The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
TitleEitWModules
CVE-2020-19897: Improper Neutralization of Input During Web Page Generation6.1 MediumN/A1%Jun 28, 2022
CVE-2020-19896: Undefined Security Weakness9.8 CriticalN/A2%Jun 28, 2022
CVE-2020-21161: Improper Neutralization of Input During Web Page Generation6.1 MediumN/A1%Jun 27, 2022
CVE-2020-9754: Improper Access Control5.3 MediumN/A1%Jun 27, 2022
CVE-2020-27509: Improper Neutralization of Input During Web Page Generation5.4 MediumN/A1%Jun 26, 2022
CVE-2020-21046: Improper Privilege Management7.8 HighN/A0%Jun 24, 2022
CVE-2020-36549: Improper Privilege Management8.8 HighN/A0%Jun 17, 2022
CVE-2020-36548: Improper Authentication5.9 MediumN/A0%Jun 17, 2022
CVE-2020-36547: Use of Hard-coded Credentials5.9 MediumN/A0%Jun 17, 2022
CVE-2020-25459: Exposure of Resource to Wrong Sphere7.5 HighN/A1%Jun 16, 2022
CVE-2020-28865: Insufficiently Protected Credentials7.5 HighN/A1%Jun 16, 2022
CVE-2020-35597: Improper Neutralization of Special Elements used in an SQL Command8.8 HighN/A2%Jun 16, 2022
CVE-2020-14125: Out-of-bounds Read7.5 HighN/A7%Jun 8, 2022
CVE-2020-6220: Improper Neutralization of Input During Web Page Generation4.7 MediumN/A1%Jun 6, 2022
CVE-2020-36544: Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)3.5 LowN/A1%Jun 4, 2022
CVE-2020-36543: Improper Neutralization of Special Elements used in an SQL Command6.3 MediumN/A1%Jun 4, 2022
CVE-2020-36542: Improper Privilege Management7.3 HighN/A1%Jun 3, 2022
CVE-2020-36541: Improper Neutralization of Special Elements used in an SQL Command7.3 HighN/A1%Jun 3, 2022
CVE-2020-36540: Improper Neutralization of Special Elements used in an SQL Command6.3 MediumN/A1%Jun 3, 2022
CVE-2020-36539: Improper Neutralization of Special Elements used in an SQL Command6.3 MediumN/A1%Jun 3, 2022
CVE-2020-36538: Improper Neutralization of Special Elements used in an SQL Command6.3 MediumN/A1%Jun 3, 2022
CVE-2020-36537: Improper Neutralization of Special Elements used in an SQL Command6.3 MediumN/A1%Jun 3, 2022
CVE-2020-36536: Improper Neutralization of Special Elements used in an SQL Command6.3 MediumN/A1%Jun 3, 2022
CVE-2020-36535: Improper Neutralization of Special Elements used in an SQL Command6.3 MediumN/A1%Jun 3, 2022
CVE-2020-36534: Cross-Site Request Forgery (CSRF)4.3 MediumN/A0%Jun 3, 2022
1701-1725 of 21077