Vulnerabilidades em Rapid7

121 resultados
Análise Vexday

O portfólio de vulnerabilidades da Rapid7 soma 100 CVEs catalogadas, com taxa de exploração ativa abaixo da média geral do catálogo — nenhuma entrada registrada no CISA KEV —, o que indica pressão operacional relativamente contida no momento. Ainda assim, 21 CVEs surgiram nos últimos 90 dias, sinalizando ritmo de descoberta recente que merece monitoramento contínuo. A falha mais comum é do tipo CWE-78 (OS Command Injection), categoria de alto impacto que facilita execução de comandos arbitrários quando explorada com sucesso. A CVE mais perigosa ativa no momento é CVE-2019-5645, com escore EPSS de 0,42, indicando probabilidade não desprezível de exploração — sendo prudente verificar se os controles de mitigação aplicáveis estão em vigor nos ambientes afetados.

CVE-2017-5234Rapid7 Insight Collector installers prior to version 1.0.16 contain a DLL preloading vulnerability, wherein it is possible for the installerEPSS 1.2%CVE-2017-5228All editions of Rapid7 Metasploit prior to version 4.13.0-2017020701 contain a directory traversal vulnerability in the Meterpreter stdapi DEPSS 1.1%CVE-2017-5229All editions of Rapid7 Metasploit prior to version 4.13.0-2017020701 contain a directory traversal vulnerability in the Meterpreter extapi CEPSS 1.1%CVE-2017-5231All editions of Rapid7 Metasploit prior to version 4.13.0-2017020701 contain a directory traversal vulnerability in the Meterpreter stdapi CEPSS 1.1%CVE-2020-7383MEDIUMSQL Injection in Rapid7 NexposeEPSS 1.1%CVE-2020-7376HIGHRapid7 Metasploit Framework Relative Path Traversal in enum_osx moduleEPSS 1.1%CVE-2023-1304HIGHRapid7 InsightCloudSec getattr() method accessEPSS 1.1%CVE-2020-7377HIGHRapid7 Metasploit Framework Relative Path Traversal in telpho10_credential_dump moduleEPSS 1.1%CVE-2019-5631HIGHRapid7 InsightAppSec Local Privilege EscalationEPSS 1.1%CVE-2025-6264MEDIUMVelociraptor priviledge escalation via UpdateConfig artifactEPSS 1.0%CVE-2017-5240Editions of Rapid7 AppSpider Pro prior to version 6.14.060 contain a heap-based buffer overflow in the FLAnalyzer.exe component. A maliciousEPSS 1.0%CVE-2017-5232All editions of Rapid7 Nexpose installers prior to version 6.4.24 contain a DLL preloading vulnerability, wherein it is possible for the insEPSS 1.0%CVE-2019-5638HIGHRapid7 Nexpose Insufficient Session ManagementEPSS 1.0%CVE-2017-5236Editions of Rapid7 AppSpider Pro installers prior to version 6.14.060 contain a DLL preloading vulnerability, wherein it is possible for theEPSS 1.0%CVE-2019-5629HIGHRapid7 Insight Agent, version 2.6.3 and prior, suffers from a local privilege escalation due to an uncontrolled DLL search path. SpecificallEPSS 0.9%CVE-2020-7355MEDIUMRapid7 Metasploit Pro Stored XSS in 'notes' fieldEPSS 0.9%CVE-2016-9757In the Create Tags page of the Rapid7 Nexpose version 6.4.12 user interface, any authenticated user who has the capability to create tags caEPSS 0.9%CVE-2020-7354MEDIUMRapid7 Metasploit Pro Stored XSS in 'host' fieldEPSS 0.9%CVE-2019-5630MEDIUMRapid7 Nexpose/InsightVM Security Console CSRFEPSS 0.9%CVE-2017-5233Rapid7 AppSpider Pro installers prior to version 6.14.053 contain a DLL preloading vulnerability, wherein it is possible for the installer tEPSS 0.9%