The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
TitleEitWModules
CVE-2015-7667: Improper Neutralization of Input During Web Page Generation6.1 MediumN/A0%Dec 27, 2017
CVE-2015-7666: Improper Neutralization of Input During Web Page Generation6.1 MediumN/A1%Dec 27, 2017
CVE-2015-7324: Improper Neutralization of Input During Web Page Generation6.1 MediumN/A0%Dec 27, 2017
CVE-2015-6237: Improper Authentication9.8 CriticalN/A1%Dec 27, 2017
CVE-2015-7224: Improper Authentication9.8 CriticalN/A1%Dec 21, 2017
CVE-2015-4100: Improper Certificate Validation6.8 MediumN/A0%Dec 21, 2017
CVE-2015-8470: Exposure of Sensitive Information to an Unauthorized Actor6.5 MediumN/A0%Dec 11, 2017
CVE-2015-6502: Improper Neutralization of Input During Web Page Generation6.1 MediumN/A0%Dec 11, 2017
CVE-2015-7269: Undefined Security Weakness4.2 MediumN/A0%Nov 27, 2017
CVE-2015-7268: Undefined Security Weakness4.2 MediumN/A0%Nov 27, 2017
CVE-2015-7267: Undefined Security Weakness4.2 MediumN/A0%Nov 27, 2017
CVE-2015-3934: Improper Neutralization of Special Elements used in an SQL Command9.8 CriticalN/A1%Nov 21, 2017
CVE-2015-7501: Deserialization of Untrusted Data9.8 CriticalN/A71%Nov 9, 2017
CVE-2015-3933: Improper Neutralization of Special Elements used in an SQL Command9.8 CriticalN/A2%Nov 8, 2017
CVE-2015-7878: Improper Neutralization of Input During Web Page Generation5.4 MediumN/A0%Nov 6, 2017
CVE-2015-7529: Improper Link Resolution Before File Access7.8 HighN/A0%Nov 6, 2017
CVE-2015-9245: Improper Access Control9.8 CriticalN/A0%Oct 31, 2017
CVE-2015-7549: NULL Pointer Dereference6.0 MediumN/A0%Oct 30, 2017
CVE-2015-3249: Improper Restriction of Operations within the Bounds of a Memory Buffer9.8 CriticalN/A4%Oct 30, 2017
CVE-2015-0226: Use of a Broken or Risky Cryptographic Algorithm7.5 HighN/A5%Oct 30, 2017
CVE-2015-0224: Undefined Security Weakness7.5 HighN/A57%Oct 30, 2017
CVE-2015-1835: Improper Input Validation5.3 MediumN/A1%Oct 27, 2017
CVE-2015-5173: Exposure of Sensitive Information to an Unauthorized Actor8.8 HighN/A0%Oct 24, 2017
CVE-2015-5172: Weak Password Recovery Mechanism for Forgotten Password9.8 CriticalN/A0%Oct 24, 2017
CVE-2015-5171: Insufficient Session Expiration9.8 CriticalN/A0%Oct 24, 2017
1051-1075 of 8780