Vulnerability index

Browse CVEs

77 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 8.8 CVE-2026-8658 OS Command Injection vulnerability in Rapid7 InsightConnect Tcpdump Plugin on Linux allows authenticated attackers to execute arbitrary OS commands v… Insightconnect Tcpdump 2.0.0+ Fix from $1,9502026-06-25 CRITICAL 9.8 CVE-2026-8660 OS Command Injection vulnerability in the ping action of Rapid7 InsightConnect Ping Plugin on Linux allows remote attackers to execute arbitrary OS c… Insightconnect Ping 1.0.4+ Fix from $2,3002026-06-25 CRITICAL 9.8 CVE-2026-8665 OS Command Injection vulnerability in the TR action of Rapid7 InsightConnect Translate Plugin on Linux allows remote attackers to execute arbitrary O… Insightconnect Translate 2.0.3+ Fix from $2,3002026-06-25 CRITICAL 9.8 CVE-2026-8666 OS Command Injection vulnerability in the traceroute action of Rapid7 InsightConnect Traceroute Plugin on Linux allows remote attackers to execute ar… Insightconnect Traceroute 1.0.3+ Fix from $2,3002026-06-25 HIGH 8.8 CVE-2026-8664 OS Command Injection vulnerability in Rapid7 InsightConnect Finger Plugin on Linux allows authenticated attackers to execute arbitrary OS commands vi… Insightconnect Finger 1.0.3+ Fix from $1,9502026-06-25 CRITICAL 9.8 CVE-2026-8592 OS Command Injection vulnerability in the process_string action of Rapid7 InsightConnect AWK Plugin on Linux allows remote attackers to execute arbit… Insightconnect Awk 1.2.2+ Fix from $2,3002026-06-25 HIGH 8.8 CVE-2026-8663 OS Command Injection vulnerability in Rapid7 InsightConnect RPM Plugin on Linux allows authenticated attackers to execute arbitrary OS commands via t… Insightconnect Rpm 1.0.2+ Fix from $1,9502026-06-25 HIGH 8.8 CVE-2026-8659 OS Command Injection vulnerability in Rapid7 InsightConnect SQLmap Plugin on Linux allows authenticated attackers to execute arbitrary OS commands vi… Insightconnect Sqlmap 2.0.1+ Fix from $1,9502026-06-25 HIGH 7.7 CVE-2026-7573 An authorization bypass (CWE-639) in the GetUserRoles gRPC API endpoint in Velocidex Velociraptor below version 0.76.5 allows any authenticated low-p… Velociraptor 0.76.5+ Fix from $1,9502026-05-06 MEDIUM 5.5 CVE-2026-7572 An off-by-one error (CWE-193) in the ConsumeUnit16Array and ConsumeUnit64Array functions in Velocidex Velociraptor before version 0.76.5 on Windows a… Velociraptor 0.76.5+ Fix from $1,6002026-05-06 HIGH 7.8 CVE-2026-6482 The Rapid7 Insight Agent (versions > 4.1.0.2) is vulnerable to a local privilege escalation attack that allows users to gain SYSTEM level control of … Insight Agent 4.1.0.2+ Fix from $1,9502026-04-17 CRITICAL 9.1 CVE-2026-6290 Velociraptor versions prior to 0.76.3 contain a vulnerability in the query() plugin which allows access to all orgs with the user's current ACL token… Velociraptor 0.76.3+ Fix from $2,3002026-04-15 MEDIUM 5.5 CVE-2026-4482 The installer certificate files in the …/bootstrap/common/ssl folder do not seem to have restricted permissions on Windows systems (users have read a… Insight Agent 4.1.0.2+ Fix from $1,6002026-04-10 MEDIUM 6.5 CVE-2026-5329 Rapid7 Velociraptor versions prior to 0.76.2 contain an improper input validation vulnerability in the client monitoring message handler on the Veloc… Velociraptor 0.76.3+ Fix from $1,6002026-04-09 HIGH 7.2 CVE-2026-4837 An eval() injection vulnerability in the Rapid7 Insight Agent beaconing logic for Linux versions could theoretically allow an attacker to achieve rem… Insight Agent 4.1.0.2+ Fix from $1,9502026-04-08 MEDIUM 6.8 CVE-2025-14728 Rapid7 Velociraptor versions before 0.75.6 contain a directory traversal issue on Linux servers that allows a rogue client to upload a file which is … Velociraptor 0.75.6+ Fix from $1,6002025-12-29 MEDIUM 5.5 CVE-2025-6264 Velociraptor allows collection of VQL queries packaged into Artifacts from endpoints. These artifacts can be used to do anything and usually run with… Velociraptor 0.74.3+ Fix from $1,6002025-06-20 MEDIUM 5.3 CVE-2024-6504 Rapid7 InsightVM Console versions below 6.6.260 suffer from a protection mechanism failure whereby an attacker with network access to the InsightVM C… Insightvm 6.6.261+ Fix from $1,6002024-07-18 MEDIUM 6.1 CVE-2023-5950 Rapid7 Velociraptor versions prior to 0.7.0-4 suffer from a reflected cross site scripting vulnerability. This vulnerability allows attackers to inje… Velociraptor 0.6.9-1+ Fix from $1,6002023-11-06 HIGH 7.5 CVE-2023-2273 Rapid7 Insight Agent token handler versions 3.2.6 and below, suffer from a Directory Traversal vulnerability whereby unsanitized input from a CLI arg… Insight Agent 3.3.0+ Fix from $1,9502023-04-26 MEDIUM 5.3 CVE-2023-2226 Due to insufficient validation in the PE and OLE parsers in Rapid7's Velociraptor versions earlier than 0.6.8 allows attacker to crash Velociraptor d… Velociraptor 0.6.8+ Fix from $1,6002023-04-21 CRITICAL 9.8 CVE-2023-1699 Rapid7 Nexpose versions 6.6.186 and below suffer from a forced browsing vulnerability.  This vulnerability allows an attacker to manipulate URLs to f… Nexpose 6.6.187+ Fix from $2,3002023-03-30 MEDIUM 5.4 CVE-2021-3844 Rapid7 InsightVM suffers from insufficient session expiration when an administrator performs a security relevant edit on an existing, logged on user.… Insightvm 6.5.50+ Fix from $1,6002023-03-24 HIGH 8.8 CVE-2023-1304 An authenticated attacker can leverage an exposed getattr() method via a Jinja template to smuggle OS commands and perform other actions that are nor… Insightappsec 23.2.1 / 2023.02.01+ Fix from $1,9502023-03-21 HIGH 8.8 CVE-2023-1306 An authenticated attacker can leverage an exposed resource.db() accessor method to smuggle Python method calls via a Jinja template, which can lead t… Insightappsec 23.2.1 / 2023.02.01+ Fix from $1,9502023-03-21 HIGH 8.1 CVE-2023-1305 An authenticated attacker can leverage an exposed “box” object to read and write arbitrary files from disk, provided those files can be parsed as yam… Insightappsec 23.2.1 / 2023.02.01+ Fix from $1,9502023-03-21 MEDIUM 6.1 CVE-2023-0681 Rapid7 InsightVM versions 6.6.178 and lower suffers from an open redirect vulnerability, whereby an attacker has the ability to redirect the user to … Insightvm 6.6.179+ Fix from $1,6002023-03-20 MEDIUM 5.3 CVE-2022-3913 Rapid7 Nexpose and InsightVM versions 6.6.82 through 6.6.177 fail to validate the certificate of the update server when downloading updates. This fai… Nexpose 6.6.178+ Fix from $1,6002023-02-01 HIGH 8.8 CVE-2023-0242 Rapid7 Velociraptor allows users to be created with different privileges on the server. Administrators are generally allowed to run any command on th… Velociraptor 0.6.7-5+ Fix from $1,9502023-01-18 HIGH 7.7 CVE-2017-5242 Nexpose and InsightVM virtual appliances downloaded between April 5th, 2017 and May 3rd, 2017 contain identical SSH host keys. Normally, a unique SSH… Insightvm after 2017-05-03 Fix from $1,9502023-01-12