Rapid7 kayıtları
rapid7 üreticisine ait 94 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 3 · %3,2
- Pre-auth RCE
- 4
- Düzeltme kaydı olan
- %24,5
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')12
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')9
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')8
- CWE-426 Untrusted Search Path5
- CWE-352 Cross-Site Request Forgery (CSRF)5
- CWE-427 Uncontrolled Search Path Element4
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
94 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
43Planlayın | CVE-2019-5645Silahlaştırılmış | Rapid7 Metasploit HTTP Handler Denial of Servicerapid7 · metasploit · CWE-400 | Yüksek7,5 | — | %41,7 | 1 Eyl 2020 |
40Planlayın | CVE-2020-7384Silahlaştırılmış | Client-Side Command Injection in Rapid7 Metasploitrapid7 · metasploit · CWE-77 | Yüksek7,8 | — | %30,5 | 29 Eki 2020 |
39İzleyin | CVE-2026-8592İstismar yok | OS Command Injection in Rapid7 InsightConnect AWK Pluginrapid7 · insightconnect awk · CWE-78 | Kritik9,8 | — | %1,2 | 24 Haz 2026 |
39İzleyin | CVE-2026-8660İstismar yok | OS Command Injection in Rapid7 InsightConnect Ping Pluginrapid7 · insightconnect ping · CWE-78 | Kritik9,8 | — | %1,2 | 24 Haz 2026 |
39İzleyin | CVE-2026-8665İstismar yok | OS Command Injection in Rapid7 InsightConnect Translate Pluginrapid7 · insightconnect translate · CWE-78 | Kritik9,8 | — | %1,2 | 24 Haz 2026 |
39İzleyin | CVE-2026-8666İstismar yok | OS Command Injection in Rapid7 InsightConnect Traceroute Pluginrapid7 · insightconnect traceroute · CWE-78 | Kritik9,8 | — | %1,2 | 24 Haz 2026 |
39İzleyin | CVE-2020-7376İstismar yok | Rapid7 Metasploit Framework Relative Path Traversal in enum_osx modulerapid7 · metasploit · CWE-23 | Kritik9,8 | — | %1,1 | 24 Ağu 2020 |
39İzleyin | CVE-2023-1699İstismar yok | Rapid7 Nexpose Forced Browsingrapid7 · nexpose · CWE-425 | Kritik9,8 | — | %0,4 | 30 Mar 2023 |
36İzleyin | CVE-2017-5264Kavram kanıtı | Versions of Nexpose prior to 6.4.66 fail to adequately validate the source of HTTP requests intended for the Automated Actions administrativrapid7 · nexpose · CWE-352 | Yüksek8,8 | — | %2,7 | 14 Ara 2017 |
36İzleyin | CVE-2020-7385İstismar yok | Metasploit Framework 'drb_remote_codeexec' code executionrapid7 · metasploit · CWE-502 | Yüksek8,8 | — | %1,8 | 23 Nis 2021 |
36İzleyin | CVE-2026-6290İstismar yok | Velociraptor Query() Plugin Misapplies Permissions To Orgsrapid7 · velociraptor · CWE-863 | Kritik9,1 | — | %0,4 | 15 Nis 2026 |
35İzleyin | CVE-2026-8663İstismar yok | OS Command Injection in Rapid7 InsightConnect RPM Pluginrapid7 · insightconnect rpm · CWE-78 | Yüksek8,8 | — | %1,3 | 24 Haz 2026 |
35İzleyin | CVE-2026-8659İstismar yok | OS Command Injection in Rapid7 InsightConnect SQLmap Pluginrapid7 · insightconnect sqlmap · CWE-78 | Yüksek8,8 | — | %1,3 | 24 Haz 2026 |
35İzleyin | CVE-2026-8664İstismar yok | OS Command Injection in Rapid7 InsightConnect Finger Pluginrapid7 · insightconnect finger · CWE-78 | Yüksek8,8 | — | %1,3 | 24 Haz 2026 |
35İzleyin | CVE-2026-8658İstismar yok | OS Command Injection in Rapid7 InsightConnect Tcpdump Pluginrapid7 · insightconnect tcpdump · CWE-78 | Yüksek8,8 | — | %1,3 | 24 Haz 2026 |
35İzleyin | CVE-2022-0757İstismar yok | Rapid7 Nexpose SQL Injectionrapid7 · nexpose · CWE-89 | Yüksek8,8 | — | %1,2 | 17 Mar 2022 |
35İzleyin | CVE-2023-1306İstismar yok | Rapid7 InsightCloudSec resource.db() method accessrapid7 · insightappsec · CWE-94 | Yüksek8,8 | — | %1,2 | 21 Mar 2023 |
35İzleyin | CVE-2023-1304İstismar yok | Rapid7 InsightCloudSec getattr() method accessrapid7 · insightappsec · CWE-94 | Yüksek8,8 | — | %1,1 | 21 Mar 2023 |
35İzleyin | CVE-2019-5630Kavram kanıtı | Rapid7 Nexpose/InsightVM Security Console CSRFrapid7 · nexpose · CWE-352 | Yüksek8,8 | — | %0,9 | 3 Tem 2019 |
35İzleyin | CVE-2023-0242İstismar yok | Insufficient permission check in the VQL copy() functionrapid7 · velociraptor · CWE-269 | Yüksek8,8 | — | %0,5 | 18 Oca 2023 |
34İzleyin | CVE-2019-5638İstismar yok | Rapid7 Nexpose Insufficient Session Managementrapid7 · nexpose · CWE-613 | Yüksek8,7 | — | %1,0 | 21 Ağu 2019 |
34İzleyin | CVE-2017-5243İstismar yok | The default SSH configuration in Rapid7 Nexpose hardware appliances shipped before June 2017 does not specify desired algorithms for key excrapid7 · nexpose · CWE-327 | Yüksek8,5 | — | %0,5 | 6 Haz 2017 |
34İzleyin | CVE-2026-6482İstismar yok | Local Privilege Escalation via OpenSSL configuration file in Insight Agentrapid7 · insight agent · CWE-829 | Yüksek8,5 | — | %0,2 | 17 Nis 2026 |
34İzleyin | CVE-2024-10526İstismar yok | Rapid7 Velociraptor Local Privilege Escalation In Windows Velociraptor Servicerapid7 · velociraptor · CWE-552 | Yüksek8,6 | — | %0,2 | 7 Kas 2024 |
33İzleyin | CVE-2020-7350Silahlaştırılmış | Metasploit Framework Plugin Libnotify Command Injectionrapid7 · metasploit · CWE-78 | Yüksek7,8 | — | %5,0 | 22 Nis 2020 |
- CVE-2019-564543Planlayın
Rapid7 Metasploit HTTP Handler Denial of Service
YüksekCVSS 7,5SilahlaştırılmışEPSS %42rapid7 · metasploit1 Eyl 2020
- CVE-2020-738440Planlayın
Client-Side Command Injection in Rapid7 Metasploit
YüksekCVSS 7,8SilahlaştırılmışEPSS %30rapid7 · metasploit29 Eki 2020
- CVE-2026-859239İzleyin
OS Command Injection in Rapid7 InsightConnect AWK Plugin
KritikCVSS 9,8İstismar yokEPSS %1rapid7 · insightconnect awk24 Haz 2026
- CVE-2026-866039İzleyin
OS Command Injection in Rapid7 InsightConnect Ping Plugin
KritikCVSS 9,8İstismar yokEPSS %1rapid7 · insightconnect ping24 Haz 2026
- CVE-2026-866539İzleyin
OS Command Injection in Rapid7 InsightConnect Translate Plugin
KritikCVSS 9,8İstismar yokEPSS %1rapid7 · insightconnect translate24 Haz 2026
- CVE-2026-866639İzleyin
OS Command Injection in Rapid7 InsightConnect Traceroute Plugin
KritikCVSS 9,8İstismar yokEPSS %1rapid7 · insightconnect traceroute24 Haz 2026
- CVE-2020-737639İzleyin
Rapid7 Metasploit Framework Relative Path Traversal in enum_osx module
KritikCVSS 9,8İstismar yokEPSS %1rapid7 · metasploit24 Ağu 2020
- CVE-2023-169939İzleyin
Rapid7 Nexpose Forced Browsing
KritikCVSS 9,8İstismar yokEPSS %0rapid7 · nexpose30 Mar 2023
- CVE-2017-526436İzleyin
Versions of Nexpose prior to 6.4.66 fail to adequately validate the source of HTTP requests intended for the Automated Actions administrativ
YüksekCVSS 8,8Kavram kanıtıEPSS %3rapid7 · nexpose14 Ara 2017
- CVE-2020-738536İzleyin
Metasploit Framework 'drb_remote_codeexec' code execution
YüksekCVSS 8,8İstismar yokEPSS %2rapid7 · metasploit23 Nis 2021
- CVE-2026-629036İzleyin
Velociraptor Query() Plugin Misapplies Permissions To Orgs
KritikCVSS 9,1İstismar yokEPSS %0rapid7 · velociraptor15 Nis 2026
- CVE-2026-866335İzleyin
OS Command Injection in Rapid7 InsightConnect RPM Plugin
YüksekCVSS 8,8İstismar yokEPSS %1rapid7 · insightconnect rpm24 Haz 2026
- CVE-2026-865935İzleyin
OS Command Injection in Rapid7 InsightConnect SQLmap Plugin
YüksekCVSS 8,8İstismar yokEPSS %1rapid7 · insightconnect sqlmap24 Haz 2026
- CVE-2026-866435İzleyin
OS Command Injection in Rapid7 InsightConnect Finger Plugin
YüksekCVSS 8,8İstismar yokEPSS %1rapid7 · insightconnect finger24 Haz 2026
- CVE-2026-865835İzleyin
OS Command Injection in Rapid7 InsightConnect Tcpdump Plugin
YüksekCVSS 8,8İstismar yokEPSS %1rapid7 · insightconnect tcpdump24 Haz 2026
- CVE-2022-075735İzleyin
Rapid7 Nexpose SQL Injection
YüksekCVSS 8,8İstismar yokEPSS %1rapid7 · nexpose17 Mar 2022
- CVE-2023-130635İzleyin
Rapid7 InsightCloudSec resource.db() method access
YüksekCVSS 8,8İstismar yokEPSS %1rapid7 · insightappsec21 Mar 2023
- CVE-2023-130435İzleyin
Rapid7 InsightCloudSec getattr() method access
YüksekCVSS 8,8İstismar yokEPSS %1rapid7 · insightappsec21 Mar 2023
- CVE-2019-563035İzleyin
Rapid7 Nexpose/InsightVM Security Console CSRF
YüksekCVSS 8,8Kavram kanıtıEPSS %1rapid7 · nexpose3 Tem 2019
- CVE-2023-024235İzleyin
Insufficient permission check in the VQL copy() function
YüksekCVSS 8,8İstismar yokEPSS %1rapid7 · velociraptor18 Oca 2023
- CVE-2019-563834İzleyin
Rapid7 Nexpose Insufficient Session Management
YüksekCVSS 8,7İstismar yokEPSS %1rapid7 · nexpose21 Ağu 2019
- CVE-2017-524334İzleyin
The default SSH configuration in Rapid7 Nexpose hardware appliances shipped before June 2017 does not specify desired algorithms for key exc
YüksekCVSS 8,5İstismar yokEPSS %1rapid7 · nexpose6 Haz 2017
- CVE-2026-648234İzleyin
Local Privilege Escalation via OpenSSL configuration file in Insight Agent
YüksekCVSS 8,5İstismar yokEPSS %0rapid7 · insight agent17 Nis 2026
- CVE-2024-1052634İzleyin
Rapid7 Velociraptor Local Privilege Escalation In Windows Velociraptor Service
YüksekCVSS 8,6İstismar yokEPSS %0rapid7 · velociraptor7 Kas 2024
- CVE-2020-735033İzleyin
Metasploit Framework Plugin Libnotify Command Injection
YüksekCVSS 7,8SilahlaştırılmışEPSS %5rapid7 · metasploit22 Nis 2020