The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
TitleEitWModules
CVE-2024-38519: Incorrect Resource Transfer Between Spheres7.8 HighN/A0%Jul 2, 2024
CVE-2024-4679: Incorrect Default Permissions7.8 HighN/A0%Jul 2, 2024
CVE-2024-38472: Server-Side Request Forgery (SSRF)7.5 HighN/A69%Jul 1, 2024
CVE-2024-36991: Path Traversal: '.../...//'7.5 HighN/A13%Jul 1, 2024
CVE-2024-24749: Improper Limitation of a Pathname to a Restricted Directory7.5 HighN/A1%Jul 1, 2024
CVE-2024-6250: Absolute Path Traversal7.5 HighN/A2%Jun 27, 2024
CVE-2024-3330: Execution with Unnecessary Privileges9.9 CriticalN/A1%Jun 27, 2024
CVE-2024-6354: Improper Access Control for Register Interface7.2 HighN/A1%Jun 26, 2024
CVE-2024-38272: Authentication Bypass by Capture-replay4.3 Medium7.1 High0%Jun 26, 2024
CVE-2024-5012: Improper Authentication8.6 HighN/A0%Jun 25, 2024
CVE-2024-36071: Untrusted Search Path6.3 MediumN/A0%Jun 20, 2024
CVE-2024-22002: Exposure of Sensitive Information to an Unauthorized Actor7.8 HighN/A0%Jun 18, 2024
CVE-2024-6055: Improper Removal of Sensitive Information Before Storage or Transfer4.7 MediumN/A0%Jun 17, 2024
CVE-2024-0095: Improper Output Neutralization for Logs9.0 CriticalN/A1%Jun 13, 2024
CVE-2024-0092: Improper Check or Handling of Exceptional Conditions5.5 MediumN/A0%Jun 13, 2024
CVE-2024-0091: Untrusted Pointer Dereference7.8 HighN/A0%Jun 13, 2024
CVE-2024-0090: Out-of-bounds Write7.8 HighN/A0%Jun 13, 2024
CVE-2024-0089: Improper Initialization7.8 HighN/A0%Jun 13, 2024
CVE-2024-0085: Incorrect Privilege Assignment6.3 MediumN/A0%Jun 13, 2024
CVE-2024-31881: Allocation of Resources Without Limits or Throttling6.5 MediumN/A1%Jun 12, 2024
CVE-2023-29267: Undefined Security Weakness5.3 MediumN/A1%Jun 12, 2024
CVE-2024-28762: Allocation of Resources Without Limits or Throttling5.3 MediumN/A1%Jun 12, 2024
CVE-2024-5909: Improper Privilege Management5.5 Medium6.8 Medium0%Jun 12, 2024
CVE-2024-5907: Improper Privilege Management7.0 High5.2 Medium0%Jun 12, 2024
CVE-2024-5905: Origin Validation Error4.4 Medium2.0 Low0%Jun 12, 2024
4576-4600 of 16013