Vulnerability index

Browse CVEs

77 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Insightvm MEDIUM 6.5
CVE-2022-4261

Rapid7 Nexpose and InsightVM versions prior to 6.6.172 failed to reliably validate the authenticity of update contents. This failure could allow an a…

Fix: 6.6.172+
Fix from $1,600 2022-12-08
Insightvm MEDIUM 5.3
CVE-2019-5641

Rapid7 InsightVM suffers from an information exposure issue whereby, when the user's session has ended due to inactivity, an attacker can use the Ins…

Fix: after 6.6.160
Fix from $1,600 2022-09-21
Velociraptor MEDIUM 6.1
CVE-2022-35630

A cross-site scripting (XSS) issue in generating a collection report made it possible for malicious clients to inject JavaScript code into the static…

Fix: 0.6.5-2+
Fix from $1,600 2022-07-29
Velociraptor MEDIUM 5.5
CVE-2022-35631

On MacOS and Linux, it may be possible to perform a symlink attack by replacing this predictable file name with a symlink to another file and have th…

Fix: 0.6.5-2+
Fix from $1,600 2022-07-29
Velociraptor MEDIUM 5.4
CVE-2022-35629

Due to a bug in the handling of the communication between the client and server, it was possible for one client, already registered with their own cl…

Fix: 0.6.5-2+
Fix from $1,600 2022-07-29
Nexpose HIGH 8.8
CVE-2022-0757

Rapid7 Nexpose versions 6.6.93 and earlier are susceptible to an SQL Injection vulnerability, whereby valid search operators are not defined. This la…

Fix: after 6.6.93
Fix from $1,950 2022-03-17
Insight Agent HIGH 7.8
CVE-2022-0237

Rapid7 Insight Agent versions 3.1.2.38 and earlier suffer from a privilege escalation vulnerability, whereby an attacker can hijack the flow of execu…

Fix: after 3.1.2.38
Fix from $1,950 2022-03-17
Nexpose MEDIUM 6.1
CVE-2022-0758

Rapid7 Nexpose versions 6.6.129 and earlier suffer from a reflected cross site scripting vulnerability, within the shared scan configuration componen…

Fix: 6.6.130+
Fix from $1,600 2022-03-17
Insight Agent HIGH 7.8
CVE-2021-4007

Rapid7 Insight Agent, versions 3.0.1 to 3.1.2.34, suffer from a local privilege escalation due to an uncontrolled DLL search path. Specifically, when…

Fix: 3.1.2.35+
Fix from $1,950 2021-12-14
Nexpose MEDIUM 5.3
CVE-2019-5640

Rapid7 Nexpose versions prior to 6.6.114 suffer from an information exposure issue whereby, when the user's session has ended due to inactivity, an a…

Fix: 6.6.114+
Fix from $1,600 2021-11-22
Nexpose MEDIUM 5.4
CVE-2021-31868

Rapid7 Nexpose version 6.6.95 and earlier allows authenticated users of the Security Console to view and edit any ticket in the legacy ticketing feat…

Fix: 6.6.96+
Fix from $1,600 2021-08-19
Nexpose MEDIUM 6.1
CVE-2021-3535

Rapid7 Nexpose is vulnerable to a non-persistent cross-site scripting vulnerability affecting the Security Console's Filtered Asset Search feature. A…

Fix: 6.6.81+
Fix from $1,600 2021-06-16
Metasploit HIGH 8.8
CVE-2020-7385

By launching the drb_remote_codeexec exploit, a Metasploit Framework user will inadvertently expose Metasploit to the same deserialization issue that…

Fix: 4.19.0+
Fix from $1,950 2021-04-23
Metasploit HIGH 7.8
CVE-2020-7384EPSS 30%

Rapid7's Metasploit msfvenom framework handles APK files in a way that allows for a malicious user to craft and publish a file that would execute arb…

Fix: 4.19.0+
Fix from $1,950 2020-10-29
Nexpose HIGH 8.1
CVE-2020-7383

A SQL Injection issue in Rapid7 Nexpose version prior to 6.6.49 that may have allowed an authenticated user with a low permission level to access res…

Fix: 6.6.49+
Fix from $1,950 2020-10-14
Appspider MEDIUM 6.5
CVE-2020-7358

In AppSpider installer versions prior to 7.2.126, the AppSpider installer calls an executable which can be placed in the appropriate directory by an …

Fix: 7.2.126+
Fix from $1,600 2020-09-18
Nexpose MEDIUM 6.5
CVE-2020-7382

Rapid7 Nexpose installer version prior to 6.6.40 contains an Unquoted Search Path which may allow an attacker on the local machine to insert an arbit…

Fix: 6.6.40+
Fix from $1,600 2020-09-03
Nexpose HIGH 7.8
CVE-2020-7381

In Rapid7 Nexpose installer versions prior to 6.6.40, the Nexpose installer calls an executable which can be placed in the appropriate directory by a…

Fix: 6.6.40+
Fix from $1,950 2020-09-03
Metasploit HIGH 7.5
CVE-2019-5645EPSS 42%

By sending a specially crafted HTTP GET request to a listening Rapid7 Metasploit HTTP handler, an attacker can register an arbitrary regular expressi…

Fix: after 5.0.27
Fix from $1,950 2020-09-01
Metasploit CRITICAL 9.8
CVE-2020-7376

The Metasploit Framework module "post/osx/gather/enum_osx module" is affected by a relative path traversal vulnerability in the get_keychains method …

Fix: 6.0.3+
Fix from $2,300 2020-08-24
Metasploit HIGH 7.5
CVE-2020-7377

The Metasploit Framework module "auxiliary/admin/http/telpho10_credential_dump" module is affected by a relative path traversal vulnerability in the …

Fix: 6.0.3+
Fix from $1,950 2020-08-24
Metasploit MEDIUM 6.1
CVE-2020-7355

Cross-site Scripting (XSS) vulnerability in the 'notes' field of a discovered scan asset in Rapid7 Metasploit Pro allows an attacker with a specially…

Fix: 4.17.1+
Fix from $1,600 2020-06-25
Metasploit MEDIUM 5.4
CVE-2020-7354

Cross-site Scripting (XSS) vulnerability in the 'host' field of a discovered scan asset in Rapid7 Metasploit Pro allows an attacker with a specially-…

Fix: 4.17.1+
Fix from $1,600 2020-06-25
Metasploit HIGH 7.8
CVE-2020-7350

Rapid7 Metasploit Framework versions before 5.0.85 suffers from an instance of CWE-78: OS Command Injection, wherein the libnotify plugin accepts unt…

Fix: 5.0.85+
Fix from $1,950 2020-04-22
Nexpose MEDIUM 6.1
CVE-2012-6494

Rapid7 Nexpose before 5.5.4 contains a session hijacking vulnerability which allows remote attackers to capture a user's session and gain unauthorize…

Fix: 5.5.4+
Fix from $1,600 2020-01-25
Appspider HIGH 7.1
CVE-2019-5647

The Chrome Plugin for Rapid7 AppSpider can incorrectly keep browser sessions active after recording a macro, even after a restart of the Chrome brows…

Fix: after 3.8.213
Fix from $1,950 2020-01-22
Nexpose HIGH 8.7
CVE-2019-5638

Rapid7 Nexpose versions 6.5.50 and prior suffer from insufficient session expiration when an administrator performs a security relevant edit on an ex…

Fix: after 6.5.50
Fix from $1,950 2019-08-21
Insightappsec HIGH 7.8
CVE-2019-5631

The Rapid7 InsightAppSec broker suffers from a DLL injection vulnerability in the 'prunsrv.exe' component of the product. If exploited, a local user …

Fix: after 2019.06.24
Fix from $1,950 2019-08-19
Insight Agent HIGH 7.8
CVE-2019-5629

Rapid7 Insight Agent, version 2.6.3 and prior, suffers from a local privilege escalation due to an uncontrolled DLL search path. Specifically, when I…

Fix: after 2.6.3
Fix from $1,950 2019-07-13
Nexpose HIGH 8.8
CVE-2019-5630

A Cross-Site Request Forgery (CSRF) vulnerability was found in Rapid7 Nexpose InsightVM Security Console versions 6.5.0 through 6.5.68. This issue al…

Fix: after 6.5.68
Fix from $1,950 2019-07-03