The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
TitleEitWModules
CVE-2020-4925: Undefined Security Weakness5.5 MediumN/A0%Mar 1, 2022
CVE-2020-12775: Improper Neutralization of Special Elements used in an OS Command9.8 CriticalN/A3%Mar 1, 2022
CVE-2020-22845: Buffer Copy without Checking Size of Input7.5 HighN/A1%Feb 28, 2022
CVE-2020-22844: Missing Release of Memory after Effective Lifetime7.5 HighN/A1%Feb 28, 2022
CVE-2020-36510: Improper Neutralization of Input During Web Page Generation6.1 MediumN/A3%Feb 28, 2022
CVE-2020-27958: Improper Encoding or Escaping of Output4.3 MediumN/A1%Feb 26, 2022
CVE-2020-36516: Use of a Broken or Risky Cryptographic Algorithm5.9 MediumN/A1%Feb 26, 2022
CVE-2020-10636: Inadequate Encryption Strength6.5 MediumN/A0%Feb 24, 2022
CVE-2020-10640: Missing Authentication for Critical Function10.0 CriticalN/A3%Feb 24, 2022
CVE-2020-10632: Improper Ownership Management8.8 HighN/A0%Feb 24, 2022
CVE-2020-10635: Improper Enforcement of Message Integrity During Transmission in a Communication Channel4.3 MediumN/A0%Feb 24, 2022
CVE-2020-14480: Cleartext Storage of Sensitive Information5.5 MediumN/A0%Feb 24, 2022
CVE-2020-14481: Weak Encoding for Password7.8 HighN/A0%Feb 24, 2022
CVE-2020-14478: Improper Restriction of XML External Entity Reference7.1 HighN/A0%Feb 24, 2022
CVE-2020-14502: Improper Neutralization of Input During Web Page Generation6.1 MediumN/A1%Feb 24, 2022
CVE-2020-14504: Improper Access Control5.3 MediumN/A1%Feb 24, 2022
CVE-2020-27467: Improper Limitation of a Pathname to a Restricted Directory7.5 HighN/A16%Feb 22, 2022
CVE-2020-8242: Improper Neutralization of Special Elements used in an SQL Command7.2 HighN/A1%Feb 18, 2022
CVE-2020-8107: Process Control8.2 HighN/A0%Feb 18, 2022
CVE-2020-25717: Improper Input Validation8.1 HighN/A2%Feb 18, 2022
CVE-2020-25722: Incorrect Authorization8.8 HighN/A2%Feb 18, 2022
CVE-2020-25719: Improper Authentication7.2 HighN/A2%Feb 18, 2022
CVE-2020-25718: Missing Authorization8.8 HighN/A2%Feb 18, 2022
CVE-2020-6921: Undefined Security Weakness7.8 HighN/A1%Feb 16, 2022
CVE-2020-6920: Undefined Security Weakness5.5 MediumN/A1%Feb 16, 2022
1876-1900 of 21077