Node.js Module Undici 6.17.x < 6.27.0 / 7.x < 7.28.0 / 8.x < 8.5.0 DoS (CVE-2026-12151) | Nessus | Misc. | high |
| 322408 | Containerd 2.1.x < 2.1.9 / 2.2.x < 2.2.5 / 2.3.x < 2.3.2 Multiple Vulnerabilities | Nessus | Misc. | critical |
| 322407 | Containerd 1.7.x < 1.7.33 / 2.0.x < 2.0.10 / 2.1.x < 2.1.9 / 2.2.x < 2.2.5 / 2.3.x < 2.3.2 Multiple Vulnerabilities | Nessus | Misc. | critical |
| 322406 | Debian dla-4644 : libmatio-dev - security update | Nessus | Debian Local Security Checks | medium |
| 322403 | RHEL 9 : libreoffice (RHSA-2026:28290) | Nessus | Red Hat Local Security Checks | medium |
| 322402 | RHEL 8 : libreoffice (RHSA-2026:28922) | Nessus | Red Hat Local Security Checks | medium |
| 322376 | RockyLinux 8 : nginx:1.24 (RLSA-2026:28921) | Nessus | Rocky Linux Local Security Checks | critical |
| 322363 | Photon OS 4.0: Rsync PHSA-2026-4.0-1038 | Nessus | PhotonOS Local Security Checks | high |