Vulnerability index

Browse CVEs

77 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Metasploit HIGH 7.3
CVE-2019-5624

Rapid7 Metasploit Framework suffers from an instance of CWE-22, Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in the…

Fix: after 4.14.0
Fix from $1,950 2019-04-30
Insightvm MEDIUM 6.5
CVE-2019-5615

Users with Site-level permissions can access files containing the username-encrypted passwords of Security Console Global Administrators and clear-te…

Fix: after 6.5.49
Fix from $1,600 2019-04-09
Nexpose HIGH 8.8
CVE-2017-5264

Versions of Nexpose prior to 6.4.66 fail to adequately validate the source of HTTP requests intended for the Automated Actions administrative web app…

Fix: 6.4.66+
Fix from $1,950 2017-12-14
Metasploit MEDIUM 6.5
CVE-2017-15084

The web UI in Rapid7 Metasploit before 4.14.1-20170828 allows logout CSRF, aka R7-2017-22.

Fix: after 4.14.1
Fix from $1,600 2017-10-06
Nexpose HIGH 8.5
CVE-2017-5243

The default SSH configuration in Rapid7 Nexpose hardware appliances shipped before June 2017 does not specify desired algorithms for key exchange and…

Fix: after 6.4.40
Fix from $1,950 2017-06-06
Appspider Pro HIGH 7.8
CVE-2017-5236

Editions of Rapid7 AppSpider Pro installers prior to version 6.14.060 contain a DLL preloading vulnerability, wherein it is possible for the installe…

Fix: after 6.14.059
Fix from $1,950 2017-05-03
Appspider Pro HIGH 7.5
CVE-2017-5240

Editions of Rapid7 AppSpider Pro prior to version 6.14.060 contain a heap-based buffer overflow in the FLAnalyzer.exe component. A malicious or malfo…

Fix: after 6.14.059
Fix from $1,950 2017-05-03
Nexpose HIGH 7.8
CVE-2017-5232

All editions of Rapid7 Nexpose installers prior to version 6.4.24 contain a DLL preloading vulnerability, wherein it is possible for the installer to…

Fix: after 6.4.23
Fix from $1,950 2017-03-02
Appspider Pro HIGH 7.8
CVE-2017-5233

Rapid7 AppSpider Pro installers prior to version 6.14.053 contain a DLL preloading vulnerability, wherein it is possible for the installer to load a …

Fix: 6.14.053+
Fix from $1,950 2017-03-02
Insight Collector HIGH 7.8
CVE-2017-5234

Rapid7 Insight Collector installers prior to version 1.0.16 contain a DLL preloading vulnerability, wherein it is possible for the installer to load …

Fix: after 1.0.15
Fix from $1,950 2017-03-02
Metasploit HIGH 7.8
CVE-2017-5235

Rapid7 Metasploit Pro installers prior to version 4.13.0-2017022101 contain a DLL preloading vulnerability, wherein it is possible for the installer …

Fix: after 4.13.0-2017012501
Fix from $1,950 2017-03-02
Nexpose HIGH 7.2
CVE-2017-5230

The Java keystore in all versions and editions of Rapid7 Nexpose prior to 6.4.50 is encrypted with a static password of 'r@p1d7k3y5t0r3' which is not…

Fix: after 6.4.23
Fix from $1,950 2017-03-02
Metasploit HIGH 7.1
CVE-2017-5228

All editions of Rapid7 Metasploit prior to version 4.13.0-2017020701 contain a directory traversal vulnerability in the Meterpreter stdapi Dir.downlo…

Fix: after 4.13.19
Fix from $1,950 2017-03-02
Metasploit HIGH 7.1
CVE-2017-5229

All editions of Rapid7 Metasploit prior to version 4.13.0-2017020701 contain a directory traversal vulnerability in the Meterpreter extapi Clipboard.…

Fix: after 4.13.19
Fix from $1,950 2017-03-02
Metasploit HIGH 7.1
CVE-2017-5231

All editions of Rapid7 Metasploit prior to version 4.13.0-2017020701 contain a directory traversal vulnerability in the Meterpreter stdapi CommandDis…

Fix: after 4.13.19
Fix from $1,950 2017-03-02
Nexpose MEDIUM 5.4
CVE-2016-9757

In the Create Tags page of the Rapid7 Nexpose version 6.4.12 user interface, any authenticated user who has the capability to create tags can inject …

Mitigation only
Fix from $1,600 2016-12-20
Nexpose MEDIUM 6.8
CVE-2012-6493

Cross-site request forgery (CSRF) vulnerability in Rapid7 Nexpose Security Console before 5.5.4 allows remote attackers to hijack the authentication …

Fix: after 5.5.3
Fix from $1,600 2014-02-04