Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
HIGH 8.8
CVE-2026-8658
OS Command Injection vulnerability in Rapid7 InsightConnect Tcpdump Plugin on Linux allows authenticated attackers to execute arbitrary OS commands v…
Insightconnect Tcpdump
2.0.0+
CRITICAL 9.8
CVE-2026-8660
OS Command Injection vulnerability in the ping action of Rapid7 InsightConnect Ping Plugin on Linux allows remote attackers to execute arbitrary OS c…
Insightconnect Ping
1.0.4+
CRITICAL 9.8
CVE-2026-8665
OS Command Injection vulnerability in the TR action of Rapid7 InsightConnect Translate Plugin on Linux allows remote attackers to execute arbitrary O…
Insightconnect Translate
2.0.3+
CRITICAL 9.8
CVE-2026-8666
OS Command Injection vulnerability in the traceroute action of Rapid7 InsightConnect Traceroute Plugin on Linux allows remote attackers to execute ar…
Insightconnect Traceroute
1.0.3+
HIGH 8.8
CVE-2026-8664
OS Command Injection vulnerability in Rapid7 InsightConnect Finger Plugin on Linux allows authenticated attackers to execute arbitrary OS commands vi…
Insightconnect Finger
1.0.3+
CRITICAL 9.8
CVE-2026-8592
OS Command Injection vulnerability in the process_string action of Rapid7 InsightConnect AWK Plugin on Linux allows remote attackers to execute arbit…
Insightconnect Awk
1.2.2+
HIGH 8.8
CVE-2026-8663
OS Command Injection vulnerability in Rapid7 InsightConnect RPM Plugin on Linux allows authenticated attackers to execute arbitrary OS commands via t…
Insightconnect Rpm
1.0.2+
HIGH 8.8
CVE-2026-8659
OS Command Injection vulnerability in Rapid7 InsightConnect SQLmap Plugin on Linux allows authenticated attackers to execute arbitrary OS commands vi…
Insightconnect Sqlmap
2.0.1+
HIGH 7.7
CVE-2026-7573
An authorization bypass (CWE-639) in the GetUserRoles gRPC API endpoint in Velocidex Velociraptor below version 0.76.5 allows any authenticated low-p…
Velociraptor
0.76.5+
MEDIUM 5.5
CVE-2026-7572
An off-by-one error (CWE-193) in the ConsumeUnit16Array and ConsumeUnit64Array functions in Velocidex Velociraptor before version 0.76.5 on Windows a…
Velociraptor
0.76.5+
HIGH 7.8
CVE-2026-6482
The Rapid7 Insight Agent (versions > 4.1.0.2) is vulnerable to a local privilege escalation attack that allows users to gain SYSTEM level control of …
Insight Agent
4.1.0.2+
CRITICAL 9.1
CVE-2026-6290
Velociraptor versions prior to 0.76.3 contain a vulnerability in the query() plugin which allows access to all orgs with the user's current ACL token…
Velociraptor
0.76.3+
MEDIUM 5.5
CVE-2026-4482
The installer certificate files in the …/bootstrap/common/ssl folder do not seem to have restricted permissions on Windows systems (users have read a…
Insight Agent
4.1.0.2+
MEDIUM 6.5
CVE-2026-5329
Rapid7 Velociraptor versions prior to 0.76.2 contain an improper input validation vulnerability in the client monitoring message handler on the Veloc…
Velociraptor
0.76.3+
HIGH 7.2
CVE-2026-4837
An eval() injection vulnerability in the Rapid7 Insight Agent beaconing logic for Linux versions could theoretically allow an attacker to achieve rem…
Insight Agent
4.1.0.2+
MEDIUM 6.8
CVE-2025-14728
Rapid7 Velociraptor versions before 0.75.6 contain a directory traversal issue on Linux servers that allows a rogue client to upload a file which is …
Velociraptor
0.75.6+
MEDIUM 5.5
CVE-2025-6264
Velociraptor allows collection of VQL queries packaged into Artifacts from endpoints. These artifacts can be used to do anything and usually run with…
Velociraptor
0.74.3+
MEDIUM 5.3
CVE-2024-6504
Rapid7 InsightVM Console versions below 6.6.260 suffer from a protection mechanism failure whereby an attacker with network access to the InsightVM C…
Insightvm
6.6.261+
MEDIUM 6.1
CVE-2023-5950
Rapid7 Velociraptor versions prior to 0.7.0-4 suffer from a reflected cross site scripting vulnerability. This vulnerability allows attackers to inje…
Velociraptor
0.6.9-1+
HIGH 7.5
CVE-2023-2273
Rapid7 Insight Agent token handler versions 3.2.6 and below, suffer from a Directory Traversal vulnerability whereby unsanitized input from a CLI arg…
Insight Agent
3.3.0+
MEDIUM 5.3
CVE-2023-2226
Due to insufficient validation in the PE and OLE parsers in Rapid7's Velociraptor versions earlier than 0.6.8 allows attacker to crash Velociraptor d…
Velociraptor
0.6.8+
CRITICAL 9.8
CVE-2023-1699
Rapid7 Nexpose versions 6.6.186 and below suffer from a forced browsing vulnerability. This vulnerability allows an attacker to manipulate URLs to f…
Nexpose
6.6.187+
MEDIUM 5.4
CVE-2021-3844
Rapid7 InsightVM suffers from insufficient session expiration when an administrator performs a security relevant edit on an existing, logged on user.…
Insightvm
6.5.50+
HIGH 8.8
CVE-2023-1304
An authenticated attacker can leverage an exposed getattr() method via a Jinja template to smuggle OS commands and perform other actions that are nor…
Insightappsec
23.2.1 / 2023.02.01+
HIGH 8.8
CVE-2023-1306
An authenticated attacker can leverage an exposed resource.db() accessor method to smuggle Python method calls via a Jinja template, which can lead t…
Insightappsec
23.2.1 / 2023.02.01+
HIGH 8.1
CVE-2023-1305
An authenticated attacker can leverage an exposed “box” object to read and write arbitrary files from disk, provided those files can be parsed as yam…
Insightappsec
23.2.1 / 2023.02.01+
MEDIUM 6.1
CVE-2023-0681
Rapid7 InsightVM versions 6.6.178 and lower suffers from an open redirect vulnerability, whereby an attacker has the ability to redirect the user to …
Insightvm
6.6.179+
MEDIUM 5.3
CVE-2022-3913
Rapid7 Nexpose and InsightVM versions 6.6.82 through 6.6.177 fail to validate the certificate of the update server when downloading updates. This fai…
Nexpose
6.6.178+
HIGH 8.8
CVE-2023-0242
Rapid7 Velociraptor allows users to be created with different privileges on the server. Administrators are generally allowed to run any command on th…
Velociraptor
0.6.7-5+
HIGH 7.7
CVE-2017-5242
Nexpose and InsightVM virtual appliances downloaded between April 5th, 2017 and May 3rd, 2017 contain identical SSH host keys. Normally, a unique SSH…
Insightvm
after 2017-05-03