The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
TitleEitWModules
CVE-2020-26008: Unrestricted Upload of File with Dangerous Type7.8 HighN/A1%Mar 20, 2022
CVE-2020-26007: Unrestricted Upload of File with Dangerous Type7.8 HighN/A1%Mar 20, 2022
CVE-2020-25193: Use of Hard-coded Cryptographic Key5.3 MediumN/A1%Mar 18, 2022
CVE-2020-25197: Improper Control of Generation of Code9.8 CriticalN/A3%Mar 18, 2022
CVE-2020-25180: Use of Hard-coded Cryptographic Key5.3 MediumN/A1%Mar 18, 2022
CVE-2020-25184: Plaintext Storage of a Password7.8 HighN/A0%Mar 18, 2022
CVE-2020-25176: Relative Path Traversal9.1 CriticalN/A6%Mar 18, 2022
CVE-2020-25182: Uncontrolled Search Path Element6.7 MediumN/A0%Mar 18, 2022
CVE-2020-25178: Cleartext Transmission of Sensitive Information7.5 HighN/A2%Mar 18, 2022
CVE-2020-16232: Buffer Copy without Checking Size of Input2.8 LowN/A1%Mar 18, 2022
CVE-2020-15388: Undefined Security Weakness6.5 MediumN/A1%Mar 18, 2022
CVE-2020-15591: Improper Control of Generation of Code9.8 CriticalN/A4%Mar 17, 2022
CVE-2020-25721: Improper Input Validation8.8 HighN/A2%Mar 16, 2022
CVE-2020-36519: Undefined Security Weakness4.9 MediumN/A1%Mar 15, 2022
CVE-2020-4989: Exposure of Resource to Wrong Sphere4.3 MediumN/A1%Mar 15, 2022
CVE-2020-36518: Out-of-bounds Write7.5 HighN/A5%Mar 11, 2022
CVE-2020-36517: Observable Discrepancy7.5 HighN/A3%Mar 7, 2022
CVE-2020-14115: Insufficient Verification of Data Authenticity9.8 CriticalN/A1%Mar 7, 2022
CVE-2020-14111: Insufficient Verification of Data Authenticity7.8 HighN/A0%Mar 7, 2022
CVE-2020-14112: Exposure of Sensitive Information to an Unauthorized Actor5.3 MediumN/A1%Mar 7, 2022
CVE-2020-18326: Cross-Site Request Forgery (CSRF)8.8 HighN/A2%Mar 4, 2022
CVE-2020-18325: Improper Neutralization of Input During Web Page Generation6.1 MediumN/A2%Mar 4, 2022
CVE-2020-18324: Improper Neutralization of Input During Web Page Generation6.1 MediumN/A2%Mar 4, 2022
CVE-2020-18327: Improper Neutralization of Input During Web Page Generation6.1 MediumN/A1%Mar 4, 2022
CVE-2020-15936: Improper Input Validation2.6 LowN/A1%Mar 1, 2022
1851-1875 of 21077