The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
TitleEitWModules
CVE-2024-30073: Improper Resolution of Path Equivalence7.8 HighN/A1%Sep 10, 2024
CVE-2024-21416: Heap-based Buffer Overflow9.8 CriticalN/A1%Sep 10, 2024
CVE-2024-43495: Integer Overflow or Wraparound7.3 HighN/A1%Sep 10, 2024
CVE-2024-43491: Use After Free9.8 CriticalN/A12%Sep 10, 2024
CVE-2024-43458: Use of Uninitialized Resource7.7 HighN/A2%Sep 10, 2024
CVE-2024-43457: Unquoted Search Path or Element7.8 HighN/A1%Sep 10, 2024
CVE-2024-38233: NULL Pointer Dereference7.5 HighN/A2%Sep 10, 2024
CVE-2024-38232: NULL Pointer Dereference7.5 HighN/A2%Sep 10, 2024
CVE-2024-31489: Improper Certificate Validation6.8 MediumN/A0%Sep 10, 2024
CVE-2022-45856: Improper Certificate Validation4.8 MediumN/A0%Sep 10, 2024
CVE-2024-36138: Improper Neutralization of Special Elements used in a Command8.1 HighN/A1%Sep 7, 2024
CVE-2022-27592: Unquoted Search Path or Element6.7 MediumN/A0%Sep 6, 2024
CVE-2024-43402: Improper Neutralization of Special Elements used in an OS Command8.1 HighN/A1%Sep 4, 2024
CVE-2024-38456: Incorrect Permission Assignment for Critical Resource7.8 HighN/A0%Sep 3, 2024
CVE-2024-8260: Authentication Bypass by Capture-replay6.1 MediumN/A0%Aug 30, 2024
CVE-2024-2881: Improper Restriction of Software Interfaces to Hardware Features6.7 MediumN/A0%Aug 30, 2024
CVE-2024-1545: Improper Restriction of Software Interfaces to Hardware Features5.9 MediumN/A1%Aug 29, 2024
CVE-2024-43033: Improper Handling of Windows ::DATA Alternate Data Stream8.8 HighN/A1%Aug 22, 2024
CVE-2024-8035: Improper Neutralization of Input During Web Page Generation4.3 MediumN/A0%Aug 21, 2024
CVE-2024-8033: Undefined Security Weakness4.3 MediumN/A0%Aug 21, 2024
CVE-2024-7980: Insufficient Verification of Data Authenticity7.8 HighN/A0%Aug 21, 2024
CVE-2024-7979: Insufficient Verification of Data Authenticity7.8 HighN/A0%Aug 21, 2024
CVE-2024-7977: Improper Input Validation7.8 HighN/A0%Aug 21, 2024
CVE-2022-26328: Improper Neutralization of Input During Web Page GenerationN/A2.0 Low0%Aug 21, 2024
CVE-2022-26327: Exposure of Sensitive Information to an Unauthorized ActorN/A5.1 Medium1%Aug 21, 2024
4376-4400 of 16013