The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
TitleEitWModules
CVE-2024-40391: Undefined Security WeaknessN/AN/AN/ADec 3, 2024
CVE-2024-54131: Incorrect Default PermissionsN/A7.3 High0%Dec 3, 2024
CVE-2024-53672: Improper Neutralization of Special Elements used in a Command4.7 MediumN/A0%Dec 3, 2024
CVE-2024-51773: Improper Neutralization of Input During Web Page Generation4.8 MediumN/A0%Dec 3, 2024
CVE-2024-51772: Improper Neutralization of Special Elements used in a Command6.4 MediumN/A0%Dec 3, 2024
CVE-2024-45757: Improper Neutralization of Special Elements used in an SQL Command7.2 HighN/A0%Dec 3, 2024
CVE-2024-51771: Improper Neutralization of Special Elements used in a Command7.2 HighN/A1%Dec 3, 2024
CVE-2024-51114: Improper Neutralization of Special Elements used in a Command8.8 HighN/A1%Dec 3, 2024
CVE-2024-53921: Incorrect Default Permissions2.8 LowN/A0%Dec 3, 2024
CVE-2024-50948: Undefined Security Weakness7.5 HighN/A1%Dec 3, 2024
CVE-2024-48080: Allocation of Resources Without Limits or Throttling7.5 HighN/A1%Dec 3, 2024
CVE-2024-12053: Access of Resource Using Incompatible Type8.8 HighN/A1%Dec 3, 2024
CVE-2024-52548: Insufficient Verification of Data Authenticity6.7 MediumN/A0%Dec 3, 2024
CVE-2024-52547: Stack-based Buffer Overflow7.2 HighN/A1%Dec 3, 2024
CVE-2024-52546: NULL Pointer Dereference5.3 MediumN/A1%Dec 3, 2024
CVE-2024-52545: Out-of-bounds Read6.5 MediumN/A1%Dec 3, 2024
CVE-2024-52544: Stack-based Buffer Overflow9.8 CriticalN/A1%Dec 3, 2024
CVE-2024-45676: Insufficient Type Distinction4.3 MediumN/A0%Dec 3, 2024
CVE-2024-41777: Use of Hard-coded Credentials7.5 HighN/A0%Dec 3, 2024
CVE-2024-41776: Cross-Site Request Forgery (CSRF)6.5 MediumN/A0%Dec 3, 2024
CVE-2024-41775: Use of a Broken or Risky Cryptographic Algorithm5.9 MediumN/A0%Dec 3, 2024
CVE-2024-25020: Unrestricted Upload of File with Dangerous Type5.5 MediumN/A0%Dec 3, 2024
CVE-2023-7255: Undefined Security WeaknessN/AN/AN/ADec 3, 2024
CVE-2024-53867: Exposure of Sensitive System Information to an Unauthorized Control Sphere4.3 MediumN/A0%Dec 3, 2024
CVE-2024-53863: Unrestricted Upload of File with Dangerous Type9.1 Critical8.2 High1%Dec 3, 2024
124851-124875 of 559420