The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
TitleEitWModules
CVE-2020-36533: Improper Authentication3.7 LowN/A1%Jun 3, 2022
CVE-2020-36532: Exposure of Sensitive Information to an Unauthorized Actor4.3 MediumN/A1%Jun 3, 2022
CVE-2020-36531: Improper Neutralization of Special Elements in Output Used by a Downstream Component6.3 MediumN/A1%Jun 3, 2022
CVE-2020-36530: Improper Neutralization of Special Elements used in an SQL Command6.3 MediumN/A1%Jun 3, 2022
CVE-2020-36529: Improper Neutralization of Special Elements used in a Command8.8 HighN/A4%Jun 3, 2022
CVE-2020-36528: Improper Authentication5.5 MediumN/A1%Jun 3, 2022
CVE-2020-36527: Improper Neutralization of Input During Web Page Generation3.5 LowN/A1%Jun 3, 2022
CVE-2020-36526: Improper Neutralization of Input During Web Page Generation3.5 LowN/A1%Jun 3, 2022
CVE-2020-36525: Improper Neutralization of Input During Web Page Generation3.5 LowN/A1%Jun 3, 2022
CVE-2020-36524: Improper Neutralization of Input During Web Page Generation3.5 LowN/A1%Jun 3, 2022
CVE-2020-36523: Improper Neutralization of Input During Web Page Generation3.5 LowN/A1%Jun 3, 2022
CVE-2020-20971: Cross-Site Request Forgery (CSRF)8.8 HighN/A1%Jun 1, 2022
CVE-2020-26185: Improper Input Validation7.5 HighN/A1%Jun 1, 2022
CVE-2020-26184: Improper Certificate Validation7.5 HighN/A1%Jun 1, 2022
CVE-2020-28246: Improper Neutralization of Special Elements in Output Used by a Downstream Component9.8 CriticalN/A2%May 31, 2022
CVE-2020-4926: Missing Authorization9.1 CriticalN/A1%May 24, 2022
CVE-2020-4107: Improper Access Control8.8 HighN/A0%May 19, 2022
CVE-2020-14496: Undefined Security Weakness8.3 HighN/A1%May 19, 2022
CVE-2020-16235: Inadequate Encryption Strength3.8 LowN/A0%May 19, 2022
CVE-2020-16231: Use of Password Hash With Insufficient Computational Effort7.2 HighN/A1%May 19, 2022
CVE-2020-16209: Stack-based Buffer Overflow9.8 CriticalN/A2%May 19, 2022
CVE-2020-4970: Cleartext Transmission of Sensitive Information5.9 MediumN/A1%May 19, 2022
CVE-2020-4994: Undefined Security Weakness7.5 HighN/A2%May 17, 2022
CVE-2020-4957: Exposure of Sensitive Information to an Unauthorized Actor5.3 MediumN/A1%May 17, 2022
CVE-2020-22983: Server-Side Request Forgery (SSRF)8.1 HighN/A2%May 13, 2022
1726-1750 of 21077