The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
TitleEitWModules
CVE-2020-10625: Missing Authentication for Critical Function9.8 CriticalN/A0%Apr 9, 2020
CVE-2020-10617: Improper Neutralization of Special Elements used in an SQL Command7.5 HighN/A0%Apr 9, 2020
CVE-2020-10623: Improper Neutralization of Special Elements used in an SQL Command6.5 MediumN/A0%Apr 9, 2020
CVE-2020-10621: Unrestricted Upload of File with Dangerous Type9.8 CriticalN/A0%Apr 9, 2020
CVE-2020-10551: Incorrect Permission Assignment for Critical Resource7.8 HighN/A10%Apr 9, 2020
CVE-2020-11553: Cross-Site Request Forgery (CSRF)8.8 HighN/A0%Apr 9, 2020
CVE-2020-11554: Undefined Security Weakness7.5 HighN/A1%Apr 9, 2020
CVE-2020-11555: Insufficiently Protected Credentials7.5 HighN/A1%Apr 9, 2020
CVE-2020-11556: Improper Neutralization of Input During Web Page Generation5.4 MediumN/A0%Apr 9, 2020
CVE-2020-11557: Cleartext Transmission of Sensitive Information7.5 HighN/A0%Apr 9, 2020
CVE-2020-11655: Improper Initialization7.5 HighN/A5%Apr 9, 2020
CVE-2020-11656: Use After Free9.8 CriticalN/A8%Apr 9, 2020
CVE-2019-20637: Improper Removal of Sensitive Information Before Storage or Transfer7.5 HighN/A0%Apr 8, 2020
CVE-2020-11650: Improper Restriction of Excessive Authentication Attempts7.5 HighN/A12%Apr 8, 2020
CVE-2020-2732: Exposure of Sensitive Information to an Unauthorized Actor5.8 MediumN/A0%Apr 8, 2020
CVE-2020-1885: Improper Link Resolution Before File Access7.8 HighN/A0%Apr 8, 2020
CVE-2020-8828: Improper Authentication8.8 HighN/A0%Apr 8, 2020
CVE-2020-8827: Improper Restriction of Excessive Authentication Attempts7.5 HighN/A1%Apr 8, 2020
CVE-2020-8826: Session Fixation7.5 HighN/A0%Apr 8, 2020
CVE-2020-1639: Improper Check or Handling of Exceptional Conditions7.5 HighN/A1%Apr 8, 2020
CVE-2020-1638: Use of sizeof() on a Pointer Type7.5 HighN/A0%Apr 8, 2020
CVE-2020-1637: Authentication Bypass Using an Alternate Path or Channel7.2 HighN/A0%Apr 8, 2020
CVE-2020-1634: Integer Overflow or Wraparound7.5 HighN/A1%Apr 8, 2020
CVE-2020-1630: Time-of-check Time-of-use (TOCTOU) Race Condition5.0 MediumN/A0%Apr 8, 2020
CVE-2020-1629: Race Condition within a Thread5.9 MediumN/A0%Apr 8, 2020
258476-258500 of 715808