The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
TitleEitWModules
CVE-2024-6516: Improper Neutralization of Input During Web Page Generation9.0 Critical9.3 Critical1%Dec 5, 2024
CVE-2024-6515: Cleartext Transmission of Sensitive Information9.6 Critical8.7 High0%Dec 5, 2024
CVE-2024-54127: Cleartext Storage of Sensitive InformationN/A4.3 Medium0%Dec 5, 2024
CVE-2024-54126: Download of Code Without Integrity CheckN/A8.5 High0%Dec 5, 2024
CVE-2024-51555: Use of Default Password10.0 Critical9.3 Critical0%Dec 5, 2024
CVE-2024-51554: Off-by-one Error9.1 Critical8.8 High0%Dec 5, 2024
CVE-2024-51551: Improper Validation of Specified Type of Input10.0 Critical9.3 Critical0%Dec 5, 2024
CVE-2024-51550: Improper Validation of Specified Type of Input10.0 Critical9.3 Critical2%Dec 5, 2024
CVE-2024-51549: Absolute Path Traversal10.0 Critical9.3 Critical1%Dec 5, 2024
CVE-2024-51548: Unrestricted Upload of File with Dangerous Type9.9 Critical8.7 High1%Dec 5, 2024
CVE-2024-51546: Improper Validation of Specified Type of Input7.5 High8.7 High1%Dec 5, 2024
CVE-2024-51545: Insufficiently Protected Credentials10.0 Critical9.3 Critical0%Dec 5, 2024
CVE-2024-51544: External Control of System or Configuration Setting8.2 High8.8 High13%Dec 5, 2024
CVE-2024-51543: External Control of System or Configuration Setting8.2 High8.8 High0%Dec 5, 2024
CVE-2024-51542: Files or Directories Accessible to External Parties8.2 High8.8 High0%Dec 5, 2024
CVE-2024-51541: Improper Control of Filename for Include/Require Statement in PHP Program8.2 High8.8 High0%Dec 5, 2024
CVE-2024-48847: Use of Weak Hash8.2 High8.8 High0%Dec 5, 2024
CVE-2024-48846: Cross-Site Request Forgery (CSRF)7.1 High7.1 High1%Dec 5, 2024
CVE-2024-48845: Weak Password Requirements9.4 Critical9.3 Critical2%Dec 5, 2024
CVE-2024-48844: Allocation of Resources Without Limits or Throttling7.7 High7.2 High1%Dec 5, 2024
CVE-2024-48843: Allocation of Resources Without Limits or Throttling7.7 High7.6 High0%Dec 5, 2024
CVE-2024-48840: Improper Control of Generation of Code10.0 Critical9.3 Critical2%Dec 5, 2024
CVE-2024-48839: Improper Control of Generation of Code10.0 Critical9.3 Critical3%Dec 5, 2024
CVE-2024-12094: Cleartext Storage of Sensitive InformationN/A5.4 Medium0%Dec 5, 2024
CVE-2024-11317: Session Fixation10.0 Critical9.3 Critical0%Dec 5, 2024
131376-131400 of 402816