The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
TitleEitWModules
CVE-2020-12937: Undefined Security WeaknessN/AN/AN/AJan 14, 2022
CVE-2020-12934: Undefined Security WeaknessN/AN/AN/AJan 14, 2022
CVE-2020-12918: Undefined Security Weakness9.8 CriticalN/AN/AJan 14, 2022
CVE-2020-12908: Undefined Security Weakness9.8 CriticalN/AN/AJan 14, 2022
CVE-2020-12907: Undefined Security WeaknessN/AN/AN/AJan 14, 2022
CVE-2020-28103: Improper Neutralization of Special Elements used in an SQL Command9.8 CriticalN/A0%Jan 11, 2022
CVE-2020-28102: Improper Neutralization of Special Elements used in an SQL Command9.8 CriticalN/A0%Jan 11, 2022
CVE-2020-25427: NULL Pointer Dereference5.5 MediumN/A0%Jan 10, 2022
CVE-2020-28679: Improper Neutralization of Special Elements used in an SQL Command8.8 HighN/A3%Jan 10, 2022
CVE-2020-10137: Insufficient Verification of Data Authenticity6.5 MediumN/A0%Jan 9, 2022
CVE-2020-29050: Improper Limitation of a Pathname to a Restricted Directory7.5 HighN/A1%Jan 7, 2022
CVE-2020-9061: Improper Authorization6.5 MediumN/A0%Jan 7, 2022
CVE-2020-9060: Origin Validation Error6.5 MediumN/A0%Jan 7, 2022
CVE-2020-9059: Uncontrolled Resource Consumption6.5 MediumN/A0%Jan 7, 2022
CVE-2020-9058: Missing Encryption of Sensitive Data8.1 HighN/A0%Jan 7, 2022
CVE-2020-9057: Missing Encryption of Sensitive Data8.8 HighN/A0%Jan 7, 2022
CVE-2020-27428: Improper Neutralization of Input During Web Page Generation6.1 MediumN/A0%Jan 5, 2022
CVE-2020-23986: Improper Neutralization of Input During Web Page Generation6.1 MediumN/A0%Jan 5, 2022
CVE-2020-5956: Improper Input Validation7.5 HighN/A0%Jan 5, 2022
CVE-2020-15933: Exposure of Sensitive Information to an Unauthorized Actor5.3 MediumN/A0%Jan 5, 2022
CVE-2020-23026: NULL Pointer Dereference7.5 HighN/A0%Jan 3, 2022
CVE-2020-11263: Integer Overflow or Wraparound7.3 HighN/A0%Jan 3, 2022
CVE-2020-29292: Cross-Site Request Forgery (CSRF)6.5 MediumN/A0%Dec 30, 2021
CVE-2020-22061: Undefined Security Weakness7.8 HighN/A0%Dec 28, 2021
CVE-2020-22057: Undefined Security Weakness9.1 CriticalN/A0%Dec 28, 2021
2076-2100 of 21077