The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
TitleEitWModules
CVE-2020-2172: Improper Restriction of Recursive Entity References in DTDs6.5 MediumN/A0%Apr 7, 2020
CVE-2020-6171: Improper Neutralization of Input During Web Page Generation6.1 MediumN/A19%Apr 7, 2020
CVE-2020-8096: Untrusted Search Path6.3 MediumN/A0%Apr 7, 2020
CVE-2020-11560: Insufficiently Protected Credentials7.8 HighN/A2%Apr 7, 2020
CVE-2020-11586: Improper Restriction of XML External Entity Reference9.8 CriticalN/A2%Apr 6, 2020
CVE-2020-11587: Undefined Security Weakness7.5 HighN/A1%Apr 6, 2020
CVE-2020-11588: Undefined Security Weakness5.3 MediumN/A1%Apr 6, 2020
CVE-2020-11589: Authorization Bypass Through User-Controlled Key7.5 HighN/A1%Apr 6, 2020
CVE-2020-11590: Undefined Security Weakness5.3 MediumN/A1%Apr 6, 2020
CVE-2020-11591: Undefined Security Weakness5.3 MediumN/A1%Apr 6, 2020
CVE-2020-11592: Undefined Security Weakness7.5 HighN/A1%Apr 6, 2020
CVE-2020-11593: Improper Neutralization of Special Elements in Output Used by a Downstream Component7.5 HighN/A1%Apr 6, 2020
CVE-2020-11594: Generation of Error Message Containing Sensitive Information7.5 HighN/A1%Apr 6, 2020
CVE-2020-11595: Undefined Security Weakness7.5 HighN/A1%Apr 6, 2020
CVE-2020-11596: Improper Limitation of a Pathname to a Restricted Directory7.5 HighN/A2%Apr 6, 2020
CVE-2020-11597: Improper Neutralization of Special Elements used in an SQL Command9.8 CriticalN/A2%Apr 6, 2020
CVE-2020-11598: Missing Authentication for Critical Function9.8 CriticalN/A3%Apr 6, 2020
CVE-2020-11599: Missing Authentication for Critical Function7.5 HighN/A0%Apr 6, 2020
CVE-2020-11585: Use of Insufficiently Random Values4.3 MediumN/A0%Apr 6, 2020
CVE-2020-11581: Improper Neutralization of Special Elements used in an OS Command8.1 HighN/A39%Apr 6, 2020
CVE-2020-11582: Exposure of Resource to Wrong Sphere8.8 HighN/A0%Apr 6, 2020
CVE-2020-11580: Improper Certificate Validation9.1 CriticalN/A0%Apr 6, 2020
CVE-2020-5832: Undefined Security Weakness7.8 HighN/A0%Apr 6, 2020
CVE-2020-5300: Authentication Bypass by Capture-replay5.8 MediumN/A0%Apr 6, 2020
CVE-2020-11102: Out-of-bounds Write5.6 MediumN/A0%Apr 6, 2020
258601-258625 of 715808