The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
TitleEitWModules
CVE-2018-21038: Improper Authentication9.8 CriticalN/A0%Apr 8, 2020
CVE-2020-11603: Access of Resource Using Incompatible Type9.8 CriticalN/A0%Apr 8, 2020
CVE-2020-11607: Undefined Security Weakness5.3 MediumN/A0%Apr 8, 2020
CVE-2020-11606: Undefined Security Weakness2.4 LowN/A0%Apr 8, 2020
CVE-2020-11605: Insertion of Sensitive Information into Log File7.5 HighN/A0%Apr 8, 2020
CVE-2020-11604: Out-of-bounds Read9.1 CriticalN/A0%Apr 8, 2020
CVE-2020-11602: Undefined Security Weakness2.4 LowN/A0%Apr 8, 2020
CVE-2020-11601: Undefined Security Weakness5.5 MediumN/A0%Apr 8, 2020
CVE-2020-11600: Out-of-bounds Write9.8 CriticalN/A0%Apr 8, 2020
CVE-2018-21081: Incorrect Permission Assignment for Critical Resource9.1 CriticalN/A0%Apr 8, 2020
CVE-2018-21082: Incorrect Authorization8.4 HighN/A0%Apr 8, 2020
CVE-2018-21083: Exposure of Sensitive Information to an Unauthorized Actor7.5 HighN/A0%Apr 8, 2020
CVE-2018-21084: Concurrent Execution using Shared Resource with Improper Synchronization8.1 HighN/A0%Apr 8, 2020
CVE-2018-21085: Concurrent Execution using Shared Resource with Improper Synchronization8.1 HighN/A0%Apr 8, 2020
CVE-2018-21086: Concurrent Execution using Shared Resource with Improper Synchronization8.1 HighN/A0%Apr 8, 2020
CVE-2018-21087: Out-of-bounds Write9.8 CriticalN/A0%Apr 8, 2020
CVE-2018-21088: Improper Handling of Exceptional Conditions7.5 HighN/A0%Apr 8, 2020
CVE-2020-4291: Session Fixation4.3 MediumN/A0%Apr 8, 2020
CVE-2020-4290: Authentication Bypass by Spoofing5.4 MediumN/A0%Apr 8, 2020
CVE-2020-4289: Incorrect Permission Assignment for Critical Resource5.3 MediumN/A0%Apr 8, 2020
CVE-2020-4284: Insufficient Session Expiration5.3 MediumN/A0%Apr 8, 2020
CVE-2020-4282: Improper Encoding or Escaping of Output4.3 MediumN/A0%Apr 8, 2020
CVE-2020-4252: Improper Neutralization of Input During Web Page Generation5.4 MediumN/A0%Apr 8, 2020
CVE-2020-4164: Generation of Error Message Containing Sensitive Information2.7 LowN/A0%Apr 8, 2020
CVE-2019-4746: Improper Neutralization of Input During Web Page Generation5.4 MediumN/A0%Apr 8, 2020
258501-258525 of 715808