The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
TitleEitWModules
CVE-2024-11287: Improper Neutralization of Input During Web Page Generation6.1 MediumN/A0%Dec 21, 2024
CVE-2024-11196: Improper Neutralization of Input During Web Page Generation6.4 MediumN/A0%Dec 21, 2024
CVE-2024-11977: Improper Control of Generation of Code7.3 HighN/A1%Dec 21, 2024
CVE-2024-11607: Cross-Site Request Forgery (CSRF)6.1 MediumN/A0%Dec 21, 2024
CVE-2024-12846: Improper Neutralization of Input During Web Page Generation4.3 Medium6.9 Medium0%Dec 21, 2024
CVE-2024-11349: Authentication Bypass Using an Alternate Path or Channel9.8 CriticalN/A1%Dec 21, 2024
CVE-2023-31280: Exposure of Sensitive Information to an Unauthorized Actor5.3 MediumN/A0%Dec 21, 2024
CVE-2023-31279: Improper Authentication8.1 HighN/A0%Dec 21, 2024
CVE-2024-11811: Improper Neutralization of Input During Web Page Generation6.1 MediumN/A0%Dec 20, 2024
CVE-2024-12845: Improper Neutralization of Input During Web Page Generation3.5 Low5.3 Medium0%Dec 20, 2024
CVE-2021-40959: Improper Neutralization of Input During Web Page Generation6.1 MediumN/A0%Dec 20, 2024
CVE-2020-13712: Improper Neutralization of Special Elements used in an OS Command7.8 HighN/A1%Dec 20, 2024
CVE-2024-56359: Improper Neutralization of Input During Web Page Generation8.1 HighN/A0%Dec 20, 2024
CVE-2024-56358: Improper Neutralization of Input During Web Page Generation8.1 HighN/A0%Dec 20, 2024
CVE-2024-56357: Improper Neutralization of Input During Web Page Generation8.1 HighN/A0%Dec 20, 2024
CVE-2024-56335: Improper Privilege Management7.6 HighN/A0%Dec 20, 2024
CVE-2024-56334: Improper Control of Generation of Code7.8 HighN/A1%Dec 20, 2024
CVE-2024-55509: Improper Neutralization of Special Elements used in an SQL Command9.8 CriticalN/A1%Dec 20, 2024
CVE-2024-40875: Improper Neutralization of Input During Web Page GenerationN/A5.9 Medium0%Dec 20, 2024
CVE-2024-12844: Improper Neutralization of Input During Web Page Generation4.3 Medium6.9 Medium0%Dec 20, 2024
CVE-2024-12843: Improper Neutralization of Input During Web Page Generation4.3 Medium6.9 Medium0%Dec 20, 2024
CVE-2024-56333: Improper Control of Generation of CodeN/A9.4 Critical1%Dec 20, 2024
CVE-2024-56331: Improper Limitation of a Pathname to a Restricted Directory6.8 MediumN/A2%Dec 20, 2024
CVE-2024-56330: Improper Access ControlN/A9.3 Critical0%Dec 20, 2024
CVE-2024-56329: Improper AuthenticationN/A8.9 High1%Dec 20, 2024
122476-122500 of 559420