Vulnerabilidades em Rapid7

121 resultados
Análise Vexday

O portfólio de vulnerabilidades da Rapid7 soma 100 CVEs catalogadas, com taxa de exploração ativa abaixo da média geral do catálogo — nenhuma entrada registrada no CISA KEV —, o que indica pressão operacional relativamente contida no momento. Ainda assim, 21 CVEs surgiram nos últimos 90 dias, sinalizando ritmo de descoberta recente que merece monitoramento contínuo. A falha mais comum é do tipo CWE-78 (OS Command Injection), categoria de alto impacto que facilita execução de comandos arbitrários quando explorada com sucesso. A CVE mais perigosa ativa no momento é CVE-2019-5645, com escore EPSS de 0,42, indicando probabilidade não desprezível de exploração — sendo prudente verificar se os controles de mitigação aplicáveis estão em vigor nos ambientes afetados.

CVE-2021-4016MEDIUMRapid7 Insight Agent Improper Access ControlEPSS 0.2%CVE-2026-15371HIGHVelociraptor Stored XSS in URL column typesEPSS 0.2%CVE-2026-19584HIGHVelociraptor VQL injection during notebook restore from backupEPSS 0.2%CVE-2025-4951MEDIUMEditions of Rapid7 AppSpider Pro before version 7.5.018 is vulnerable to a stored cross-site scripting vulnerability in the "ScanName" fieldEPSS 0.2%CVE-2024-8042LOWRapid7 Insight Platform Unauthorized Empty Group CreationEPSS 0.2%CVE-2024-2745LOWRapid7 InsightVM Sensitive Information Exposure via URLEPSS 0.2%CVE-2026-6482HIGHLocal Privilege Escalation via OpenSSL configuration file in Insight AgentEPSS 0.2%CVE-2026-64952MEDIUMVelociraptor Hunt Deletion With Insufficient Permission CheckEPSS 0.2%CVE-2024-3185MEDIUMRapid7 Insight Agent Sensitive Key Exposed To Local UsersEPSS 0.2%CVE-2026-7373HIGHMetasploit Pro on Windows: Local Privilege Escalation via OpenSSL Configuration File LoadingEPSS 0.2%CVE-2024-10526HIGHRapid7 Velociraptor Local Privilege Escalation In Windows Velociraptor ServiceEPSS 0.2%CVE-2026-64951LOWVelociraptor DoS triggered by Divide by Zero panicEPSS 0.2%CVE-2026-16895MEDIUMAuthentication Bypass in Metasploit JSON-RPC Service When DB Health Check FailsEPSS 0.2%CVE-2026-1814MEDIUMRapid7 Nexpose Insecure Java Keystore Password GenerationEPSS 0.2%CVE-2026-8795HIGHA YAML injection vulnerability exists in the Windows.Collectors.Remapping artifact of Rapid7 Velociraptor before version 0.76.6. The hostnamEPSS 0.1%CVE-2026-1568CRITICALRapid7 InsightVM Signature Validation VulnerabilityEPSS 0.1%CVE-2025-36857LOWRapid7 Appspider Broken Access Control VulnerabilityEPSS 0.1%CVE-2026-17535MEDIUMVelociraptor Multiple Crashes in NTFS Parser when applied to invalid NTFS VolumesEPSS 0.1%CVE-2026-14172HIGHRapid7 InsightVM, Nexpose, and Insight Agent Local Privilege Escalation via Unvalidated Executable InvocationEPSS 0.1%CVE-2025-11195LOWRapid7 AppSpider Project Name Validation BypassEPSS 0.1%