The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
TitleEitWModules
CVE-2015-4646: Improper Input Validation7.5 HighN/A1%Apr 13, 2017
CVE-2015-2947: Unintended Proxy or Intermediary9.1 CriticalN/A1%Apr 13, 2017
CVE-2015-8780: Improper Limitation of a Pathname to a Restricted Directory6.4 MediumN/A0%Apr 13, 2017
CVE-2015-8864: Improper Neutralization of Input During Web Page Generation6.1 MediumN/A0%Apr 13, 2017
CVE-2015-8284: Improper Access Control8.8 HighN/A6%Apr 13, 2017
CVE-2015-8283: Improper Limitation of a Pathname to a Restricted Directory6.5 MediumN/A14%Apr 13, 2017
CVE-2015-8282: Undefined Security Weakness9.8 CriticalN/A26%Apr 13, 2017
CVE-2015-8272: NULL Pointer Dereference6.5 MediumN/A1%Apr 13, 2017
CVE-2015-8271: Write-what-where Condition9.8 CriticalN/A1%Apr 13, 2017
CVE-2015-8270: NULL Pointer Dereference7.5 HighN/A1%Apr 13, 2017
CVE-2015-8223: Undefined Security Weakness5.5 MediumN/A0%Apr 13, 2017
CVE-2015-8107: Use of Externally-Controlled Format String7.8 HighN/A2%Apr 13, 2017
CVE-2015-7740: Improper Input Validation5.5 MediumN/A0%Apr 13, 2017
CVE-2015-7565: Improper Neutralization of Input During Web Page Generation6.1 MediumN/A0%Apr 13, 2017
CVE-2015-6674: Improper Restriction of Operations within the Bounds of a Memory Buffer9.8 CriticalN/A2%Apr 13, 2017
CVE-2015-1839: Undefined Security Weakness5.3 MediumN/A0%Apr 13, 2017
CVE-2015-1838: Undefined Security Weakness5.3 MediumN/A0%Apr 13, 2017
CVE-2015-7564: Improper Neutralization of Special Elements used in an SQL Command9.8 CriticalN/A2%Apr 12, 2017
CVE-2015-7563: Cross-Site Request Forgery (CSRF)8.8 HighN/A0%Apr 12, 2017
CVE-2015-7562: Improper Neutralization of Input During Web Page Generation6.1 MediumN/A1%Apr 12, 2017
CVE-2015-8666: Out-of-bounds Write7.9 HighN/A0%Apr 11, 2017
CVE-2015-8613: Out-of-bounds Write6.5 MediumN/A0%Apr 11, 2017
CVE-2015-8568: Missing Release of Resource after Effective Lifetime6.5 MediumN/A0%Apr 11, 2017
CVE-2015-8504: Divide By Zero6.5 MediumN/A3%Apr 11, 2017
CVE-2015-7893: Improper Input Validation8.8 HighN/A14%Apr 11, 2017
2151-2175 of 8780