Vulnerabilidades en Rapid7

121 resultados
Análisis Vexday

O portfólio de vulnerabilidades da Rapid7 soma 100 CVEs catalogadas, com taxa de exploração ativa abaixo da média geral do catálogo — nenhuma entrada registrada no CISA KEV —, o que indica pressão operacional relativamente contida no momento. Ainda assim, 21 CVEs surgiram nos últimos 90 dias, sinalizando ritmo de descoberta recente que merece monitoramento contínuo. A falha mais comum é do tipo CWE-78 (OS Command Injection), categoria de alto impacto que facilita execução de comandos arbitrários quando explorada com sucesso. A CVE mais perigosa ativa no momento é CVE-2019-5645, com escore EPSS de 0,42, indicando probabilidade não desprezível de exploração — sendo prudente verificar se os controles de mitigação aplicáveis estão em vigor nos ambientes afetados.

CVE-2026-8665HIGHOS Command Injection in Rapid7 InsightConnect Translate PluginEPSS 1.2%CVE-2026-8592HIGHOS Command Injection in Rapid7 InsightConnect AWK PluginEPSS 1.2%CVE-2020-7383MEDIUMSQL Injection in Rapid7 NexposeEPSS 1.1%CVE-2020-7376HIGHRapid7 Metasploit Framework Relative Path Traversal in enum_osx moduleEPSS 1.1%CVE-2023-1304HIGHRapid7 InsightCloudSec getattr() method accessEPSS 1.1%CVE-2020-7377HIGHRapid7 Metasploit Framework Relative Path Traversal in telpho10_credential_dump moduleEPSS 1.1%CVE-2019-5631HIGHRapid7 InsightAppSec Local Privilege EscalationEPSS 1.1%CVE-2025-6264MEDIUMVelociraptor priviledge escalation via UpdateConfig artifactEPSS 1.0%CVE-2017-5240Editions of Rapid7 AppSpider Pro prior to version 6.14.060 contain a heap-based buffer overflow in the FLAnalyzer.exe component. A maliciousEPSS 1.0%CVE-2019-5638HIGHRapid7 Nexpose Insufficient Session ManagementEPSS 1.0%CVE-2019-5629HIGHRapid7 Insight Agent, version 2.6.3 and prior, suffers from a local privilege escalation due to an uncontrolled DLL search path. SpecificallEPSS 0.9%CVE-2017-5236Editions of Rapid7 AppSpider Pro installers prior to version 6.14.060 contain a DLL preloading vulnerability, wherein it is possible for theEPSS 0.9%CVE-2017-5235Rapid7 Metasploit Pro installers prior to version 4.13.0-2017022101 contain a DLL preloading vulnerability, wherein it is possible for the iEPSS 0.9%CVE-2017-5234Rapid7 Insight Collector installers prior to version 1.0.16 contain a DLL preloading vulnerability, wherein it is possible for the installerEPSS 0.9%CVE-2019-5630MEDIUMRapid7 Nexpose/InsightVM Security Console CSRFEPSS 0.9%CVE-2020-7354MEDIUMRapid7 Metasploit Pro Stored XSS in 'host' fieldEPSS 0.9%CVE-2020-7355MEDIUMRapid7 Metasploit Pro Stored XSS in 'notes' fieldEPSS 0.9%CVE-2017-5233Rapid7 AppSpider Pro installers prior to version 6.14.053 contain a DLL preloading vulnerability, wherein it is possible for the installer tEPSS 0.9%CVE-2019-5615LOWRapid7 InsightVM Stored Credential ExposureEPSS 0.8%CVE-2023-1305HIGHRapid7 InsightCloudSec box object access EPSS 0.8%