Vulnerabilidades em Rapid7

121 resultados
Análise Vexday

O portfólio de vulnerabilidades da Rapid7 soma 100 CVEs catalogadas, com taxa de exploração ativa abaixo da média geral do catálogo — nenhuma entrada registrada no CISA KEV —, o que indica pressão operacional relativamente contida no momento. Ainda assim, 21 CVEs surgiram nos últimos 90 dias, sinalizando ritmo de descoberta recente que merece monitoramento contínuo. A falha mais comum é do tipo CWE-78 (OS Command Injection), categoria de alto impacto que facilita execução de comandos arbitrários quando explorada com sucesso. A CVE mais perigosa ativa no momento é CVE-2019-5645, com escore EPSS de 0,42, indicando probabilidade não desprezível de exploração — sendo prudente verificar se os controles de mitigação aplicáveis estão em vigor nos ambientes afetados.

CVE-2017-5232All editions of Rapid7 Nexpose installers prior to version 6.4.24 contain a DLL preloading vulnerability, wherein it is possible for the insEPSS 0.8%CVE-2023-0290MEDIUMRapid7 Velociraptor directory traversal in client ID parameter EPSS 0.7%CVE-2023-2273MEDIUMRapid7 Insight Agent Directory TraversalEPSS 0.7%CVE-2017-5244Routes used to stop running Metasploit tasks (either particular ones or all tasks) allowed GET requests. Only POST requests should have beenEPSS 0.7%CVE-2020-7381MEDIUMCode Injection in Rapid7 Nexpose InstallerEPSS 0.7%CVE-2016-9757In the Create Tags page of the Rapid7 Nexpose version 6.4.12 user interface, any authenticated user who has the capability to create tags caEPSS 0.6%CVE-2018-5559LOWIn Rapid7 Komand version 0.41.0 and prior, certain endpoints that are able to list the always encrypted-at-rest connection data could returnEPSS 0.6%CVE-2026-19583CRITICALVelociraptor Required Permissions bypass by using client monitoring queriesEPSS 0.6%CVE-2021-3535MEDIUMRapid7 Nexpose is vulnerable to a non-persistent cross-site scripting vulnerability affecting the Security Console's Filtered Asset Search fEPSS 0.6%CVE-2021-3619LOWRapid7 Velociraptor Notebooks Authenticated Persistent XSSEPSS 0.6%CVE-2025-14728MEDIUMRapid7 Velociraptor Directory Traversal VulnerabilityEPSS 0.5%CVE-2023-0242HIGHInsufficient permission check in the VQL copy() functionEPSS 0.5%CVE-2019-5640LOWRapid7 Nexpose Information Disclosure after logoutEPSS 0.5%CVE-2017-5243The default SSH configuration in Rapid7 Nexpose hardware appliances shipped before June 2017 does not specify desired algorithms for key excEPSS 0.5%CVE-2022-35630Unsafe HTML Injection in Artifact Collection ReportEPSS 0.5%CVE-2022-0237MEDIUMRapid7 Insight Agent Privilege EscalationEPSS 0.5%CVE-2021-31868MEDIUMRapid7 Nexpose Security Console Ticket Access Authentication VulnerabilityEPSS 0.5%CVE-2022-35632XSS in User InterfaceEPSS 0.5%CVE-2023-5950HIGHRapid7 Velociraptor Reflected XSS EPSS 0.5%CVE-2026-5329HIGHRapid7 Velociraptor Improper Input Validation in Client Message HandlerEPSS 0.5%