The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
TitleEitWModules
CVE-2020-5002: Improper Input Validation4.3 MediumN/A0%Mar 1, 2023
CVE-2020-5001: Improper Limitation of a Pathname to a Restricted Directory4.3 MediumN/A0%Mar 1, 2023
CVE-2020-36652: Incorrect Default Permissions6.6 MediumN/A0%Feb 28, 2023
CVE-2020-9846: Exposure of Sensitive Information to an Unauthorized Actor5.3 MediumN/A0%Feb 27, 2023
CVE-2020-36656: Improper Neutralization of Input During Web Page Generation5.4 MediumN/A0%Feb 21, 2023
CVE-2020-29168: Improper Neutralization of Special Elements used in an SQL Command9.8 CriticalN/A0%Feb 17, 2023
CVE-2020-19824: Concurrent Execution using Shared Resource with Improper Synchronization7.0 HighN/A0%Feb 17, 2023
CVE-2020-6817: Inefficient Regular Expression Complexity7.5 HighN/A0%Feb 16, 2023
CVE-2020-12413: Observable Discrepancy5.9 MediumN/A0%Feb 16, 2023
CVE-2020-21119: Improper Neutralization of Special Elements used in an SQL Command9.8 CriticalN/A0%Feb 15, 2023
CVE-2020-21120: Improper Neutralization of Special Elements used in an SQL Command9.8 CriticalN/A0%Feb 15, 2023
CVE-2020-19825: Improper Neutralization of Input During Web Page Generation9.6 CriticalN/A0%Feb 15, 2023
CVE-2020-36661: Inefficient Regular Expression Complexity3.5 LowN/A0%Feb 12, 2023
CVE-2020-27834: Undefined Security Weakness9.8 CriticalN/AN/AFeb 12, 2023
CVE-2020-36660: Exposure of Sensitive Information to an Unauthorized Actor4.3 MediumN/A0%Feb 6, 2023
CVE-2020-24307: Improper Privilege Management7.8 HighN/A0%Feb 2, 2023
CVE-2020-14395: Undefined Security Weakness9.8 CriticalN/AN/AFeb 1, 2023
CVE-2020-20402: Improper Authentication7.5 HighN/A0%Jan 31, 2023
CVE-2020-36658: Improper Certificate Validation8.1 HighN/A0%Jan 27, 2023
CVE-2020-36659: Improper Certificate Validation8.1 HighN/A0%Jan 27, 2023
CVE-2020-22452: Improper Neutralization of Special Elements used in an SQL Command9.8 CriticalN/A2%Jan 26, 2023
CVE-2020-22327: Improper Neutralization of Input During Web Page Generation6.1 MediumN/A0%Jan 26, 2023
CVE-2020-18329: Improper Preservation of Permissions7.5 HighN/A0%Jan 25, 2023
CVE-2020-18330: Improper Limitation of a Pathname to a Restricted Directory9.1 CriticalN/A0%Jan 25, 2023
CVE-2020-18331: Improper Limitation of a Pathname to a Restricted Directory9.1 CriticalN/A1%Jan 25, 2023
1151-1175 of 21077