Записи Rapid7
94 опубликованных записей вендора rapid7.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 3 · 3,2 %
- Pre-auth RCE
- 4
- С записью об исправлении
- 24,5 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')12
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')9
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')8
- CWE-426 Untrusted Search Path5
- CWE-352 Cross-Site Request Forgery (CSRF)5
- CWE-427 Uncontrolled Search Path Element4
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
94 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
43В плане | CVE-2019-5645Готовый эксплойт | Rapid7 Metasploit HTTP Handler Denial of Servicerapid7 · metasploit · CWE-400 | Высокая7,5 | — | 41,7 % | 1 сент. 2020 г. |
40В плане | CVE-2020-7384Готовый эксплойт | Client-Side Command Injection in Rapid7 Metasploitrapid7 · metasploit · CWE-77 | Высокая7,8 | — | 30,5 % | 29 окт. 2020 г. |
39Наблюдать | CVE-2026-8592Эксплойта нет | OS Command Injection in Rapid7 InsightConnect AWK Pluginrapid7 · insightconnect awk · CWE-78 | Критическая9,8 | — | 1,2 % | 24 июн. 2026 г. |
39Наблюдать | CVE-2026-8660Эксплойта нет | OS Command Injection in Rapid7 InsightConnect Ping Pluginrapid7 · insightconnect ping · CWE-78 | Критическая9,8 | — | 1,2 % | 24 июн. 2026 г. |
39Наблюдать | CVE-2026-8665Эксплойта нет | OS Command Injection in Rapid7 InsightConnect Translate Pluginrapid7 · insightconnect translate · CWE-78 | Критическая9,8 | — | 1,2 % | 24 июн. 2026 г. |
39Наблюдать | CVE-2026-8666Эксплойта нет | OS Command Injection in Rapid7 InsightConnect Traceroute Pluginrapid7 · insightconnect traceroute · CWE-78 | Критическая9,8 | — | 1,2 % | 24 июн. 2026 г. |
39Наблюдать | CVE-2020-7376Эксплойта нет | Rapid7 Metasploit Framework Relative Path Traversal in enum_osx modulerapid7 · metasploit · CWE-23 | Критическая9,8 | — | 1,1 % | 24 авг. 2020 г. |
39Наблюдать | CVE-2023-1699Эксплойта нет | Rapid7 Nexpose Forced Browsingrapid7 · nexpose · CWE-425 | Критическая9,8 | — | 0,4 % | 30 мар. 2023 г. |
36Наблюдать | CVE-2017-5264Proof of concept | Versions of Nexpose prior to 6.4.66 fail to adequately validate the source of HTTP requests intended for the Automated Actions administrativrapid7 · nexpose · CWE-352 | Высокая8,8 | — | 2,7 % | 14 дек. 2017 г. |
36Наблюдать | CVE-2020-7385Эксплойта нет | Metasploit Framework 'drb_remote_codeexec' code executionrapid7 · metasploit · CWE-502 | Высокая8,8 | — | 1,8 % | 23 апр. 2021 г. |
36Наблюдать | CVE-2026-6290Эксплойта нет | Velociraptor Query() Plugin Misapplies Permissions To Orgsrapid7 · velociraptor · CWE-863 | Критическая9,1 | — | 0,4 % | 15 апр. 2026 г. |
35Наблюдать | CVE-2026-8663Эксплойта нет | OS Command Injection in Rapid7 InsightConnect RPM Pluginrapid7 · insightconnect rpm · CWE-78 | Высокая8,8 | — | 1,3 % | 24 июн. 2026 г. |
35Наблюдать | CVE-2026-8659Эксплойта нет | OS Command Injection in Rapid7 InsightConnect SQLmap Pluginrapid7 · insightconnect sqlmap · CWE-78 | Высокая8,8 | — | 1,3 % | 24 июн. 2026 г. |
35Наблюдать | CVE-2026-8664Эксплойта нет | OS Command Injection in Rapid7 InsightConnect Finger Pluginrapid7 · insightconnect finger · CWE-78 | Высокая8,8 | — | 1,3 % | 24 июн. 2026 г. |
35Наблюдать | CVE-2026-8658Эксплойта нет | OS Command Injection in Rapid7 InsightConnect Tcpdump Pluginrapid7 · insightconnect tcpdump · CWE-78 | Высокая8,8 | — | 1,3 % | 24 июн. 2026 г. |
35Наблюдать | CVE-2022-0757Эксплойта нет | Rapid7 Nexpose SQL Injectionrapid7 · nexpose · CWE-89 | Высокая8,8 | — | 1,2 % | 17 мар. 2022 г. |
35Наблюдать | CVE-2023-1306Эксплойта нет | Rapid7 InsightCloudSec resource.db() method accessrapid7 · insightappsec · CWE-94 | Высокая8,8 | — | 1,2 % | 21 мар. 2023 г. |
35Наблюдать | CVE-2023-1304Эксплойта нет | Rapid7 InsightCloudSec getattr() method accessrapid7 · insightappsec · CWE-94 | Высокая8,8 | — | 1,1 % | 21 мар. 2023 г. |
35Наблюдать | CVE-2019-5630Proof of concept | Rapid7 Nexpose/InsightVM Security Console CSRFrapid7 · nexpose · CWE-352 | Высокая8,8 | — | 0,9 % | 3 июл. 2019 г. |
35Наблюдать | CVE-2023-0242Эксплойта нет | Insufficient permission check in the VQL copy() functionrapid7 · velociraptor · CWE-269 | Высокая8,8 | — | 0,5 % | 18 янв. 2023 г. |
34Наблюдать | CVE-2019-5638Эксплойта нет | Rapid7 Nexpose Insufficient Session Managementrapid7 · nexpose · CWE-613 | Высокая8,7 | — | 1,0 % | 21 авг. 2019 г. |
34Наблюдать | CVE-2017-5243Эксплойта нет | The default SSH configuration in Rapid7 Nexpose hardware appliances shipped before June 2017 does not specify desired algorithms for key excrapid7 · nexpose · CWE-327 | Высокая8,5 | — | 0,5 % | 6 июн. 2017 г. |
34Наблюдать | CVE-2026-6482Эксплойта нет | Local Privilege Escalation via OpenSSL configuration file in Insight Agentrapid7 · insight agent · CWE-829 | Высокая8,5 | — | 0,2 % | 17 апр. 2026 г. |
34Наблюдать | CVE-2024-10526Эксплойта нет | Rapid7 Velociraptor Local Privilege Escalation In Windows Velociraptor Servicerapid7 · velociraptor · CWE-552 | Высокая8,6 | — | 0,2 % | 7 нояб. 2024 г. |
33Наблюдать | CVE-2020-7350Готовый эксплойт | Metasploit Framework Plugin Libnotify Command Injectionrapid7 · metasploit · CWE-78 | Высокая7,8 | — | 5,0 % | 22 апр. 2020 г. |
- CVE-2019-564543В плане
Rapid7 Metasploit HTTP Handler Denial of Service
ВысокаяCVSS 7,5Готовый эксплойтEPSS 42 %rapid7 · metasploit1 сент. 2020 г.
- CVE-2020-738440В плане
Client-Side Command Injection in Rapid7 Metasploit
ВысокаяCVSS 7,8Готовый эксплойтEPSS 30 %rapid7 · metasploit29 окт. 2020 г.
- CVE-2026-859239Наблюдать
OS Command Injection in Rapid7 InsightConnect AWK Plugin
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %rapid7 · insightconnect awk24 июн. 2026 г.
- CVE-2026-866039Наблюдать
OS Command Injection in Rapid7 InsightConnect Ping Plugin
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %rapid7 · insightconnect ping24 июн. 2026 г.
- CVE-2026-866539Наблюдать
OS Command Injection in Rapid7 InsightConnect Translate Plugin
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %rapid7 · insightconnect translate24 июн. 2026 г.
- CVE-2026-866639Наблюдать
OS Command Injection in Rapid7 InsightConnect Traceroute Plugin
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %rapid7 · insightconnect traceroute24 июн. 2026 г.
- CVE-2020-737639Наблюдать
Rapid7 Metasploit Framework Relative Path Traversal in enum_osx module
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %rapid7 · metasploit24 авг. 2020 г.
- CVE-2023-169939Наблюдать
Rapid7 Nexpose Forced Browsing
КритическаяCVSS 9,8Эксплойта нетEPSS 0 %rapid7 · nexpose30 мар. 2023 г.
- CVE-2017-526436Наблюдать
Versions of Nexpose prior to 6.4.66 fail to adequately validate the source of HTTP requests intended for the Automated Actions administrativ
ВысокаяCVSS 8,8Proof of conceptEPSS 3 %rapid7 · nexpose14 дек. 2017 г.
- CVE-2020-738536Наблюдать
Metasploit Framework 'drb_remote_codeexec' code execution
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %rapid7 · metasploit23 апр. 2021 г.
- CVE-2026-629036Наблюдать
Velociraptor Query() Plugin Misapplies Permissions To Orgs
КритическаяCVSS 9,1Эксплойта нетEPSS 0 %rapid7 · velociraptor15 апр. 2026 г.
- CVE-2026-866335Наблюдать
OS Command Injection in Rapid7 InsightConnect RPM Plugin
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %rapid7 · insightconnect rpm24 июн. 2026 г.
- CVE-2026-865935Наблюдать
OS Command Injection in Rapid7 InsightConnect SQLmap Plugin
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %rapid7 · insightconnect sqlmap24 июн. 2026 г.
- CVE-2026-866435Наблюдать
OS Command Injection in Rapid7 InsightConnect Finger Plugin
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %rapid7 · insightconnect finger24 июн. 2026 г.
- CVE-2026-865835Наблюдать
OS Command Injection in Rapid7 InsightConnect Tcpdump Plugin
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %rapid7 · insightconnect tcpdump24 июн. 2026 г.
- CVE-2022-075735Наблюдать
Rapid7 Nexpose SQL Injection
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %rapid7 · nexpose17 мар. 2022 г.
- CVE-2023-130635Наблюдать
Rapid7 InsightCloudSec resource.db() method access
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %rapid7 · insightappsec21 мар. 2023 г.
- CVE-2023-130435Наблюдать
Rapid7 InsightCloudSec getattr() method access
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %rapid7 · insightappsec21 мар. 2023 г.
- CVE-2019-563035Наблюдать
Rapid7 Nexpose/InsightVM Security Console CSRF
ВысокаяCVSS 8,8Proof of conceptEPSS 1 %rapid7 · nexpose3 июл. 2019 г.
- CVE-2023-024235Наблюдать
Insufficient permission check in the VQL copy() function
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %rapid7 · velociraptor18 янв. 2023 г.
- CVE-2019-563834Наблюдать
Rapid7 Nexpose Insufficient Session Management
ВысокаяCVSS 8,7Эксплойта нетEPSS 1 %rapid7 · nexpose21 авг. 2019 г.
- CVE-2017-524334Наблюдать
The default SSH configuration in Rapid7 Nexpose hardware appliances shipped before June 2017 does not specify desired algorithms for key exc
ВысокаяCVSS 8,5Эксплойта нетEPSS 1 %rapid7 · nexpose6 июн. 2017 г.
- CVE-2026-648234Наблюдать
Local Privilege Escalation via OpenSSL configuration file in Insight Agent
ВысокаяCVSS 8,5Эксплойта нетEPSS 0 %rapid7 · insight agent17 апр. 2026 г.
- CVE-2024-1052634Наблюдать
Rapid7 Velociraptor Local Privilege Escalation In Windows Velociraptor Service
ВысокаяCVSS 8,6Эксплойта нетEPSS 0 %rapid7 · velociraptor7 нояб. 2024 г.
- CVE-2020-735033Наблюдать
Metasploit Framework Plugin Libnotify Command Injection
ВысокаяCVSS 7,8Готовый эксплойтEPSS 5 %rapid7 · metasploit22 апр. 2020 г.