The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
TitleEitWModules
CVE-2024-12946: Improper Neutralization of Special Elements used in an SQL Command7.3 High6.9 Medium1%Dec 26, 2024
CVE-2024-12945: Improper Neutralization of Special Elements used in an SQL Command7.3 High6.9 Medium1%Dec 26, 2024
CVE-2024-56433: Initialization of a Resource with an Insecure Default3.6 LowN/A0%Dec 26, 2024
CVE-2024-12944: Improper Neutralization of Special Elements used in an SQL Command7.3 High6.9 Medium1%Dec 26, 2024
CVE-2024-12943: Improper Neutralization of Special Elements used in an SQL Command7.3 High6.9 Medium1%Dec 26, 2024
CVE-2023-7300: Path Traversal: '.../...//'8.0 HighN/A0%Dec 26, 2024
CVE-2024-12942: Improper Neutralization of Special Elements used in an SQL Command7.3 High6.9 Medium1%Dec 26, 2024
CVE-2024-12941: Improper Neutralization of Special Elements used in an SQL Command6.3 Medium5.3 Medium0%Dec 26, 2024
CVE-2024-12940: Improper Neutralization of Special Elements used in an SQL Command7.3 High6.9 Medium1%Dec 26, 2024
CVE-2024-12939: Improper Neutralization of Special Elements used in an SQL Command6.3 Medium5.3 Medium0%Dec 26, 2024
CVE-2024-12938: Improper Neutralization of Special Elements used in an SQL Command6.3 Medium5.3 Medium1%Dec 26, 2024
CVE-2024-12937: Improper Neutralization of Special Elements used in an SQL Command6.3 Medium5.3 Medium1%Dec 26, 2024
CVE-2024-11223: Improper Neutralization of Input During Web Page Generation4.7 MediumN/A1%Dec 26, 2024
CVE-2024-10903: Server-Side Request Forgery (SSRF)4.7 MediumN/A0%Dec 26, 2024
CVE-2024-12936: Improper Neutralization of Special Elements used in an SQL Command6.3 Medium5.3 Medium1%Dec 26, 2024
CVE-2024-12935: Improper Neutralization of Special Elements used in an SQL Command6.3 Medium5.3 Medium1%Dec 26, 2024
CVE-2024-12934: Improper Neutralization of Special Elements used in an SQL Command6.3 Medium5.3 Medium0%Dec 26, 2024
CVE-2024-12933: Improper Neutralization of Input During Web Page Generation3.5 Low5.3 Medium0%Dec 26, 2024
CVE-2024-12652: Improper Control of Generation of Code8.8 High9.3 Critical1%Dec 26, 2024
CVE-2024-12932: Improper Neutralization of Input During Web Page Generation3.5 Low5.3 Medium0%Dec 26, 2024
CVE-2024-12931: Improper Neutralization of Special Elements used in an SQL Command6.3 Medium5.3 Medium1%Dec 26, 2024
CVE-2024-12930: Improper Neutralization of Input During Web Page Generation3.5 Low5.3 Medium0%Dec 26, 2024
CVE-2024-12929: Improper Neutralization of Special Elements used in an SQL Command6.3 Medium5.3 Medium0%Dec 26, 2024
CVE-2024-12928: Improper Neutralization of Special Elements used in an SQL Command6.3 Medium5.3 Medium0%Dec 26, 2024
CVE-2024-12927: Improper Neutralization of Special Elements used in an SQL Command7.3 High6.9 Medium1%Dec 25, 2024
122326-122350 of 559420