As information about new vulnerabilities is discovered and released into the general public domain, Tenable Research designs programs to detect them. These programs are named plugins and are written in the Nessus Attack Scripting Language (NASL). The plugins contain vulnerability information, a simplified set of remediation actions and the algorithm to test for the presence of the security issue. Tenable Research has published 317779 plugins, covering 116349 CVE IDs and 30933 Bugtraq IDs.
| ID | Name | Product | Family | Severity |
|---|---|---|---|---|
| 303479 | macOS 14.x < 14.8.5 Multiple Vulnerabilities (126796) | Nessus | MacOS X Local Security Checks | high |
| 303478 | macOS 15.x < 15.7.5 Multiple Vulnerabilities (126795) | Nessus | MacOS X Local Security Checks | high |
| 303477 | Linux Distros Unpatched Vulnerability : CVE-2026-4538 | Nessus | Misc. | high |
| 303476 | Linux Distros Unpatched Vulnerability : CVE-2026-4675 | Nessus | Misc. | high |
| 303475 | Linux Distros Unpatched Vulnerability : CVE-2026-4680 | Nessus | Misc. | high |
| 303474 | Mozilla Firefox < 149.0 | Nessus | Windows | high |
| 303473 | Mozilla Firefox ESR < 140.9 | Nessus | MacOS X Local Security Checks | high |
| 303472 | Mozilla Firefox ESR < 140.9 | Nessus | Windows | high |
| 303471 | Mozilla Firefox < 149.0 | Nessus | MacOS X Local Security Checks | high |
| 303470 | Mozilla Firefox ESR < 115.34 | Nessus | MacOS X Local Security Checks | high |
| 303469 | Mozilla Firefox ESR < 115.34 | Nessus | Windows | high |
| 303468 | Oracle Linux 10 / 9 : Unbreakable Enterprise kernel (ELSA-2026-50160) | Nessus | Oracle Linux Local Security Checks | critical |
| 303467 | Linux Distros Unpatched Vulnerability : CVE-2026-4678 | Nessus | Misc. | high |
| 303466 | Linux Distros Unpatched Vulnerability : CVE-2026-30836 | Nessus | Misc. | critical |
| 303465 | Linux Distros Unpatched Vulnerability : CVE-2026-4679 | Nessus | Misc. | high |
| 303464 | Linux Distros Unpatched Vulnerability : CVE-2026-4677 | Nessus | Misc. | high |
| 303463 | Linux Distros Unpatched Vulnerability : CVE-2026-33191 | Nessus | Misc. | high |
| 303462 | Linux Distros Unpatched Vulnerability : CVE-2026-33040 | Nessus | Misc. | high |
| 303461 | Linux Distros Unpatched Vulnerability : CVE-2026-33064 | Nessus | Misc. | high |
| 303460 | Linux Distros Unpatched Vulnerability : CVE-2026-33065 | Nessus | Misc. | medium |
| 303459 | Linux Distros Unpatched Vulnerability : CVE-2026-33192 | Nessus | Misc. | high |
| 303458 | Linux Distros Unpatched Vulnerability : CVE-2026-33186 | Nessus | Misc. | critical |
| 303457 | Linux Distros Unpatched Vulnerability : CVE-2026-30924 | Nessus | Misc. | critical |
| 303456 | Linux Distros Unpatched Vulnerability : CVE-2026-29111 | Nessus | Misc. | medium |
| 303455 | Linux Distros Unpatched Vulnerability : CVE-2026-4676 | Nessus | Misc. | high |
| 303454 | Linux Distros Unpatched Vulnerability : CVE-2026-4674 | Nessus | Misc. | high |
| 303453 | Linux Distros Unpatched Vulnerability : CVE-2026-4673 | Nessus | Misc. | high |
| 303452 | ConnectWise ScreenConnect < 26.1 Authentication Bypass | Nessus | Misc. | critical |
| 303451 | Unraid < 7.2.4 Multiple Vulnerabilities (ZDI-26-171 / ZDI-26-172) | Nessus | CGI abuses | high |
| 303450 | MantisBT 2.28.x < 2.28.2 Timeline Tag Name XSS (GHSA-73vx-49mv-v8w5) | Nessus | CGI abuses : XSS | medium |
| 303449 | MantisBT < 2.28.1 SOAP API Authentication Bypass (GHSA-phrq-pc6r-f6gh) | Nessus | CGI abuses | critical |
| 303448 | MantisBT 2.28.0 Tag Deletion XSS (GHSA-fh48-f69w-7vmp) | Nessus | CGI abuses : XSS | medium |
| 303447 | RHEL 8 : 389-ds:1.4 (RHSA-2026:5511) | Nessus | Red Hat Local Security Checks | high |
| 303446 | RHEL 9 : osbuild-composer (RHSA-2026:5533) | Nessus | Red Hat Local Security Checks | high |
| 303445 | RHEL 8 : redhat-ds:11 (RHSA-2026:5514) | Nessus | Red Hat Local Security Checks | high |
| 303444 | RHEL 8 : 389-ds:1.4 (RHSA-2026:5513) | Nessus | Red Hat Local Security Checks | high |
| 303443 | RHEL 8 : redhat-ds:11 (RHSA-2026:5512) | Nessus | Red Hat Local Security Checks | high |
| 303442 | RHEL 9 : thunderbird (RHSA-2026:3516) | Nessus | Red Hat Local Security Checks | critical |
| 303441 | Linux Distros Unpatched Vulnerability : CVE-2019-25586 | Nessus | Misc. | medium |
| 303440 | Linux Distros Unpatched Vulnerability : CVE-2019-25591 | Nessus | Misc. | medium |
| 303439 | Linux Distros Unpatched Vulnerability : CVE-2019-25585 | Nessus | Misc. | medium |
| 303438 | Alibaba Cloud Linux 3 : 0060: container-tools (ALINUX3-SA-2026:0060) | Nessus | Alibaba Cloud Linux Local Security Checks | critical |
| 303437 | Alibaba Cloud Linux 3 : 0059: postgresql:13 (ALINUX3-SA-2026:0059) | Nessus | Alibaba Cloud Linux Local Security Checks | high |
| 303436 | Alibaba Cloud Linux 3 : 0057: vim (ALINUX3-SA-2026:0057) | Nessus | Alibaba Cloud Linux Local Security Checks | medium |
| 303435 | Alibaba Cloud Linux 3 : 0055: libpng (ALINUX3-SA-2026:0055) | Nessus | Alibaba Cloud Linux Local Security Checks | high |
| 303434 | Alibaba Cloud Linux 3 : 0056: grub2 (ALINUX3-SA-2026:0056) | Nessus | Alibaba Cloud Linux Local Security Checks | high |
| 303433 | Alibaba Cloud Linux 3 : 0058: osbuild-composer (ALINUX3-SA-2026:0058) | Nessus | Alibaba Cloud Linux Local Security Checks | critical |
| 303432 | Alibaba Cloud Linux 3 : 0061: python3.11 (ALINUX3-SA-2026:0061) | Nessus | Alibaba Cloud Linux Local Security Checks | medium |
| 303431 | RockyLinux 8 : virt:rhel and virt-devel:rhel (RLSA-2026:5578) | Nessus | Rocky Linux Local Security Checks | high |
| 303430 | RockyLinux 8 : mysql:8.0 (RLSA-2026:5580) | Nessus | Rocky Linux Local Security Checks | medium |
| ID | Name | Product | Family | Severity |
|---|---|---|---|---|
| 66334 | Patch Report | Nessus | General | info |
| 53545 | Plone Detection | Nessus | CGI abuses | info |
| 505309 | Qnap QTS and QuTS hero Improper Neutralization of Special Elements used in an OS Command (CVE-2024-14026) | Tenable OT Security | Tenable.ot | medium |
| 505308 | Qnap QTS and QuTS hero Improper Neutralization of Special Elements used in a Command (CVE-2024-14026) | Tenable OT Security | Tenable.ot | medium |
| 505307 | Qnap QTS and QuTS hero Improper Neutralization of CRLF Sequences (CVE-2024-14026) | Tenable OT Security | Tenable.ot | medium |
| 505306 | Qnap QTS and QuTS hero Improper Neutralization of CRLF Sequences (CVE-2024-14026) | Tenable OT Security | Tenable.ot | medium |
| 505305 | Siemens APE1808 Inconsistent Interpretation of HTTP Requests (CVE-2025-55018) | Tenable OT Security | Tenable.ot | medium |
| 505304 | Siemens SIMATIC S7-1500 NULL Pointer Dereference (CVE-2025-38364) | Tenable OT Security | Tenable.ot | medium |
| 505303 | Siemens SIMATIC S7-1500 Improper Input Validation(CVE-2025-38457) | Tenable OT Security | Tenable.ot | medium |
| 505302 | Siemens APE1808 Improper Neutralization of Script in Attributes in a Web Page (CVE-2025-4615) | Tenable OT Security | Tenable.ot | high |
| 505301 | Siemens APE1808 Insertion of Sensitive Information into Sent Data (CVE-2024-46665) | Tenable OT Security | Tenable.ot | low |
| 505300 | Siemens APE1808 Heap-based Buffer Overflow (CVE-2023-27997) | Tenable OT Security | Tenable.ot | critical |
| 505299 | Siemens SIMATIC S7-1500 Use After Free (CVE-2025-38212) | Tenable OT Security | Tenable.ot | high |
| 505298 | Siemens APE1808 Improper Restriction of Communication Channel to Intended Endpoints (CVE-2024-26013) | Tenable OT Security | Tenable.ot | high |
| 505297 | Siemens SIMATIC S7-1500 Use After Free(CVE-2025-38236) | Tenable OT Security | Tenable.ot | high |
| 505296 | Siemens APE1808 Improper Check for Unusual or Exceptional Conditions (CVE-2026-0227) | Tenable OT Security | Tenable.ot | high |
| 505295 | Siemens SIMATIC S7-1500 Improper Input Validation (CVE-2025-38067) | Tenable OT Security | Tenable.ot | medium |
| 505294 | Siemens SIMATIC S7-1500 Improper Input Validation (CVE-2025-38071) | Tenable OT Security | Tenable.ot | medium |
| 505293 | Siemens APE1808 Integer Overflow or Wraparound (CVE-2024-46669) | Tenable OT Security | Tenable.ot | medium |
| 505292 | Siemens SIMATIC S7-1500 NULL Pointer Dereference(CVE-2025-38231) | Tenable OT Security | Tenable.ot | medium |
| 505291 | Siemens APE1808 Use of Externally-Controlled Format String (CVE-2025-64157) | Tenable OT Security | Tenable.ot | high |
| 505290 | Siemens SIMATIC S7-1500 NULL Pointer Dereference (CVE-2025-38100) | Tenable OT Security | Tenable.ot | medium |
| 505289 | Siemens APE1808 Improper Restriction of Communication Channel to Intended Endpoints (CVE-2024-50565) | Tenable OT Security | Tenable.ot | high |
| 505288 | Siemens SIMATIC S7-1500 NULL Pointer Dereference (CVE-2025-38198) | Tenable OT Security | Tenable.ot | high |
| 505287 | Siemens SIMATIC S7-1500 NULL Pointer Dereference(CVE-2025-38214) | Tenable OT Security | Tenable.ot | medium |
| 505286 | Siemens APE1808 Heap-based Buffer Overflow (CVE-2022-42475) | Tenable OT Security | Tenable.ot | critical |
| 505285 | Siemens SIMATIC S7-1500 Integer Overflow or Wraparound (CVE-2025-38222) | Tenable OT Security | Tenable.ot | medium |
| 505284 | Siemens SIMATIC S7-1500 Concurrent Execution using Shared Resource with Improper Synchronization (CVE-2025-38393) | Tenable OT Security | Tenable.ot | medium |
| 505283 | Siemens SIMATIC S7-1500 Improper Locking (CVE-2025-38058) | Tenable OT Security | Tenable.ot | medium |
| 505282 | Siemens SIMATIC S7-1500 Improper Input Validation (CVE-2025-38470) | Tenable OT Security | Tenable.ot | medium |
| 505281 | Siemens SIMATIC S7-1500 Improper Input Validation (CVE-2025-38280) | Tenable OT Security | Tenable.ot | high |
| 505280 | Siemens SIMATIC S7-1500 Missing Release of Memory after Effective Lifetime (CVE-2025-38124) | Tenable OT Security | Tenable.ot | medium |
| 505279 | Siemens APE1808 Weak Authentication (CVE-2024-50563) | Tenable OT Security | Tenable.ot | critical |
| 505278 | Siemens APE1808 Improper Check for Unusual or Exceptional Conditions(CVE-2026-0229) | Tenable OT Security | Tenable.ot | high |
| 505277 | Siemens APE1808 Exposure of Sensitive Information to an Unauthorized Actor (CVE-2025-68686) | Tenable OT Security | Tenable.ot | medium |
| 505276 | Siemens SIMATIC S7-1500 Improper Input Validation (CVE-2025-38400) | Tenable OT Security | Tenable.ot | medium |
| 505275 | Siemens SIMATIC S7-1500 Concurrent Execution using Shared Resource with Improper Synchronization (CVE-2025-38083) | Tenable OT Security | Tenable.ot | medium |
| 505274 | Siemens APE1808 Improper Restriction of Communication Channel to Intended Endpoints (CVE-2025-22251) | Tenable OT Security | Tenable.ot | medium |
| 505273 | Siemens SIMATIC S7-1500 Double Free (CVE-2025-38079) | Tenable OT Security | Tenable.ot | high |
| 505272 | Siemens APE1808 Insufficient Session Expiration (CVE-2025-25252) | Tenable OT Security | Tenable.ot | medium |
| 505271 | Siemens APE1808 Insertion of Sensitive Information into Sent Data (CVE-2024-47569) | Tenable OT Security | Tenable.ot | medium |
| 505270 | Siemens APE1808 Improper Limitation of a Pathname to a Restricted Directory (CVE-2024-48885) | Tenable OT Security | Tenable.ot | critical |
| 505269 | Siemens APE1808 Authentication Bypass Using an Alternate Path or Channel (CVE-2026-24858) | Tenable OT Security | Tenable.ot | critical |
| 505268 | Siemens SIMATIC S7-1500 NULL Pointer Dereference(CVE-2025-38215) | Tenable OT Security | Tenable.ot | medium |
| 505267 | Siemens SIMATIC S7-1500 NULL Pointer Dereference (CVE-2025-38167) | Tenable OT Security | Tenable.ot | medium |
| 505266 | Siemens APE1808 Improper Limitation of a Pathname to a Restricted Directory (CVE-2024-48884) | Tenable OT Security | Tenable.ot | critical |
| 505265 | Siemens APE1808 Improper Certificate Validation (CVE-2026-0228) | Tenable OT Security | Tenable.ot | medium |
| 505264 | Siemens SIMATIC S7-1500 Reachable Assertion (CVE-2025-38285) | Tenable OT Security | Tenable.ot | medium |
| 505263 | Siemens APE1808 Incorrect Provision of Specified Functionality (CVE-2025-58325) | Tenable OT Security | Tenable.ot | medium |
| 505262 | Siemens APE1808 Exposure of Sensitive System Information to an Unauthorized Control Sphere (CVE-2025-4229) | Tenable OT Security | Tenable.ot | medium |