CVE-2025-36625: Tenable Nessus
Medium severity, CVSS 4.3. EPSS: 0.3% chance of exploitation in the next 30 days.
In Nessus versions prior to 10.8.4, a non-authenticated attacker could alter Nessus logging entries by manipulating http requests to the application.
Affected products
- Tenable Nessus: before 10.8.4 (fixed in 10.8.4)
Published 2025-04-18. Last modified 2026-06-17.