Skip to content
Noroxi

Rapid7 records

94 published records for vendor rapid7.

All records

94 records
  • Rapid7 Metasploit HTTP Handler Denial of Service

    HighCVSS 7.5WeaponizedEPSS 42%

    rapid7 · metasploitSep 1, 2020

  • Client-Side Command Injection in Rapid7 Metasploit

    HighCVSS 7.8WeaponizedEPSS 30%

    rapid7 · metasploitOct 29, 2020

  • CVE-2026-8592
    39Monitor

    OS Command Injection in Rapid7 InsightConnect AWK Plugin

    CriticalCVSS 9.8No exploitEPSS 1%

    rapid7 · insightconnect awkJun 24, 2026

  • CVE-2026-8660
    39Monitor

    OS Command Injection in Rapid7 InsightConnect Ping Plugin

    CriticalCVSS 9.8No exploitEPSS 1%

    rapid7 · insightconnect pingJun 24, 2026

  • CVE-2026-8665
    39Monitor

    OS Command Injection in Rapid7 InsightConnect Translate Plugin

    CriticalCVSS 9.8No exploitEPSS 1%

    rapid7 · insightconnect translateJun 24, 2026

  • CVE-2026-8666
    39Monitor

    OS Command Injection in Rapid7 InsightConnect Traceroute Plugin

    CriticalCVSS 9.8No exploitEPSS 1%

    rapid7 · insightconnect tracerouteJun 24, 2026

  • CVE-2020-7376
    39Monitor

    Rapid7 Metasploit Framework Relative Path Traversal in enum_osx module

    CriticalCVSS 9.8No exploitEPSS 1%

    rapid7 · metasploitAug 24, 2020

  • CVE-2023-1699
    39Monitor

    Rapid7 Nexpose Forced Browsing

    CriticalCVSS 9.8No exploitEPSS 0%

    rapid7 · nexposeMar 30, 2023

  • CVE-2017-5264
    36Monitor

    Versions of Nexpose prior to 6.4.66 fail to adequately validate the source of HTTP requests intended for the Automated Actions administrativ

    HighCVSS 8.8Proof of conceptEPSS 3%

    rapid7 · nexposeDec 14, 2017

  • CVE-2020-7385
    36Monitor

    Metasploit Framework 'drb_remote_codeexec' code execution

    HighCVSS 8.8No exploitEPSS 2%

    rapid7 · metasploitApr 23, 2021

  • CVE-2026-6290
    36Monitor

    Velociraptor Query() Plugin Misapplies Permissions To Orgs

    CriticalCVSS 9.1No exploitEPSS 0%

    rapid7 · velociraptorApr 15, 2026

  • CVE-2026-8663
    35Monitor

    OS Command Injection in Rapid7 InsightConnect RPM Plugin

    HighCVSS 8.8No exploitEPSS 1%

    rapid7 · insightconnect rpmJun 24, 2026

  • CVE-2026-8659
    35Monitor

    OS Command Injection in Rapid7 InsightConnect SQLmap Plugin

    HighCVSS 8.8No exploitEPSS 1%

    rapid7 · insightconnect sqlmapJun 24, 2026

  • CVE-2026-8664
    35Monitor

    OS Command Injection in Rapid7 InsightConnect Finger Plugin

    HighCVSS 8.8No exploitEPSS 1%

    rapid7 · insightconnect fingerJun 24, 2026

  • CVE-2026-8658
    35Monitor

    OS Command Injection in Rapid7 InsightConnect Tcpdump Plugin

    HighCVSS 8.8No exploitEPSS 1%

    rapid7 · insightconnect tcpdumpJun 24, 2026

  • CVE-2022-0757
    35Monitor

    Rapid7 Nexpose SQL Injection

    HighCVSS 8.8No exploitEPSS 1%

    rapid7 · nexposeMar 17, 2022

  • CVE-2023-1306
    35Monitor

    Rapid7 InsightCloudSec resource.db() method access

    HighCVSS 8.8No exploitEPSS 1%

    rapid7 · insightappsecMar 21, 2023

  • CVE-2023-1304
    35Monitor

    Rapid7 InsightCloudSec getattr() method access

    HighCVSS 8.8No exploitEPSS 1%

    rapid7 · insightappsecMar 21, 2023

  • CVE-2019-5630
    35Monitor

    Rapid7 Nexpose/InsightVM Security Console CSRF

    HighCVSS 8.8Proof of conceptEPSS 1%

    rapid7 · nexposeJul 3, 2019

  • CVE-2023-0242
    35Monitor

    Insufficient permission check in the VQL copy() function

    HighCVSS 8.8No exploitEPSS 1%

    rapid7 · velociraptorJan 18, 2023

  • CVE-2019-5638
    34Monitor

    Rapid7 Nexpose Insufficient Session Management

    HighCVSS 8.7No exploitEPSS 1%

    rapid7 · nexposeAug 21, 2019

  • CVE-2017-5243
    34Monitor

    The default SSH configuration in Rapid7 Nexpose hardware appliances shipped before June 2017 does not specify desired algorithms for key exc

    HighCVSS 8.5No exploitEPSS 1%

    rapid7 · nexposeJun 6, 2017

  • CVE-2026-6482
    34Monitor

    Local Privilege Escalation via OpenSSL configuration file in Insight Agent

    HighCVSS 8.5No exploitEPSS 0%

    rapid7 · insight agentApr 17, 2026

  • Rapid7 Velociraptor Local Privilege Escalation In Windows Velociraptor Service

    HighCVSS 8.6No exploitEPSS 0%

    rapid7 · velociraptorNov 7, 2024

  • CVE-2020-7350
    33Monitor

    Metasploit Framework Plugin Libnotify Command Injection

    HighCVSS 7.8WeaponizedEPSS 5%

    rapid7 · metasploitApr 22, 2020