The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
TitleEitWModules
CVE-2015-3171: Exposure of Sensitive Information to an Unauthorized Actor5.5 MediumN/A0%Jul 25, 2017
CVE-2015-3149: Improper Link Resolution Before File Access5.5 MediumN/A0%Jul 25, 2017
CVE-2015-2798: Improper Neutralization of Special Elements used in an SQL Command9.8 CriticalN/A1%Jul 25, 2017
CVE-2015-1438: Improper Restriction of Operations within the Bounds of a Memory Buffer7.8 HighN/A0%Jul 25, 2017
CVE-2015-1417: Uncontrolled Resource Consumption7.5 HighN/A1%Jul 25, 2017
CVE-2015-1332: Improper Restriction of Operations within the Bounds of a Memory Buffer8.8 HighN/A1%Jul 25, 2017
CVE-2015-0904: Improper Certificate Validation5.9 MediumN/A0%Jul 25, 2017
CVE-2015-0674: Improper Neutralization of Input During Web Page Generation6.1 MediumN/A0%Jul 25, 2017
CVE-2015-3208: Undefined Security Weakness9.8 CriticalN/AN/AJul 25, 2017
CVE-2015-8009: Undefined Security Weakness9.8 CriticalN/A0%Jul 25, 2017
CVE-2015-7543: Concurrent Execution using Shared Resource with Improper Synchronization7.0 HighN/A0%Jul 25, 2017
CVE-2015-2280: Improper Neutralization of Special Elements used in an OS Command8.8 HighN/A30%Jul 25, 2017
CVE-2015-2279: Improper Neutralization of Special Elements used in an OS Command9.8 CriticalN/A42%Jul 25, 2017
CVE-2015-1847: Improper Limitation of a Pathname to a Restricted Directory7.5 HighN/A0%Jul 25, 2017
CVE-2015-7703: Improper Input Validation7.5 HighN/A8%Jul 24, 2017
CVE-2015-5300: Undefined Security Weakness7.5 HighN/A37%Jul 21, 2017
CVE-2015-5219: Incorrect Type Conversion or Cast7.5 HighN/A2%Jul 21, 2017
CVE-2015-5195: Improper Input Validation7.5 HighN/A10%Jul 21, 2017
CVE-2015-5194: Improper Input Validation7.5 HighN/A12%Jul 21, 2017
CVE-2015-4639: Cross-Site Request Forgery (CSRF)8.8 HighN/A0%Jul 21, 2017
CVE-2015-3932: XML Injection (aka Blind XPath Injection)7.8 HighN/A0%Jul 21, 2017
CVE-2015-3931: XML Injection (aka Blind XPath Injection)7.8 HighN/A0%Jul 21, 2017
CVE-2015-3886: Improper Certificate Validation9.8 CriticalN/A1%Jul 21, 2017
CVE-2015-3640: Improper Control of Generation of Code7.5 HighN/A1%Jul 21, 2017
CVE-2015-3639: Improper Input Validation8.8 HighN/A1%Jul 21, 2017
1501-1525 of 8780