The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
TitleEitWModules
CVE-2024-12197: Out-of-bounds Write7.8 HighN/A0%Dec 17, 2024
CVE-2024-12194: Buffer Copy without Checking Size of Input7.8 HighN/A0%Dec 17, 2024
CVE-2024-12193: Out-of-bounds Write7.8 HighN/A0%Dec 17, 2024
CVE-2024-12192: Out-of-bounds Write7.8 HighN/A0%Dec 17, 2024
CVE-2024-12191: Out-of-bounds Write7.8 HighN/A0%Dec 17, 2024
CVE-2024-12179: Heap-based Buffer Overflow7.8 HighN/A0%Dec 17, 2024
CVE-2024-12178: Out-of-bounds Write7.8 HighN/A0%Dec 17, 2024
CVE-2024-11422: Out-of-bounds Write7.8 HighN/A0%Dec 17, 2024
CVE-2024-10476: Use of Default Credentials8.0 HighN/A0%Dec 17, 2024
CVE-2024-53144: Undefined Security Weakness8.8 HighN/A0%Dec 17, 2024
CVE-2024-37607: Buffer Copy without Checking Size of Input6.5 MediumN/A1%Dec 17, 2024
CVE-2024-37606: Buffer Copy without Checking Size of Input6.5 MediumN/A1%Dec 17, 2024
CVE-2024-37605: NULL Pointer Dereference6.5 MediumN/A1%Dec 17, 2024
CVE-2024-36832: NULL Pointer Dereference7.5 HighN/A0%Dec 17, 2024
CVE-2024-36831: NULL Pointer Dereference5.3 MediumN/A1%Dec 17, 2024
CVE-2024-8972: Improper Neutralization of Special Elements used in an SQL Command9.8 CriticalN/A0%Dec 17, 2024
CVE-2024-9819: Authorization Bypass Through User-Controlled Key6.5 MediumN/A0%Dec 17, 2024
CVE-2024-54677: Uncontrolled Resource Consumption5.3 MediumN/A2%Dec 17, 2024
CVE-2024-50379: Time-of-check Time-of-use (TOCTOU) Race Condition9.8 CriticalN/A32%Dec 17, 2024
CVE-2024-10356: Exposure of Sensitive Information to an Unauthorized Actor4.3 MediumN/A0%Dec 17, 2024
CVE-2024-9654: Incorrect Authorization3.7 LowN/A0%Dec 17, 2024
CVE-2024-8475: Authentication Bypass by Assumed-Immutable Data6.5 MediumN/A0%Dec 17, 2024
CVE-2024-8429: Improper Restriction of Excessive Authentication Attempts4.3 MediumN/A0%Dec 17, 2024
CVE-2024-52542: UNIX Symbolic Link (Symlink) Following4.4 MediumN/A0%Dec 17, 2024
CVE-2024-12601: Uncontrolled Resource Consumption5.3 MediumN/A1%Dec 17, 2024
122726-122750 of 389462