Vulnerability index

Browse CVEs

77 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.5 CVE-2022-4261 Rapid7 Nexpose and InsightVM versions prior to 6.6.172 failed to reliably validate the authenticity of update contents. This failure could allow an a… Insightvm 6.6.172+ Fix from $1,6002022-12-08 MEDIUM 5.3 CVE-2019-5641 Rapid7 InsightVM suffers from an information exposure issue whereby, when the user's session has ended due to inactivity, an attacker can use the Ins… Insightvm after 6.6.160 Fix from $1,6002022-09-21 MEDIUM 6.1 CVE-2022-35630 A cross-site scripting (XSS) issue in generating a collection report made it possible for malicious clients to inject JavaScript code into the static… Velociraptor 0.6.5-2+ Fix from $1,6002022-07-29 MEDIUM 5.5 CVE-2022-35631 On MacOS and Linux, it may be possible to perform a symlink attack by replacing this predictable file name with a symlink to another file and have th… Velociraptor 0.6.5-2+ Fix from $1,6002022-07-29 MEDIUM 5.4 CVE-2022-35629 Due to a bug in the handling of the communication between the client and server, it was possible for one client, already registered with their own cl… Velociraptor 0.6.5-2+ Fix from $1,6002022-07-29 HIGH 8.8 CVE-2022-0757 Rapid7 Nexpose versions 6.6.93 and earlier are susceptible to an SQL Injection vulnerability, whereby valid search operators are not defined. This la… Nexpose after 6.6.93 Fix from $1,9502022-03-17 HIGH 7.8 CVE-2022-0237 Rapid7 Insight Agent versions 3.1.2.38 and earlier suffer from a privilege escalation vulnerability, whereby an attacker can hijack the flow of execu… Insight Agent after 3.1.2.38 Fix from $1,9502022-03-17 MEDIUM 6.1 CVE-2022-0758 Rapid7 Nexpose versions 6.6.129 and earlier suffer from a reflected cross site scripting vulnerability, within the shared scan configuration componen… Nexpose 6.6.130+ Fix from $1,6002022-03-17 HIGH 7.8 CVE-2021-4007 Rapid7 Insight Agent, versions 3.0.1 to 3.1.2.34, suffer from a local privilege escalation due to an uncontrolled DLL search path. Specifically, when… Insight Agent 3.1.2.35+ Fix from $1,9502021-12-14 MEDIUM 5.3 CVE-2019-5640 Rapid7 Nexpose versions prior to 6.6.114 suffer from an information exposure issue whereby, when the user's session has ended due to inactivity, an a… Nexpose 6.6.114+ Fix from $1,6002021-11-22 MEDIUM 5.4 CVE-2021-31868 Rapid7 Nexpose version 6.6.95 and earlier allows authenticated users of the Security Console to view and edit any ticket in the legacy ticketing feat… Nexpose 6.6.96+ Fix from $1,6002021-08-19 MEDIUM 6.1 CVE-2021-3535 Rapid7 Nexpose is vulnerable to a non-persistent cross-site scripting vulnerability affecting the Security Console's Filtered Asset Search feature. A… Nexpose 6.6.81+ Fix from $1,6002021-06-16 HIGH 8.8 CVE-2020-7385 By launching the drb_remote_codeexec exploit, a Metasploit Framework user will inadvertently expose Metasploit to the same deserialization issue that… Metasploit 4.19.0+ Fix from $1,9502021-04-23 HIGH 7.8 CVE-2020-7384EPSS 30% Rapid7's Metasploit msfvenom framework handles APK files in a way that allows for a malicious user to craft and publish a file that would execute arb… Metasploit 4.19.0+ Fix from $1,9502020-10-29 HIGH 8.1 CVE-2020-7383 A SQL Injection issue in Rapid7 Nexpose version prior to 6.6.49 that may have allowed an authenticated user with a low permission level to access res… Nexpose 6.6.49+ Fix from $1,9502020-10-14 MEDIUM 6.5 CVE-2020-7358 In AppSpider installer versions prior to 7.2.126, the AppSpider installer calls an executable which can be placed in the appropriate directory by an … Appspider 7.2.126+ Fix from $1,6002020-09-18 MEDIUM 6.5 CVE-2020-7382 Rapid7 Nexpose installer version prior to 6.6.40 contains an Unquoted Search Path which may allow an attacker on the local machine to insert an arbit… Nexpose 6.6.40+ Fix from $1,6002020-09-03 HIGH 7.8 CVE-2020-7381 In Rapid7 Nexpose installer versions prior to 6.6.40, the Nexpose installer calls an executable which can be placed in the appropriate directory by a… Nexpose 6.6.40+ Fix from $1,9502020-09-03 HIGH 7.5 CVE-2019-5645EPSS 42% By sending a specially crafted HTTP GET request to a listening Rapid7 Metasploit HTTP handler, an attacker can register an arbitrary regular expressi… Metasploit after 5.0.27 Fix from $1,9502020-09-01 CRITICAL 9.8 CVE-2020-7376 The Metasploit Framework module "post/osx/gather/enum_osx module" is affected by a relative path traversal vulnerability in the get_keychains method … Metasploit 6.0.3+ Fix from $2,3002020-08-24 HIGH 7.5 CVE-2020-7377 The Metasploit Framework module "auxiliary/admin/http/telpho10_credential_dump" module is affected by a relative path traversal vulnerability in the … Metasploit 6.0.3+ Fix from $1,9502020-08-24 MEDIUM 6.1 CVE-2020-7355 Cross-site Scripting (XSS) vulnerability in the 'notes' field of a discovered scan asset in Rapid7 Metasploit Pro allows an attacker with a specially… Metasploit 4.17.1+ Fix from $1,6002020-06-25 MEDIUM 5.4 CVE-2020-7354 Cross-site Scripting (XSS) vulnerability in the 'host' field of a discovered scan asset in Rapid7 Metasploit Pro allows an attacker with a specially-… Metasploit 4.17.1+ Fix from $1,6002020-06-25 HIGH 7.8 CVE-2020-7350 Rapid7 Metasploit Framework versions before 5.0.85 suffers from an instance of CWE-78: OS Command Injection, wherein the libnotify plugin accepts unt… Metasploit 5.0.85+ Fix from $1,9502020-04-22 MEDIUM 6.1 CVE-2012-6494 Rapid7 Nexpose before 5.5.4 contains a session hijacking vulnerability which allows remote attackers to capture a user's session and gain unauthorize… Nexpose 5.5.4+ Fix from $1,6002020-01-25 HIGH 7.1 CVE-2019-5647 The Chrome Plugin for Rapid7 AppSpider can incorrectly keep browser sessions active after recording a macro, even after a restart of the Chrome brows… Appspider after 3.8.213 Fix from $1,9502020-01-22 HIGH 8.7 CVE-2019-5638 Rapid7 Nexpose versions 6.5.50 and prior suffer from insufficient session expiration when an administrator performs a security relevant edit on an ex… Nexpose after 6.5.50 Fix from $1,9502019-08-21 HIGH 7.8 CVE-2019-5631 The Rapid7 InsightAppSec broker suffers from a DLL injection vulnerability in the 'prunsrv.exe' component of the product. If exploited, a local user … Insightappsec after 2019.06.24 Fix from $1,9502019-08-19 HIGH 7.8 CVE-2019-5629 Rapid7 Insight Agent, version 2.6.3 and prior, suffers from a local privilege escalation due to an uncontrolled DLL search path. Specifically, when I… Insight Agent after 2.6.3 Fix from $1,9502019-07-13 HIGH 8.8 CVE-2019-5630 A Cross-Site Request Forgery (CSRF) vulnerability was found in Rapid7 Nexpose InsightVM Security Console versions 6.5.0 through 6.5.68. This issue al… Nexpose after 6.5.68 Fix from $1,9502019-07-03