Rapid7 / Metasploit
17 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2023-0599 | Rapid7 Metasploit Pro Stored XSS | MEDIUM | 6.1 | Feb 1, 2023 |
| CVE-2020-7385 | Metasploit Framework 'drb_remote_codeexec' code execution | HIGH | 8.8 | Apr 23, 2021 |
| CVE-2020-7384 | Client-Side Command Injection in Rapid7 Metasploit | HIGH | 7.8 | Oct 29, 2020 |
| CVE-2019-5645 | Rapid7 Metasploit HTTP Handler Denial of Service | HIGH | 7.5 | Sep 1, 2020 |
| CVE-2020-7377 | Rapid7 Metasploit Framework Relative Path Traversal in telpho10_credential_dump module | HIGH | 8.1 | Aug 24, 2020 |
| CVE-2020-7376 | Rapid7 Metasploit Framework Relative Path Traversal in enum_osx module | CRITICAL | 9.8 | Aug 24, 2020 |
| CVE-2020-7355 | Rapid7 Metasploit Pro Stored XSS in 'notes' field | MEDIUM | 6.1 | Jun 25, 2020 |
| CVE-2020-7354 | Rapid7 Metasploit Pro Stored XSS in 'host' field | MEDIUM | 6.1 | Jun 25, 2020 |
| CVE-2020-7350 | Metasploit Framework Plugin Libnotify Command Injection | HIGH | 7.8 | Apr 22, 2020 |
| CVE-2019-5642 | MAGICK | LOW | 3.3 | Nov 6, 2019 |
| CVE-2019-5624 | Rapid7 Metasploit Framework Zip Import Directory Traversal | HIGH | 7.3 | Apr 30, 2019 |
| CVE-2017-15084 | The web UI in Rapid7 Metasploit before 4.14.1-20170828 allows logout CSRF, aka R7-2017-22. | MEDIUM | 6.5 | Oct 6, 2017 |
| CVE-2017-5244 | Routes used to stop running Metasploit tasks (either particular ones or all tasks) allowed GET requests. Only POST requests should have been allowed, as the st… | LOW | 3.5 | Jun 15, 2017 |
| CVE-2017-5235 | Rapid7 Metasploit Pro installers prior to version 4.13.0-2017022101 contain a DLL preloading vulnerability, wherein it is possible for the installer to load a… | HIGH | 7.8 | Mar 2, 2017 |
| CVE-2017-5231 | All editions of Rapid7 Metasploit prior to version 4.13.0-2017020701 contain a directory traversal vulnerability in the Meterpreter stdapi CommandDispatcher.cm… | HIGH | 7.1 | Mar 2, 2017 |
| CVE-2017-5229 | All editions of Rapid7 Metasploit prior to version 4.13.0-2017020701 contain a directory traversal vulnerability in the Meterpreter extapi Clipboard.parse_dump… | HIGH | 7.1 | Mar 2, 2017 |
| CVE-2017-5228 | All editions of Rapid7 Metasploit prior to version 4.13.0-2017020701 contain a directory traversal vulnerability in the Meterpreter stdapi Dir.download() funct… | HIGH | 7.1 | Mar 2, 2017 |
Showing 1 to 17 of 17 CVEs