Rapid7 records
94 published records for vendor rapid7.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 3 · 3.2%
- Pre-auth RCE
- 4
- With a fix record
- 25.5%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')12
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')9
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')8
- CWE-426 Untrusted Search Path5
- CWE-352 Cross-Site Request Forgery (CSRF)5
- CWE-427 Uncontrolled Search Path Element4
The weakness classes this vendor ships most often: where to look.
CWEAll records
94 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
43Plan | CVE-2019-5645Weaponized | Rapid7 Metasploit HTTP Handler Denial of Servicerapid7 · metasploit · CWE-400 | High7.5 | — | 41.7% | Sep 1, 2020 |
40Plan | CVE-2020-7384Weaponized | Client-Side Command Injection in Rapid7 Metasploitrapid7 · metasploit · CWE-77 | High7.8 | — | 30.5% | Oct 29, 2020 |
39Monitor | CVE-2026-8592No exploit | OS Command Injection in Rapid7 InsightConnect AWK Pluginrapid7 · insightconnect awk · CWE-78 | Critical9.8 | — | 1.2% | Jun 24, 2026 |
39Monitor | CVE-2026-8660No exploit | OS Command Injection in Rapid7 InsightConnect Ping Pluginrapid7 · insightconnect ping · CWE-78 | Critical9.8 | — | 1.2% | Jun 24, 2026 |
39Monitor | CVE-2026-8665No exploit | OS Command Injection in Rapid7 InsightConnect Translate Pluginrapid7 · insightconnect translate · CWE-78 | Critical9.8 | — | 1.2% | Jun 24, 2026 |
39Monitor | CVE-2026-8666No exploit | OS Command Injection in Rapid7 InsightConnect Traceroute Pluginrapid7 · insightconnect traceroute · CWE-78 | Critical9.8 | — | 1.2% | Jun 24, 2026 |
39Monitor | CVE-2020-7376No exploit | Rapid7 Metasploit Framework Relative Path Traversal in enum_osx modulerapid7 · metasploit · CWE-23 | Critical9.8 | — | 1.1% | Aug 24, 2020 |
39Monitor | CVE-2023-1699No exploit | Rapid7 Nexpose Forced Browsingrapid7 · nexpose · CWE-425 | Critical9.8 | — | 0.4% | Mar 30, 2023 |
36Monitor | CVE-2017-5264Proof of concept | Versions of Nexpose prior to 6.4.66 fail to adequately validate the source of HTTP requests intended for the Automated Actions administrativrapid7 · nexpose · CWE-352 | High8.8 | — | 2.7% | Dec 14, 2017 |
36Monitor | CVE-2020-7385No exploit | Metasploit Framework 'drb_remote_codeexec' code executionrapid7 · metasploit · CWE-502 | High8.8 | — | 1.8% | Apr 23, 2021 |
36Monitor | CVE-2026-6290No exploit | Velociraptor Query() Plugin Misapplies Permissions To Orgsrapid7 · velociraptor · CWE-863 | Critical9.1 | — | 0.4% | Apr 15, 2026 |
35Monitor | CVE-2026-8663No exploit | OS Command Injection in Rapid7 InsightConnect RPM Pluginrapid7 · insightconnect rpm · CWE-78 | High8.8 | — | 1.3% | Jun 24, 2026 |
35Monitor | CVE-2026-8659No exploit | OS Command Injection in Rapid7 InsightConnect SQLmap Pluginrapid7 · insightconnect sqlmap · CWE-78 | High8.8 | — | 1.3% | Jun 24, 2026 |
35Monitor | CVE-2026-8664No exploit | OS Command Injection in Rapid7 InsightConnect Finger Pluginrapid7 · insightconnect finger · CWE-78 | High8.8 | — | 1.3% | Jun 24, 2026 |
35Monitor | CVE-2026-8658No exploit | OS Command Injection in Rapid7 InsightConnect Tcpdump Pluginrapid7 · insightconnect tcpdump · CWE-78 | High8.8 | — | 1.3% | Jun 24, 2026 |
35Monitor | CVE-2022-0757No exploit | Rapid7 Nexpose SQL Injectionrapid7 · nexpose · CWE-89 | High8.8 | — | 1.2% | Mar 17, 2022 |
35Monitor | CVE-2023-1306No exploit | Rapid7 InsightCloudSec resource.db() method accessrapid7 · insightappsec · CWE-94 | High8.8 | — | 1.2% | Mar 21, 2023 |
35Monitor | CVE-2023-1304No exploit | Rapid7 InsightCloudSec getattr() method accessrapid7 · insightappsec · CWE-94 | High8.8 | — | 1.1% | Mar 21, 2023 |
35Monitor | CVE-2019-5630Proof of concept | Rapid7 Nexpose/InsightVM Security Console CSRFrapid7 · nexpose · CWE-352 | High8.8 | — | 0.9% | Jul 3, 2019 |
35Monitor | CVE-2023-0242No exploit | Insufficient permission check in the VQL copy() functionrapid7 · velociraptor · CWE-269 | High8.8 | — | 0.5% | Jan 18, 2023 |
34Monitor | CVE-2019-5638No exploit | Rapid7 Nexpose Insufficient Session Managementrapid7 · nexpose · CWE-613 | High8.7 | — | 1.0% | Aug 21, 2019 |
34Monitor | CVE-2017-5243No exploit | The default SSH configuration in Rapid7 Nexpose hardware appliances shipped before June 2017 does not specify desired algorithms for key excrapid7 · nexpose · CWE-327 | High8.5 | — | 0.5% | Jun 6, 2017 |
34Monitor | CVE-2026-6482No exploit | Local Privilege Escalation via OpenSSL configuration file in Insight Agentrapid7 · insight agent · CWE-829 | High8.5 | — | 0.2% | Apr 17, 2026 |
34Monitor | CVE-2024-10526No exploit | Rapid7 Velociraptor Local Privilege Escalation In Windows Velociraptor Servicerapid7 · velociraptor · CWE-552 | High8.6 | — | 0.2% | Nov 7, 2024 |
33Monitor | CVE-2020-7350Weaponized | Metasploit Framework Plugin Libnotify Command Injectionrapid7 · metasploit · CWE-78 | High7.8 | — | 5.0% | Apr 22, 2020 |
- CVE-2019-564543Plan
Rapid7 Metasploit HTTP Handler Denial of Service
HighCVSS 7.5WeaponizedEPSS 42%rapid7 · metasploitSep 1, 2020
- CVE-2020-738440Plan
Client-Side Command Injection in Rapid7 Metasploit
HighCVSS 7.8WeaponizedEPSS 30%rapid7 · metasploitOct 29, 2020
- CVE-2026-859239Monitor
OS Command Injection in Rapid7 InsightConnect AWK Plugin
CriticalCVSS 9.8No exploitEPSS 1%rapid7 · insightconnect awkJun 24, 2026
- CVE-2026-866039Monitor
OS Command Injection in Rapid7 InsightConnect Ping Plugin
CriticalCVSS 9.8No exploitEPSS 1%rapid7 · insightconnect pingJun 24, 2026
- CVE-2026-866539Monitor
OS Command Injection in Rapid7 InsightConnect Translate Plugin
CriticalCVSS 9.8No exploitEPSS 1%rapid7 · insightconnect translateJun 24, 2026
- CVE-2026-866639Monitor
OS Command Injection in Rapid7 InsightConnect Traceroute Plugin
CriticalCVSS 9.8No exploitEPSS 1%rapid7 · insightconnect tracerouteJun 24, 2026
- CVE-2020-737639Monitor
Rapid7 Metasploit Framework Relative Path Traversal in enum_osx module
CriticalCVSS 9.8No exploitEPSS 1%rapid7 · metasploitAug 24, 2020
- CVE-2023-169939Monitor
Rapid7 Nexpose Forced Browsing
CriticalCVSS 9.8No exploitEPSS 0%rapid7 · nexposeMar 30, 2023
- CVE-2017-526436Monitor
Versions of Nexpose prior to 6.4.66 fail to adequately validate the source of HTTP requests intended for the Automated Actions administrativ
HighCVSS 8.8Proof of conceptEPSS 3%rapid7 · nexposeDec 14, 2017
- CVE-2020-738536Monitor
Metasploit Framework 'drb_remote_codeexec' code execution
HighCVSS 8.8No exploitEPSS 2%rapid7 · metasploitApr 23, 2021
- CVE-2026-629036Monitor
Velociraptor Query() Plugin Misapplies Permissions To Orgs
CriticalCVSS 9.1No exploitEPSS 0%rapid7 · velociraptorApr 15, 2026
- CVE-2026-866335Monitor
OS Command Injection in Rapid7 InsightConnect RPM Plugin
HighCVSS 8.8No exploitEPSS 1%rapid7 · insightconnect rpmJun 24, 2026
- CVE-2026-865935Monitor
OS Command Injection in Rapid7 InsightConnect SQLmap Plugin
HighCVSS 8.8No exploitEPSS 1%rapid7 · insightconnect sqlmapJun 24, 2026
- CVE-2026-866435Monitor
OS Command Injection in Rapid7 InsightConnect Finger Plugin
HighCVSS 8.8No exploitEPSS 1%rapid7 · insightconnect fingerJun 24, 2026
- CVE-2026-865835Monitor
OS Command Injection in Rapid7 InsightConnect Tcpdump Plugin
HighCVSS 8.8No exploitEPSS 1%rapid7 · insightconnect tcpdumpJun 24, 2026
- CVE-2022-075735Monitor
Rapid7 Nexpose SQL Injection
HighCVSS 8.8No exploitEPSS 1%rapid7 · nexposeMar 17, 2022
- CVE-2023-130635Monitor
Rapid7 InsightCloudSec resource.db() method access
HighCVSS 8.8No exploitEPSS 1%rapid7 · insightappsecMar 21, 2023
- CVE-2023-130435Monitor
Rapid7 InsightCloudSec getattr() method access
HighCVSS 8.8No exploitEPSS 1%rapid7 · insightappsecMar 21, 2023
- CVE-2019-563035Monitor
Rapid7 Nexpose/InsightVM Security Console CSRF
HighCVSS 8.8Proof of conceptEPSS 1%rapid7 · nexposeJul 3, 2019
- CVE-2023-024235Monitor
Insufficient permission check in the VQL copy() function
HighCVSS 8.8No exploitEPSS 1%rapid7 · velociraptorJan 18, 2023
- CVE-2019-563834Monitor
Rapid7 Nexpose Insufficient Session Management
HighCVSS 8.7No exploitEPSS 1%rapid7 · nexposeAug 21, 2019
- CVE-2017-524334Monitor
The default SSH configuration in Rapid7 Nexpose hardware appliances shipped before June 2017 does not specify desired algorithms for key exc
HighCVSS 8.5No exploitEPSS 1%rapid7 · nexposeJun 6, 2017
- CVE-2026-648234Monitor
Local Privilege Escalation via OpenSSL configuration file in Insight Agent
HighCVSS 8.5No exploitEPSS 0%rapid7 · insight agentApr 17, 2026
- CVE-2024-1052634Monitor
Rapid7 Velociraptor Local Privilege Escalation In Windows Velociraptor Service
HighCVSS 8.6No exploitEPSS 0%rapid7 · velociraptorNov 7, 2024
- CVE-2020-735033Monitor
Metasploit Framework Plugin Libnotify Command Injection
HighCVSS 7.8WeaponizedEPSS 5%rapid7 · metasploitApr 22, 2020