Vulnerability index

Browse CVEs

77 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Insightconnect Tcpdump HIGH 8.8
CVE-2026-8658

OS Command Injection vulnerability in Rapid7 InsightConnect Tcpdump Plugin on Linux allows authenticated attackers to execute arbitrary OS commands v…

Fix: 2.0.0+
Fix from $1,950 2026-06-25
Insightconnect Ping CRITICAL 9.8
CVE-2026-8660

OS Command Injection vulnerability in the ping action of Rapid7 InsightConnect Ping Plugin on Linux allows remote attackers to execute arbitrary OS c…

Fix: 1.0.4+
Fix from $2,300 2026-06-25
Insightconnect Translate CRITICAL 9.8
CVE-2026-8665

OS Command Injection vulnerability in the TR action of Rapid7 InsightConnect Translate Plugin on Linux allows remote attackers to execute arbitrary O…

Fix: 2.0.3+
Fix from $2,300 2026-06-25
Insightconnect Traceroute CRITICAL 9.8
CVE-2026-8666

OS Command Injection vulnerability in the traceroute action of Rapid7 InsightConnect Traceroute Plugin on Linux allows remote attackers to execute ar…

Fix: 1.0.3+
Fix from $2,300 2026-06-25
Insightconnect Finger HIGH 8.8
CVE-2026-8664

OS Command Injection vulnerability in Rapid7 InsightConnect Finger Plugin on Linux allows authenticated attackers to execute arbitrary OS commands vi…

Fix: 1.0.3+
Fix from $1,950 2026-06-25
Insightconnect Awk CRITICAL 9.8
CVE-2026-8592

OS Command Injection vulnerability in the process_string action of Rapid7 InsightConnect AWK Plugin on Linux allows remote attackers to execute arbit…

Fix: 1.2.2+
Fix from $2,300 2026-06-25
Insightconnect Rpm HIGH 8.8
CVE-2026-8663

OS Command Injection vulnerability in Rapid7 InsightConnect RPM Plugin on Linux allows authenticated attackers to execute arbitrary OS commands via t…

Fix: 1.0.2+
Fix from $1,950 2026-06-25
Insightconnect Sqlmap HIGH 8.8
CVE-2026-8659

OS Command Injection vulnerability in Rapid7 InsightConnect SQLmap Plugin on Linux allows authenticated attackers to execute arbitrary OS commands vi…

Fix: 2.0.1+
Fix from $1,950 2026-06-25
Velociraptor HIGH 7.7
CVE-2026-7573

An authorization bypass (CWE-639) in the GetUserRoles gRPC API endpoint in Velocidex Velociraptor below version 0.76.5 allows any authenticated low-p…

Fix: 0.76.5+
Fix from $1,950 2026-05-06
Velociraptor MEDIUM 5.5
CVE-2026-7572

An off-by-one error (CWE-193) in the ConsumeUnit16Array and ConsumeUnit64Array functions in Velocidex Velociraptor before version 0.76.5 on Windows a…

Fix: 0.76.5+
Fix from $1,600 2026-05-06
Insight Agent HIGH 7.8
CVE-2026-6482

The Rapid7 Insight Agent (versions > 4.1.0.2) is vulnerable to a local privilege escalation attack that allows users to gain SYSTEM level control of …

Fix: 4.1.0.2+
Fix from $1,950 2026-04-17
Velociraptor CRITICAL 9.1
CVE-2026-6290

Velociraptor versions prior to 0.76.3 contain a vulnerability in the query() plugin which allows access to all orgs with the user's current ACL token…

Fix: 0.76.3+
Fix from $2,300 2026-04-15
Insight Agent MEDIUM 5.5
CVE-2026-4482

The installer certificate files in the …/bootstrap/common/ssl folder do not seem to have restricted permissions on Windows systems (users have read a…

Fix: 4.1.0.2+
Fix from $1,600 2026-04-10
Velociraptor MEDIUM 6.5
CVE-2026-5329

Rapid7 Velociraptor versions prior to 0.76.2 contain an improper input validation vulnerability in the client monitoring message handler on the Veloc…

Fix: 0.76.3+
Fix from $1,600 2026-04-09
Insight Agent HIGH 7.2
CVE-2026-4837

An eval() injection vulnerability in the Rapid7 Insight Agent beaconing logic for Linux versions could theoretically allow an attacker to achieve rem…

Fix: 4.1.0.2+
Fix from $1,950 2026-04-08
Velociraptor MEDIUM 6.8
CVE-2025-14728

Rapid7 Velociraptor versions before 0.75.6 contain a directory traversal issue on Linux servers that allows a rogue client to upload a file which is …

Fix: 0.75.6+
Fix from $1,600 2025-12-29
Velociraptor MEDIUM 5.5
CVE-2025-6264

Velociraptor allows collection of VQL queries packaged into Artifacts from endpoints. These artifacts can be used to do anything and usually run with…

Fix: 0.74.3+
Fix from $1,600 2025-06-20
Insightvm MEDIUM 5.3
CVE-2024-6504

Rapid7 InsightVM Console versions below 6.6.260 suffer from a protection mechanism failure whereby an attacker with network access to the InsightVM C…

Fix: 6.6.261+
Fix from $1,600 2024-07-18
Velociraptor MEDIUM 6.1
CVE-2023-5950

Rapid7 Velociraptor versions prior to 0.7.0-4 suffer from a reflected cross site scripting vulnerability. This vulnerability allows attackers to inje…

Fix: 0.6.9-1+
Fix from $1,600 2023-11-06
Insight Agent HIGH 7.5
CVE-2023-2273

Rapid7 Insight Agent token handler versions 3.2.6 and below, suffer from a Directory Traversal vulnerability whereby unsanitized input from a CLI arg…

Fix: 3.3.0+
Fix from $1,950 2023-04-26
Velociraptor MEDIUM 5.3
CVE-2023-2226

Due to insufficient validation in the PE and OLE parsers in Rapid7's Velociraptor versions earlier than 0.6.8 allows attacker to crash Velociraptor d…

Fix: 0.6.8+
Fix from $1,600 2023-04-21
Nexpose CRITICAL 9.8
CVE-2023-1699

Rapid7 Nexpose versions 6.6.186 and below suffer from a forced browsing vulnerability.  This vulnerability allows an attacker to manipulate URLs to f…

Fix: 6.6.187+
Fix from $2,300 2023-03-30
Insightvm MEDIUM 5.4
CVE-2021-3844

Rapid7 InsightVM suffers from insufficient session expiration when an administrator performs a security relevant edit on an existing, logged on user.…

Fix: 6.5.50+
Fix from $1,600 2023-03-24
Insightappsec HIGH 8.8
CVE-2023-1304

An authenticated attacker can leverage an exposed getattr() method via a Jinja template to smuggle OS commands and perform other actions that are nor…

Fix: 23.2.1 / 2023.02.01+
Fix from $1,950 2023-03-21
Insightappsec HIGH 8.8
CVE-2023-1306

An authenticated attacker can leverage an exposed resource.db() accessor method to smuggle Python method calls via a Jinja template, which can lead t…

Fix: 23.2.1 / 2023.02.01+
Fix from $1,950 2023-03-21
Insightappsec HIGH 8.1
CVE-2023-1305

An authenticated attacker can leverage an exposed “box” object to read and write arbitrary files from disk, provided those files can be parsed as yam…

Fix: 23.2.1 / 2023.02.01+
Fix from $1,950 2023-03-21
Insightvm MEDIUM 6.1
CVE-2023-0681

Rapid7 InsightVM versions 6.6.178 and lower suffers from an open redirect vulnerability, whereby an attacker has the ability to redirect the user to …

Fix: 6.6.179+
Fix from $1,600 2023-03-20
Nexpose MEDIUM 5.3
CVE-2022-3913

Rapid7 Nexpose and InsightVM versions 6.6.82 through 6.6.177 fail to validate the certificate of the update server when downloading updates. This fai…

Fix: 6.6.178+
Fix from $1,600 2023-02-01
Velociraptor HIGH 8.8
CVE-2023-0242

Rapid7 Velociraptor allows users to be created with different privileges on the server. Administrators are generally allowed to run any command on th…

Fix: 0.6.7-5+
Fix from $1,950 2023-01-18
Insightvm HIGH 7.7
CVE-2017-5242

Nexpose and InsightVM virtual appliances downloaded between April 5th, 2017 and May 3rd, 2017 contain identical SSH host keys. Normally, a unique SSH…

Fix: after 2017-05-03
Fix from $1,950 2023-01-12