The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
TitleEitWModules
CVE-2015-3313: Improper Neutralization of Special Elements used in an SQL Command9.8 CriticalN/A18%Sep 7, 2017
CVE-2015-3222: Undefined Security Weakness7.0 HighN/A0%Sep 7, 2017
CVE-2015-3169: Improper Neutralization of Input During Web Page Generation6.1 MediumN/A0%Sep 7, 2017
CVE-2015-1590: Undefined Security Weakness7.8 HighN/A0%Sep 7, 2017
CVE-2015-3442: Improper Authentication9.8 CriticalN/A2%Sep 7, 2017
CVE-2015-3250: Exposure of Sensitive Information to an Unauthorized Actor7.5 HighN/A2%Sep 7, 2017
CVE-2015-8316: Improper Validation of Array Index5.9 MediumN/A1%Sep 6, 2017
CVE-2015-7294: Improper Neutralization of Special Elements used in an LDAP Query7.5 HighN/A1%Sep 6, 2017
CVE-2015-7241: Improper Restriction of XML External Entity Reference9.8 CriticalN/A27%Sep 6, 2017
CVE-2015-7225: Undefined Security Weakness5.3 MediumN/A1%Sep 6, 2017
CVE-2015-6250: Exposure of Sensitive Information to an Unauthorized Actor5.3 MediumN/A0%Sep 6, 2017
CVE-2015-5959: Exposure of Sensitive Information to an Unauthorized Actor9.8 CriticalN/A1%Sep 6, 2017
CVE-2015-5948: Concurrent Execution using Shared Resource with Improper Synchronization8.1 HighN/A2%Sep 6, 2017
CVE-2015-5947: Concurrent Execution using Shared Resource with Improper Synchronization8.1 HighN/A3%Sep 6, 2017
CVE-2015-5705: Improper Link Resolution Before File Access7.5 HighN/A1%Sep 6, 2017
CVE-2015-5186: Improper Input Validation5.3 MediumN/A0%Sep 6, 2017
CVE-2015-3454: Exposure of Sensitive Information to an Unauthorized Actor7.5 HighN/A2%Sep 6, 2017
CVE-2015-3450: Improper Restriction of Operations within the Bounds of a Memory Buffer8.8 HighN/A1%Sep 6, 2017
CVE-2015-3163: Improper Access Control4.3 MediumN/A0%Sep 6, 2017
CVE-2015-3162: Improper Neutralization of Input During Web Page Generation5.4 MediumN/A0%Sep 6, 2017
CVE-2015-3161: Improper Neutralization of Input During Web Page Generation4.8 MediumN/A0%Sep 6, 2017
CVE-2015-3160: Improper Restriction of XML External Entity Reference4.3 MediumN/A0%Sep 6, 2017
CVE-2015-2943: Improper Certificate Validation5.9 MediumN/A0%Sep 6, 2017
CVE-2015-2210: Improper Neutralization of Special Elements used in a Command7.8 HighN/A0%Sep 6, 2017
CVE-2015-0853: Improper Input Validation8.8 HighN/A2%Sep 6, 2017
1276-1300 of 8780