Idk about Tenable specifically, but a lot of the major security vendors have their own pool of security researchers who very frequently contribute to CVE. Mostly from finding vulns in their own product, but a lot of those vulns are due to upstream libraries.