The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
TitleEitWModules
CVE-2024-47579: Insertion of Sensitive Information into Externally-Accessible File or Directory6.8 MediumN/A1%Dec 10, 2024
CVE-2024-47578: Server-Side Request Forgery (SSRF)9.1 CriticalN/A1%Dec 10, 2024
CVE-2024-47577: Cleartext Transmission of Sensitive Information2.7 LowN/A0%Dec 10, 2024
CVE-2024-47576: Uncontrolled Search Path Element3.3 LowN/A0%Dec 10, 2024
CVE-2024-32732: Exposure of Sensitive System Information to an Unauthorized Control Sphere5.3 MediumN/A0%Dec 10, 2024
CVE-2024-9672: Improper Neutralization of Special Elements used in an Expression Language Statement5.4 Medium6.3 Medium0%Dec 10, 2024
CVE-2024-55638: Improperly Controlled Modification of Dynamically-Determined Object Attributes9.8 CriticalN/A1%Dec 10, 2024
CVE-2024-55637: Improperly Controlled Modification of Dynamically-Determined Object Attributes9.8 CriticalN/A1%Dec 10, 2024
CVE-2024-55636: Improperly Controlled Modification of Dynamically-Determined Object Attributes9.8 CriticalN/A1%Dec 10, 2024
CVE-2024-55635: Improper Neutralization of Input During Web Page Generation6.1 MediumN/A0%Dec 10, 2024
CVE-2024-55634: Improper Handling of Case Sensitivity8.1 HighN/A0%Dec 10, 2024
CVE-2024-12393: Improper Neutralization of Input During Web Page Generation5.4 MediumN/A0%Dec 10, 2024
CVE-2024-55601: Improper Neutralization of Input During Web Page GenerationN/A5.3 Medium1%Dec 9, 2024
CVE-2024-50628: Missing Authorization8.8 HighN/A0%Dec 9, 2024
CVE-2024-50627: Files or Directories Accessible to External Parties8.8 HighN/A0%Dec 9, 2024
CVE-2024-50626: Improper Limitation of a Pathname to a Restricted Directory8.8 HighN/A1%Dec 9, 2024
CVE-2024-50625: Unrestricted Upload of File with Dangerous Type8.0 HighN/A0%Dec 9, 2024
CVE-2024-12174: Improper Certificate Validation2.7 LowN/A0%Dec 9, 2024
CVE-2024-54151: Exposure of Sensitive Information to an Unauthorized Actor7.5 HighN/A1%Dec 9, 2024
CVE-2024-54149: Incomplete List of Disallowed Inputs8.4 HighN/A0%Dec 9, 2024
CVE-2024-46455: Improper Restriction of XML External Entity Reference9.8 CriticalN/A1%Dec 9, 2024
CVE-2024-12369: Insufficient Verification of Data Authenticity4.2 MediumN/A0%Dec 9, 2024
CVE-2024-53441: Use of a Broken or Risky Cryptographic Algorithm9.1 CriticalN/A0%Dec 9, 2024
CVE-2024-54938: Out-of-bounds Read7.5 HighN/A1%Dec 9, 2024
CVE-2024-54934: Improper Neutralization of Special Elements used in an SQL Command9.8 CriticalN/A1%Dec 9, 2024
128251-128275 of 591205