The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
TitleEitWModules
CVE-2024-43502: Use of Uninitialized Resource7.1 HighN/A6%Oct 8, 2024
CVE-2024-38261: Improper Input Validation7.8 HighN/A1%Oct 8, 2024
CVE-2024-43516: Untrusted Pointer Dereference7.8 HighN/A1%Oct 8, 2024
CVE-2024-8926: Improper Neutralization of Special Elements used in an OS Command8.1 HighN/A4%Oct 8, 2024
CVE-2024-25707: Improper Neutralization of Input During Web Page Generation4.8 MediumN/A0%Oct 4, 2024
CVE-2024-0125: NULL Pointer Dereference3.3 LowN/A0%Oct 3, 2024
CVE-2024-0124: Use After Free3.3 LowN/A0%Oct 3, 2024
CVE-2024-0123: Improper Validation of Specified Index, Position, or Offset in Input3.3 LowN/A0%Oct 3, 2024
CVE-2024-47611: Improper Neutralization of Argument Delimiters in a CommandN/A6.3 Medium1%Oct 2, 2024
CVE-2024-8885: Use of Unmaintained Third Party Components8.8 HighN/A0%Oct 2, 2024
CVE-2024-9194: Improper Neutralization of Special Elements used in an SQL Command9.8 Critical8.7 High0%Sep 30, 2024
CVE-2024-7400: Insecure Operation on Windows Junction / Mount PointN/A8.5 High0%Sep 27, 2024
CVE-2024-6769: Untrusted Search Path6.7 Medium8.4 High1%Sep 26, 2024
CVE-2024-8405: Improper Neutralization of Special Elements used in a Command6.1 MediumN/A0%Sep 26, 2024
CVE-2024-8404: Improper Link Resolution Before File Access7.8 HighN/A0%Sep 26, 2024
CVE-2024-45750: Improper Authentication7.3 HighN/A1%Sep 25, 2024
CVE-2024-8996: Unquoted Search Path or Element7.3 HighN/A0%Sep 25, 2024
CVE-2024-8975: Unquoted Search Path or Element7.3 HighN/A0%Sep 25, 2024
CVE-2024-7421: Insertion of Sensitive Information into Log File5.5 MediumN/A0%Sep 25, 2024
CVE-2024-6594: Improper Handling of Exceptional Conditions7.5 High8.7 High1%Sep 25, 2024
CVE-2024-6593: Incorrect Authorization9.1 Critical9.3 Critical1%Sep 25, 2024
CVE-2024-6592: Missing Authentication for Critical Function9.1 Critical9.3 Critical1%Sep 25, 2024
CVE-2024-7481: Improper Verification of Cryptographic Signature8.8 HighN/A0%Sep 25, 2024
CVE-2024-7479: Improper Verification of Cryptographic Signature8.8 HighN/A0%Sep 25, 2024
CVE-2024-9120: Use After Free8.8 HighN/A0%Sep 25, 2024
4301-4325 of 16013