The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
TitleEitWModules
CVE-2015-5182: Cross-Site Request Forgery (CSRF)8.8 HighN/A0%Sep 25, 2017
CVE-2015-5181: Improper Neutralization of Input During Web Page Generation5.4 MediumN/A0%Sep 25, 2017
CVE-2015-5169: Improper Neutralization of Input During Web Page Generation6.1 MediumN/A1%Sep 25, 2017
CVE-2015-7318: Improper Input Validation7.5 HighN/A0%Sep 25, 2017
CVE-2015-7317: Undefined Security Weakness6.8 MediumN/A0%Sep 25, 2017
CVE-2015-7316: Improper Neutralization of Input During Web Page Generation6.1 MediumN/A1%Sep 25, 2017
CVE-2015-7315: Improper Access Control5.9 MediumN/A0%Sep 25, 2017
CVE-2015-6748: Improper Neutralization of Input During Web Page Generation6.1 MediumN/A2%Sep 25, 2017
CVE-2015-5282: Improper Neutralization of Input During Web Page Generation6.1 MediumN/A0%Sep 25, 2017
CVE-2015-5237: Out-of-bounds Write8.8 HighN/A1%Sep 25, 2017
CVE-2015-4669: Improper Neutralization of Special Elements used in an SQL Command7.8 HighN/A0%Sep 25, 2017
CVE-2015-4668: URL Redirection to Untrusted Site6.1 MediumN/A4%Sep 25, 2017
CVE-2015-4667: Use of Hard-coded Credentials9.8 CriticalN/A24%Sep 25, 2017
CVE-2015-3887: Untrusted Search Path7.8 HighN/A0%Sep 21, 2017
CVE-2015-1187: Improper Authentication9.8 CriticalN/A81%Sep 21, 2017
CVE-2015-8559: Exposure of Sensitive Information to an Unauthorized Actor7.5 HighN/A0%Sep 21, 2017
CVE-2015-5284: Exposure of Sensitive Information to an Unauthorized Actor9.8 CriticalN/A0%Sep 21, 2017
CVE-2015-4706: Improper Neutralization of Input During Web Page Generation6.1 MediumN/A1%Sep 21, 2017
CVE-2015-3296: Improper Neutralization of Input During Web Page Generation6.1 MediumN/A0%Sep 21, 2017
CVE-2015-0276: Cross-Site Request Forgery (CSRF)8.8 HighN/A0%Sep 21, 2017
CVE-2015-9232: Insufficient Verification of Data Authenticity5.3 MediumN/A0%Sep 20, 2017
CVE-2015-9231: Exposure of Sensitive Information to an Unauthorized Actor7.5 HighN/A1%Sep 20, 2017
CVE-2015-7347: Improper Neutralization of Input During Web Page Generation4.8 MediumN/A0%Sep 20, 2017
CVE-2015-6673: Use After Free9.8 CriticalN/A1%Sep 20, 2017
CVE-2015-5608: URL Redirection to Untrusted Site6.1 MediumN/A0%Sep 20, 2017
1176-1200 of 8780