The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
TitleEitWModules
CVE-2020-3834: Out-of-bounds Write7.8 HighN/A0%Feb 27, 2020
CVE-2020-3841: Cleartext Transmission of Sensitive Information6.5 MediumN/A0%Feb 27, 2020
CVE-2020-3838: Incorrect Default Permissions7.8 HighN/A0%Feb 27, 2020
CVE-2020-3845: Out-of-bounds Write7.8 HighN/A0%Feb 27, 2020
CVE-2020-3836: Undefined Security Weakness5.5 MediumN/A0%Feb 27, 2020
CVE-2020-3831: Concurrent Execution using Shared Resource with Improper Synchronization7.0 HighN/A0%Feb 27, 2020
CVE-2020-3840: Improper Restriction of Operations within the Bounds of a Memory Buffer7.8 HighN/A0%Feb 27, 2020
CVE-2020-3843: Out-of-bounds Write8.8 HighN/A2%Feb 27, 2020
CVE-2020-7063: Improper Preservation of Permissions5.5 MediumN/A0%Feb 27, 2020
CVE-2020-7062: NULL Pointer Dereference7.5 HighN/A1%Feb 27, 2020
CVE-2020-7061: Out-of-bounds Read6.5 MediumN/A2%Feb 27, 2020
CVE-2020-5402: Cross-Site Request Forgery (CSRF)8.8 HighN/A0%Feb 27, 2020
CVE-2020-5401: Return of Wrong Status Code5.3 MediumN/A0%Feb 27, 2020
CVE-2020-5400: Insufficiently Protected Credentials6.5 MediumN/A0%Feb 27, 2020
CVE-2015-2992: Improper Neutralization of Input During Web Page Generation6.1 MediumN/A2%Feb 27, 2020
CVE-2017-16900: Improper Restriction of Excessive Authentication Attempts5.5 MediumN/A0%Feb 27, 2020
CVE-2020-7043: Improper Certificate Validation9.1 CriticalN/A0%Feb 27, 2020
CVE-2020-7042: Improper Certificate Validation5.3 MediumN/A1%Feb 27, 2020
CVE-2020-7041: Improper Certificate Validation5.3 MediumN/A1%Feb 27, 2020
CVE-2020-6864: Undefined Security Weakness6.5 MediumN/A0%Feb 27, 2020
CVE-2020-6863: Undefined Security Weakness6.5 MediumN/A0%Feb 27, 2020
CVE-2019-5326: Deserialization of Untrusted Data7.2 HighN/A3%Feb 27, 2020
CVE-2019-5323: Improper Neutralization of Special Elements used in a Command7.2 HighN/A1%Feb 27, 2020
CVE-2019-4669: Improper Neutralization of Special Elements used in an SQL Command6.3 MediumN/A0%Feb 27, 2020
CVE-2019-12882: Undefined Security Weakness9.8 CriticalN/AN/AFeb 27, 2020
259501-259525 of 703397