The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
TitleEitWModules
CVE-2024-53703: Stack-based Buffer Overflow8.1 HighN/A29%Dec 5, 2024
CVE-2024-53702: Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)5.3 MediumN/A0%Dec 5, 2024
CVE-2024-52271: User Interface (UI) Misrepresentation of Critical InformationN/A8.2 High0%Dec 5, 2024
CVE-2024-45319: Use of Hard-coded Credentials6.3 MediumN/A1%Dec 5, 2024
CVE-2024-45318: Stack-based Buffer Overflow8.1 HighN/A2%Dec 5, 2024
CVE-2024-40763: Heap-based Buffer Overflow7.5 HighN/A8%Dec 5, 2024
CVE-2024-12228: Improper Neutralization of Special Elements used in an SQL Command7.3 High6.9 Medium0%Dec 5, 2024
CVE-2024-12227: NULL Pointer Dereference5.5 Medium6.8 Medium0%Dec 5, 2024
CVE-2024-6784: Server-Side Request Forgery (SSRF)9.9 Critical8.7 High0%Dec 5, 2024
CVE-2024-6516: Improper Neutralization of Input During Web Page Generation9.0 Critical9.3 Critical1%Dec 5, 2024
CVE-2024-6515: Cleartext Transmission of Sensitive Information9.6 Critical8.7 High0%Dec 5, 2024
CVE-2024-54127: Cleartext Storage of Sensitive InformationN/A4.3 Medium0%Dec 5, 2024
CVE-2024-54126: Download of Code Without Integrity CheckN/A8.5 High0%Dec 5, 2024
CVE-2024-51555: Use of Default Password10.0 Critical9.3 Critical0%Dec 5, 2024
CVE-2024-51554: Off-by-one Error9.1 Critical8.8 High0%Dec 5, 2024
CVE-2024-51551: Improper Validation of Specified Type of Input10.0 Critical9.3 Critical0%Dec 5, 2024
CVE-2024-51550: Improper Validation of Specified Type of Input10.0 Critical9.3 Critical2%Dec 5, 2024
CVE-2024-51549: Absolute Path Traversal10.0 Critical9.3 Critical0%Dec 5, 2024
CVE-2024-51548: Unrestricted Upload of File with Dangerous Type9.9 Critical8.7 High0%Dec 5, 2024
CVE-2024-51546: Improper Validation of Specified Type of Input7.5 High8.7 High7%Dec 5, 2024
CVE-2024-51545: Insufficiently Protected Credentials10.0 Critical9.3 Critical0%Dec 5, 2024
CVE-2024-51544: External Control of System or Configuration Setting8.2 High8.8 High4%Dec 5, 2024
CVE-2024-51543: External Control of System or Configuration Setting8.2 High8.8 High0%Dec 5, 2024
CVE-2024-51542: Files or Directories Accessible to External Parties8.2 High8.8 High0%Dec 5, 2024
CVE-2024-51541: Improper Control of Filename for Include/Require Statement in PHP Program8.2 High8.8 High0%Dec 5, 2024
126651-126675 of 703397