The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
TitleEitWModules
CVE-2020-36847: Unrestricted Upload of File with Dangerous Type9.8 CriticalN/A87%Jul 12, 2025
CVE-2020-36846: Dependency on Vulnerable Third-Party Component9.8 CriticalN/A0%May 30, 2025
CVE-2020-36791: Out-of-bounds Read7.8 HighN/A0%May 7, 2025
CVE-2020-36790: Missing Release of Memory after Effective Lifetime5.5 MediumN/A0%May 1, 2025
CVE-2020-36845: URL Redirection to Untrusted Site5.3 MediumN/A0%Apr 20, 2025
CVE-2020-36844: Improper Neutralization of Input During Web Page Generation6.1 MediumN/A0%Apr 20, 2025
CVE-2020-36789: NULL Pointer Dereference5.5 MediumN/A0%Apr 17, 2025
CVE-2020-18243: Improper Neutralization of Special Elements used in an SQL Command6.5 MediumN/A0%Apr 15, 2025
CVE-2020-6645: Undefined Security WeaknessN/AN/AN/AMar 17, 2025
CVE-2020-9295: Improperly Implemented Security Check for Standard4.7 MediumN/A0%Mar 17, 2025
CVE-2020-29010: Exposure of Sensitive Information to an Unauthorized Actor5.0 MediumN/A0%Mar 17, 2025
CVE-2020-36843: Improper Verification of Cryptographic Signature4.3 MediumN/A0%Mar 13, 2025
CVE-2020-23438: Uncontrolled Search Path Element7.8 HighN/A0%Mar 4, 2025
CVE-2020-3122: Improper Access Control5.3 MediumN/A0%Mar 4, 2025
CVE-2020-19248: Improper Neutralization of Special Elements used in an SQL Command5.1 MediumN/A0%Feb 21, 2025
CVE-2020-6158: Authentication Bypass by Spoofing4.7 MediumN/A0%Feb 21, 2025
CVE-2020-13481: Exposure of Sensitive Information to an Unauthorized Actor6.1 MediumN/A0%Feb 19, 2025
CVE-2020-10095: Cross-Site Request Forgery (CSRF)8.1 HighN/A0%Feb 19, 2025
CVE-2020-35546: Improper Access ControlN/AN/A0%Feb 19, 2025
CVE-2020-3432: Improper Link Resolution Before File Access5.6 MediumN/A0%Feb 12, 2025
CVE-2020-36085: Improper Neutralization of Input During Web Page Generation6.3 MediumN/A0%Feb 6, 2025
CVE-2020-36084: Improper Neutralization of Special Elements used in an SQL Command9.8 CriticalN/A0%Feb 5, 2025
CVE-2020-11936: Undefined Security Weakness3.1 LowN/A0%Jan 31, 2025
CVE-2020-0436: Undefined Security WeaknessN/AN/AN/AJan 18, 2025
CVE-2020-0040: Undefined Security WeaknessN/AN/AN/AJan 18, 2025
476-500 of 21077