The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
TitleEitWModules
CVE-2024-42004: Improper Verification of Cryptographic Signature7.1 HighN/A1%Dec 18, 2024
CVE-2024-41165: Improper Verification of Cryptographic Signature7.1 HighN/A1%Dec 18, 2024
CVE-2024-41159: Improper Verification of Cryptographic Signature7.1 HighN/A1%Dec 18, 2024
CVE-2024-41145: Improper Verification of Cryptographic Signature7.1 HighN/A1%Dec 18, 2024
CVE-2024-41138: Improper Verification of Cryptographic Signature7.1 HighN/A1%Dec 18, 2024
CVE-2024-39804: Improper Verification of Cryptographic Signature7.1 HighN/A1%Dec 18, 2024
CVE-2024-37649: Improper Preservation of Permissions4.6 MediumN/A0%Dec 18, 2024
CVE-2022-40733: NULL Pointer Dereference5.0 MediumN/A1%Dec 18, 2024
CVE-2022-40732: NULL Pointer Dereference5.0 MediumN/A1%Dec 18, 2024
CVE-2024-55505: Improper Control of Generation of Code8.8 HighN/A1%Dec 18, 2024
CVE-2024-55232: Authentication Bypass by Spoofing5.4 MediumN/A0%Dec 18, 2024
CVE-2024-55231: Authorization Bypass Through User-Controlled Key4.3 MediumN/A0%Dec 18, 2024
CVE-2024-12695: Out-of-bounds Write8.8 HighN/A0%Dec 18, 2024
CVE-2024-12694: Use After Free8.8 HighN/A0%Dec 18, 2024
CVE-2024-12693: Out-of-bounds Write8.8 HighN/A0%Dec 18, 2024
CVE-2024-12692: Access of Resource Using Incompatible Type8.8 HighN/A7%Dec 18, 2024
CVE-2024-56145: Improper Control of Generation of Code9.8 Critical9.3 Critical97%Dec 18, 2024
CVE-2024-56140: Cross-Site Request Forgery (CSRF)5.9 MediumN/A0%Dec 18, 2024
CVE-2024-45338: Inefficient Regular Expression Complexity5.3 MediumN/A1%Dec 18, 2024
CVE-2024-12686: Improper Neutralization of Special Elements used in an OS Command6.6 MediumN/A14%Dec 18, 2024
CVE-2024-53271: Always-Incorrect Control Flow Implementation7.1 HighN/A1%Dec 18, 2024
CVE-2024-53270: Always-Incorrect Control Flow Implementation7.5 HighN/A1%Dec 18, 2024
CVE-2024-53269: Always-Incorrect Control Flow Implementation4.5 MediumN/A1%Dec 18, 2024
CVE-2024-52593: Improper Input Validation5.3 Medium5.1 Medium0%Dec 18, 2024
CVE-2024-52592: Improper Input Validation5.3 Medium6.9 Medium0%Dec 18, 2024
122651-122675 of 395809