Vulnerability index

Browse CVEs

77 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.3 CVE-2019-5624 Rapid7 Metasploit Framework suffers from an instance of CWE-22, Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in the… Metasploit after 4.14.0 Fix from $1,9502019-04-30 MEDIUM 6.5 CVE-2019-5615 Users with Site-level permissions can access files containing the username-encrypted passwords of Security Console Global Administrators and clear-te… Insightvm after 6.5.49 Fix from $1,6002019-04-09 HIGH 8.8 CVE-2017-5264 Versions of Nexpose prior to 6.4.66 fail to adequately validate the source of HTTP requests intended for the Automated Actions administrative web app… Nexpose 6.4.66+ Fix from $1,9502017-12-14 MEDIUM 6.5 CVE-2017-15084 The web UI in Rapid7 Metasploit before 4.14.1-20170828 allows logout CSRF, aka R7-2017-22. Metasploit after 4.14.1 Fix from $1,6002017-10-06 HIGH 8.5 CVE-2017-5243 The default SSH configuration in Rapid7 Nexpose hardware appliances shipped before June 2017 does not specify desired algorithms for key exchange and… Nexpose after 6.4.40 Fix from $1,9502017-06-06 HIGH 7.8 CVE-2017-5236 Editions of Rapid7 AppSpider Pro installers prior to version 6.14.060 contain a DLL preloading vulnerability, wherein it is possible for the installe… Appspider Pro after 6.14.059 Fix from $1,9502017-05-03 HIGH 7.5 CVE-2017-5240 Editions of Rapid7 AppSpider Pro prior to version 6.14.060 contain a heap-based buffer overflow in the FLAnalyzer.exe component. A malicious or malfo… Appspider Pro after 6.14.059 Fix from $1,9502017-05-03 HIGH 7.8 CVE-2017-5232 All editions of Rapid7 Nexpose installers prior to version 6.4.24 contain a DLL preloading vulnerability, wherein it is possible for the installer to… Nexpose after 6.4.23 Fix from $1,9502017-03-02 HIGH 7.8 CVE-2017-5233 Rapid7 AppSpider Pro installers prior to version 6.14.053 contain a DLL preloading vulnerability, wherein it is possible for the installer to load a … Appspider Pro 6.14.053+ Fix from $1,9502017-03-02 HIGH 7.8 CVE-2017-5234 Rapid7 Insight Collector installers prior to version 1.0.16 contain a DLL preloading vulnerability, wherein it is possible for the installer to load … Insight Collector after 1.0.15 Fix from $1,9502017-03-02 HIGH 7.8 CVE-2017-5235 Rapid7 Metasploit Pro installers prior to version 4.13.0-2017022101 contain a DLL preloading vulnerability, wherein it is possible for the installer … Metasploit after 4.13.0-2017012501 Fix from $1,9502017-03-02 HIGH 7.2 CVE-2017-5230 The Java keystore in all versions and editions of Rapid7 Nexpose prior to 6.4.50 is encrypted with a static password of 'r@p1d7k3y5t0r3' which is not… Nexpose after 6.4.23 Fix from $1,9502017-03-02 HIGH 7.1 CVE-2017-5228 All editions of Rapid7 Metasploit prior to version 4.13.0-2017020701 contain a directory traversal vulnerability in the Meterpreter stdapi Dir.downlo… Metasploit after 4.13.19 Fix from $1,9502017-03-02 HIGH 7.1 CVE-2017-5229 All editions of Rapid7 Metasploit prior to version 4.13.0-2017020701 contain a directory traversal vulnerability in the Meterpreter extapi Clipboard.… Metasploit after 4.13.19 Fix from $1,9502017-03-02 HIGH 7.1 CVE-2017-5231 All editions of Rapid7 Metasploit prior to version 4.13.0-2017020701 contain a directory traversal vulnerability in the Meterpreter stdapi CommandDis… Metasploit after 4.13.19 Fix from $1,9502017-03-02 MEDIUM 5.4 CVE-2016-9757 In the Create Tags page of the Rapid7 Nexpose version 6.4.12 user interface, any authenticated user who has the capability to create tags can inject … Nexpose Mitigation only Fix from $1,6002016-12-20 MEDIUM 6.8 CVE-2012-6493 Cross-site request forgery (CSRF) vulnerability in Rapid7 Nexpose Security Console before 5.5.4 allows remote attackers to hijack the authentication … Nexpose after 5.5.3 Fix from $1,6002014-02-04