The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
TitleEitWModules
CVE-2020-6922: Undefined Security Weakness7.8 HighN/A1%Feb 16, 2022
CVE-2020-6917: Undefined Security Weakness7.8 HighN/A1%Feb 16, 2022
CVE-2020-6919: Undefined Security Weakness7.8 HighN/A1%Feb 16, 2022
CVE-2020-6918: Undefined Security Weakness7.8 HighN/A1%Feb 16, 2022
CVE-2020-26728: Undefined Security Weakness9.8 CriticalN/A4%Feb 11, 2022
CVE-2020-14523: Improper Limitation of a Pathname to a Restricted Directory8.3 HighN/A2%Feb 11, 2022
CVE-2020-14521: Unquoted Search Path or Element8.3 HighN/A1%Feb 11, 2022
CVE-2020-13677: Improper Access Control7.5 HighN/A1%Feb 11, 2022
CVE-2020-13676: Improper Access Control6.5 MediumN/A1%Feb 11, 2022
CVE-2020-13670: Exposure of Resource to Wrong Sphere7.5 HighN/A1%Feb 11, 2022
CVE-2020-13674: Cross-Site Request Forgery (CSRF)6.5 MediumN/A0%Feb 11, 2022
CVE-2020-13675: Improper Access Control9.8 CriticalN/A1%Feb 11, 2022
CVE-2020-13673: Cross-Site Request Forgery (CSRF)6.1 MediumN/A0%Feb 11, 2022
CVE-2020-13672: Improper Neutralization of Input During Web Page Generation6.1 MediumN/A1%Feb 11, 2022
CVE-2020-13669: Improper Neutralization of Input During Web Page Generation6.1 MediumN/A1%Feb 11, 2022
CVE-2020-13668: Improper Neutralization of Input During Web Page Generation6.1 MediumN/A1%Feb 11, 2022
CVE-2020-36062: Use of Hard-coded Credentials9.8 CriticalN/A2%Feb 11, 2022
CVE-2020-7534: Cross-Site Request Forgery (CSRF)8.8 HighN/A0%Feb 4, 2022
CVE-2020-12965: Improper Neutralization of Special Elements in Output Used by a Downstream Component7.5 HighN/A2%Feb 4, 2022
CVE-2020-12966: Exposure of Sensitive Information to an Unauthorized Actor5.5 MediumN/A0%Feb 4, 2022
CVE-2020-12891: Uncontrolled Search Path Element7.8 HighN/A0%Feb 4, 2022
CVE-2020-5953: Undefined Security Weakness7.5 HighN/A0%Feb 3, 2022
CVE-2020-26208: Out-of-bounds Write5.3 MediumN/A1%Feb 2, 2022
CVE-2020-8562: Time-of-check Time-of-use (TOCTOU) Race Condition2.2 LowN/A1%Feb 1, 2022
CVE-2020-36056: Improper Neutralization of Input During Web Page Generation5.4 MediumN/A1%Jan 31, 2022
1901-1925 of 21077