Search/CVE-2024-9158
CVE — High

CVE-2024-9158

A stored cross site scripting vulnerability exists in Nessus Network Monitor where an authenticated, privileged local attacker could inject arbitrary code into the NNM UI via the local CLI.

CVSS v3.1
8.4 HIGH
EPSS
0.32%
probability of exploitation in 30 days
CISA KEV
Not listed
no confirmed exploitation reported
News coverage
0
sources referencing this CVE
EPSS Trend
Aug 16, 2026Sep 11, 2026
0.01pp
0.31% → 0.32% over 3 tracked changes
CVSS v3.1 Detail
Attack VectorNETWORK
Attack ComplexityLOW
Privileges RequiredHIGH
User InteractionREQUIRED
ScopeCHANGED
ConfidentialityHIGH
IntegrityHIGH
AvailabilityHIGH
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H
Connections
2 relationships
Timeline
disclosure → media coverage
Sep 30, 2024
Disclosure — published as a CVE record. · last revised by NVD Oct 7, 2024