The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
TitleEitWModules
CVE-2015-5170: Cross-Site Request Forgery (CSRF)8.8 HighN/A0%Oct 24, 2017
CVE-2015-6839: Improper Input Validation4.6 MediumN/A0%Oct 23, 2017
CVE-2015-5533: Improper Neutralization of Special Elements used in an SQL Command7.2 HighN/A10%Oct 23, 2017
CVE-2015-5532: Improper Neutralization of Input During Web Page Generation6.1 MediumN/A1%Oct 23, 2017
CVE-2015-5379: Improper Neutralization of Input During Web Page Generation5.4 MediumN/A0%Oct 23, 2017
CVE-2015-2878: Cross-Site Request Forgery (CSRF)8.8 HighN/A0%Oct 23, 2017
CVE-2015-5699: Undefined Security Weakness7.8 HighN/A0%Oct 22, 2017
CVE-2015-5177: Double Free7.5 HighN/A1%Oct 22, 2017
CVE-2015-6668: Exposure of Sensitive Information to an Unauthorized Actor7.5 HighN/A86%Oct 19, 2017
CVE-2015-4422: Improper Restriction of Operations within the Bounds of a Memory Buffer7.0 HighN/A0%Oct 19, 2017
CVE-2015-4421: Improper Restriction of Operations within the Bounds of a Memory Buffer7.5 HighN/A0%Oct 19, 2017
CVE-2015-6961: URL Redirection to Untrusted Site6.1 MediumN/A0%Oct 18, 2017
CVE-2015-5740: Inconsistent Interpretation of HTTP Requests9.8 CriticalN/A4%Oct 18, 2017
CVE-2015-5739: Inconsistent Interpretation of HTTP Requests9.8 CriticalN/A19%Oct 18, 2017
CVE-2015-5376: Improper Neutralization of Special Elements used in an SQL Command9.8 CriticalN/A0%Oct 18, 2017
CVE-2015-5227: Improper Neutralization of Special Elements in Output Used by a Downstream Component8.8 HighN/A2%Oct 18, 2017
CVE-2015-7943: URL Redirection to Untrusted Site6.1 MediumN/A1%Oct 18, 2017
CVE-2015-7715: Cross-Site Request Forgery (CSRF)8.8 HighN/A0%Oct 18, 2017
CVE-2015-7714: Improper Neutralization of Special Elements used in an SQL Command7.2 HighN/A3%Oct 18, 2017
CVE-2015-1239: Double Free6.5 MediumN/A1%Oct 18, 2017
CVE-2015-5164: Deserialization of Untrusted Data7.2 HighN/A2%Oct 18, 2017
CVE-2015-3400: Exposure of Sensitive Information to an Unauthorized Actor4.3 MediumN/A0%Oct 18, 2017
CVE-2015-2156: Improper Input Validation7.5 HighN/A3%Oct 18, 2017
CVE-2015-7806: Improper Neutralization of Special Elements used in a Command9.8 CriticalN/A14%Oct 17, 2017
CVE-2015-7504: Out-of-bounds Write8.8 HighN/A1%Oct 16, 2017
1076-1100 of 8780