Vulnerabilidades em Rapid7

121 resultados
Análise Vexday

O portfólio de vulnerabilidades da Rapid7 soma 100 CVEs catalogadas, com taxa de exploração ativa abaixo da média geral do catálogo — nenhuma entrada registrada no CISA KEV —, o que indica pressão operacional relativamente contida no momento. Ainda assim, 21 CVEs surgiram nos últimos 90 dias, sinalizando ritmo de descoberta recente que merece monitoramento contínuo. A falha mais comum é do tipo CWE-78 (OS Command Injection), categoria de alto impacto que facilita execução de comandos arbitrários quando explorada com sucesso. A CVE mais perigosa ativa no momento é CVE-2019-5645, com escore EPSS de 0,42, indicando probabilidade não desprezível de exploração — sendo prudente verificar se os controles de mitigação aplicáveis estão em vigor nos ambientes afetados.

CVE-2019-5645HIGHRapid7 Metasploit HTTP Handler Denial of ServiceEPSS 41.7%CVE-2020-7384HIGHClient-Side Command Injection in Rapid7 MetasploitEPSS 30.5%CVE-2026-18972CRITICALVelociraptor authenticated identity-spoofing vulnerabilityEPSS 6.1%CVE-2020-7350MEDIUMMetasploit Framework Plugin Libnotify Command InjectionEPSS 5.0%CVE-2019-5624HIGHRapid7 Metasploit Framework Zip Import Directory TraversalEPSS 2.8%CVE-2017-5264Versions of Nexpose prior to 6.4.66 fail to adequately validate the source of HTTP requests intended for the Automated Actions administrativEPSS 2.7%CVE-2020-7385HIGHMetasploit Framework 'drb_remote_codeexec' code executionEPSS 1.8%CVE-2026-9155HIGHOS Command Injection in Rapid7 InsightConnect Sed Plugin via expression parameter.EPSS 1.6%CVE-2017-5230The Java keystore in all versions and editions of Rapid7 Nexpose prior to 6.4.50 is encrypted with a static password of 'r@p1d7k3y5t0r3' whiEPSS 1.5%CVE-2026-8658MEDIUMOS Command Injection in Rapid7 InsightConnect Tcpdump PluginEPSS 1.3%CVE-2026-8659MEDIUMOS Command Injection in Rapid7 InsightConnect SQLmap PluginEPSS 1.3%CVE-2026-8664MEDIUMOS Command Injection in Rapid7 InsightConnect Finger PluginEPSS 1.3%CVE-2026-8663MEDIUMOS Command Injection in Rapid7 InsightConnect RPM PluginEPSS 1.3%CVE-2022-0757MEDIUMRapid7 Nexpose SQL InjectionEPSS 1.2%CVE-2017-5231All editions of Rapid7 Metasploit prior to version 4.13.0-2017020701 contain a directory traversal vulnerability in the Meterpreter stdapi CEPSS 1.2%CVE-2017-5228All editions of Rapid7 Metasploit prior to version 4.13.0-2017020701 contain a directory traversal vulnerability in the Meterpreter stdapi DEPSS 1.2%CVE-2017-5229All editions of Rapid7 Metasploit prior to version 4.13.0-2017020701 contain a directory traversal vulnerability in the Meterpreter extapi CEPSS 1.2%CVE-2023-1306HIGHRapid7 InsightCloudSec resource.db() method accessEPSS 1.2%CVE-2026-8660HIGHOS Command Injection in Rapid7 InsightConnect Ping PluginEPSS 1.2%CVE-2026-8592HIGHOS Command Injection in Rapid7 InsightConnect AWK PluginEPSS 1.2%