The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
TitleEitWModules
CVE-2024-53476: Concurrent Execution using Shared Resource with Improper Synchronization5.9 MediumN/A1%Dec 27, 2024
CVE-2024-50945: Improper Access Control7.5 HighN/A1%Dec 27, 2024
CVE-2024-50944: Integer Overflow or Wraparound9.8 CriticalN/A1%Dec 27, 2024
CVE-2024-12990: URL Redirection to Untrusted Site4.3 Medium5.3 Medium0%Dec 27, 2024
CVE-2024-12989: Server-Side Request Forgery (SSRF)5.3 Medium6.9 Medium0%Dec 27, 2024
CVE-2024-12988: Buffer Copy without Checking Size of Input7.3 High6.9 Medium1%Dec 27, 2024
CVE-2024-56509: Exposure of Sensitive Information to an Unauthorized Actor8.6 HighN/A1%Dec 27, 2024
CVE-2024-56508: Unrestricted Upload of File with Dangerous Type7.6 HighN/A0%Dec 27, 2024
CVE-2024-56507: Improper Neutralization of Input During Web Page Generation4.6 MediumN/A0%Dec 27, 2024
CVE-2024-12987: Improper Neutralization of Special Elements used in an OS Command7.3 High6.9 Medium98%Dec 27, 2024
CVE-2024-12986: Improper Neutralization of Special Elements used in an OS Command7.3 High6.9 Medium33%Dec 27, 2024
CVE-2024-12856: Improper Neutralization of Special Elements used in an OS Command7.2 HighN/A84%Dec 27, 2024
CVE-2024-56657: Undefined Security Weakness5.5 MediumN/A0%Dec 27, 2024
CVE-2024-56647: Undefined Security Weakness5.5 MediumN/A0%Dec 27, 2024
CVE-2024-56639: Undefined Security Weakness5.5 MediumN/A0%Dec 27, 2024
CVE-2024-56571: Undefined Security WeaknessN/AN/AN/ADec 27, 2024
CVE-2024-12985: Improper Neutralization of Special Elements used in an OS Command6.3 Medium5.3 Medium2%Dec 27, 2024
CVE-2024-12984: Exposure of Sensitive Information to an Unauthorized Actor5.3 Medium6.9 Medium1%Dec 27, 2024
CVE-2024-56675: Use After Free7.8 HighN/A0%Dec 27, 2024
CVE-2024-56674: Operation on a Resource after Expiration or Release5.5 MediumN/A0%Dec 27, 2024
CVE-2024-56673: Undefined Security Weakness5.5 MediumN/A0%Dec 27, 2024
CVE-2024-56672: Use After Free7.8 HighN/A0%Dec 27, 2024
CVE-2024-56671: Undefined Security Weakness5.5 MediumN/A0%Dec 27, 2024
CVE-2024-56670: NULL Pointer Dereference5.5 MediumN/A0%Dec 27, 2024
CVE-2024-56669: Missing Release of Memory after Effective Lifetime8.8 HighN/A0%Dec 27, 2024
122101-122125 of 552652