The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
TitleEitWModules
CVE-2015-5395: Cross-Site Request Forgery (CSRF)8.8 HighN/A0%Sep 20, 2017
CVE-2015-4707: Improper Neutralization of Input During Web Page Generation6.1 MediumN/A1%Sep 20, 2017
CVE-2015-3890: Use After Free7.5 HighN/A0%Sep 20, 2017
CVE-2015-2927: Undefined Security Weakness6.5 MediumN/A1%Sep 20, 2017
CVE-2015-2826: Exposure of Sensitive Information to an Unauthorized Actor5.3 MediumN/A43%Sep 20, 2017
CVE-2015-1866: Improper Neutralization of Input During Web Page Generation6.1 MediumN/A0%Sep 20, 2017
CVE-2015-1865: Concurrent Execution using Shared Resource with Improper Synchronization5.1 MediumN/A0%Sep 20, 2017
CVE-2015-0162: Undefined Security Weakness7.0 HighN/A0%Sep 20, 2017
CVE-2015-8224: Exposure of Sensitive Information to an Unauthorized Actor3.7 LowN/A0%Sep 20, 2017
CVE-2015-5607: Cross-Site Request Forgery (CSRF)8.8 HighN/A0%Sep 20, 2017
CVE-2015-5248: Improper Input Validation6.5 MediumN/A0%Sep 20, 2017
CVE-2015-5179: Improper Input Validation7.5 HighN/A0%Sep 20, 2017
CVE-2015-4075: Improper Neutralization of Special Elements in Output Used by a Downstream Component8.1 HighN/A17%Sep 20, 2017
CVE-2015-4074: Improper Limitation of a Pathname to a Restricted Directory7.5 HighN/A86%Sep 20, 2017
CVE-2015-4073: Improper Neutralization of Special Elements used in an SQL Command9.8 CriticalN/A10%Sep 20, 2017
CVE-2015-4072: Improper Neutralization of Input During Web Page Generation5.4 MediumN/A0%Sep 20, 2017
CVE-2015-1329: Use After Free8.8 HighN/A2%Sep 20, 2017
CVE-2015-4685: Undefined Security Weakness7.0 HighN/A0%Sep 19, 2017
CVE-2015-4684: Undefined Security Weakness6.5 MediumN/A11%Sep 19, 2017
CVE-2015-4683: Undefined Security Weakness9.8 CriticalN/A34%Sep 19, 2017
CVE-2015-4682: Exposure of Sensitive Information to an Unauthorized Actor6.5 MediumN/A12%Sep 19, 2017
CVE-2015-4681: Undefined Security Weakness7.8 HighN/A1%Sep 19, 2017
CVE-2015-1849: Exposure of Sensitive Information to an Unauthorized Actor5.9 MediumN/A0%Sep 19, 2017
CVE-2015-7837: Undefined Security Weakness5.5 MediumN/A0%Sep 19, 2017
CVE-2015-4089: Cross-Site Request Forgery (CSRF)8.8 HighN/A0%Sep 19, 2017
1201-1225 of 8780