The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
TitleEitWModules
CVE-2020-11694: Cleartext Storage of Sensitive Information7.5 HighN/A0%Apr 10, 2020
CVE-2020-11647: Uncontrolled Recursion7.5 HighN/A2%Apr 10, 2020
CVE-2020-5330: Exposure of Sensitive Information to an Unauthorized Actor8.1 HighN/A21%Apr 10, 2020
CVE-2015-9546: Improper Limitation of a Pathname to a Restricted Directory4.8 MediumN/A0%Apr 10, 2020
CVE-2020-5406: Insufficiently Protected Credentials6.5 MediumN/A0%Apr 10, 2020
CVE-2015-9547: Exposure of Sensitive Information to an Unauthorized Actor7.5 HighN/A0%Apr 10, 2020
CVE-2015-8546: Out-of-bounds Write9.8 CriticalN/A2%Apr 10, 2020
CVE-2020-9056: Improper Neutralization of Input During Web Page Generation3.9 LowN/A0%Apr 10, 2020
CVE-2020-11002: Improper Neutralization of Special Elements in Output Used by a Downstream Component8.0 HighN/A1%Apr 10, 2020
CVE-2020-5303: Memory Allocation with Excessive Size Value3.1 LowN/A0%Apr 10, 2020
CVE-2015-5524: Buffer Copy without Checking Size of Input9.8 CriticalN/A0%Apr 10, 2020
CVE-2020-6765: Improper Neutralization of Special Elements used in an OS Command7.2 HighN/A1%Apr 10, 2020
CVE-2020-11669: Undefined Security Weakness5.5 MediumN/A0%Apr 10, 2020
CVE-2020-1801: Improper Authentication5.5 MediumN/A0%Apr 10, 2020
CVE-2020-4362: Undefined Security Weakness8.8 HighN/A1%Apr 10, 2020
CVE-2020-1802: Improper Validation of Integrity Check Value4.6 MediumN/A0%Apr 10, 2020
CVE-2020-3952: Missing Authentication for Critical Function9.8 CriticalN/A94%Apr 10, 2020
CVE-2020-8832: Exposure of Sensitive Information to an Unauthorized Actor5.5 MediumN/A0%Apr 9, 2020
CVE-2019-7305: Exposure of Sensitive Information to an Unauthorized Actor5.8 MediumN/A1%Apr 9, 2020
CVE-2019-18375: Undefined Security Weakness6.5 MediumN/A0%Apr 9, 2020
CVE-2019-18376: Cross-Site Request Forgery (CSRF)5.9 MediumN/A0%Apr 9, 2020
CVE-2020-1633: Improper Input Validation7.4 HighN/A0%Apr 9, 2020
CVE-2020-8834: Context Switching Race Condition6.5 MediumN/A0%Apr 9, 2020
CVE-2020-11668: NULL Pointer Dereference7.1 HighN/A0%Apr 9, 2020
CVE-2020-8961: Undefined Security Weakness9.8 CriticalN/A1%Apr 9, 2020
258451-258475 of 715808