The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
TitleEitWModules
CVE-2024-53441: Use of a Broken or Risky Cryptographic Algorithm9.1 CriticalN/A0%Dec 9, 2024
CVE-2024-54938: Out-of-bounds Read7.5 HighN/A1%Dec 9, 2024
CVE-2024-54934: Improper Neutralization of Special Elements used in an SQL Command9.8 CriticalN/A1%Dec 9, 2024
CVE-2024-54932: Improper Neutralization of Special Elements used in an SQL Command9.8 CriticalN/A1%Dec 9, 2024
CVE-2024-54931: Improper Neutralization of Special Elements used in an SQL Command9.8 CriticalN/A1%Dec 9, 2024
CVE-2024-54928: Improper Neutralization of Special Elements used in an SQL Command7.2 HighN/A0%Dec 9, 2024
CVE-2024-54927: Improper Neutralization of Special Elements used in an SQL Command7.2 HighN/A0%Dec 9, 2024
CVE-2024-54925: Improper Neutralization of Special Elements used in an SQL Command9.8 CriticalN/A1%Dec 9, 2024
CVE-2024-54924: Improper Neutralization of Special Elements used in an SQL Command9.8 CriticalN/A1%Dec 9, 2024
CVE-2024-54923: Improper Neutralization of Special Elements used in an SQL Command9.8 CriticalN/A1%Dec 9, 2024
CVE-2024-54921: Improper Neutralization of Special Elements used in an SQL Command9.8 CriticalN/A1%Dec 9, 2024
CVE-2024-54918: Unrestricted Upload of File with Dangerous Type9.8 CriticalN/A1%Dec 9, 2024
CVE-2024-54147: Improper Certificate Validation6.8 MediumN/A0%Dec 9, 2024
CVE-2024-53847: Improper Neutralization of Input During Web Page GenerationN/A5.1 Medium0%Dec 9, 2024
CVE-2024-52599: Improper Neutralization of Input During Web Page Generation5.4 MediumN/A0%Dec 9, 2024
CVE-2024-52586: Authentication Bypass Using an Alternate Path or Channel5.4 MediumN/A0%Dec 9, 2024
CVE-2024-48956: Use of Default Cryptographic Key9.8 CriticalN/A1%Dec 9, 2024
CVE-2024-46547: Improper Encoding or Escaping of Output7.5 HighN/A0%Dec 9, 2024
CVE-2024-12057: Insertion of Sensitive Information into Log FileN/A1.8 Low0%Dec 9, 2024
CVE-2022-29974: Buffer Copy without Checking Size of Input4.3 MediumN/A0%Dec 9, 2024
CVE-2024-54935: Improper Neutralization of Input During Web Page Generation5.4 MediumN/A0%Dec 9, 2024
CVE-2024-54933: Improper Neutralization of Special Elements used in an SQL Command7.2 HighN/A0%Dec 9, 2024
CVE-2024-54930: Improper Neutralization of Special Elements used in an SQL Command7.2 HighN/A0%Dec 9, 2024
CVE-2024-54922: Improper Neutralization of Special Elements used in an SQL Command7.2 HighN/A1%Dec 9, 2024
CVE-2024-11608: Heap-based Buffer Overflow7.8 HighN/A0%Dec 9, 2024
128276-128300 of 591205