Vulnerabilities > Rapid7 > Metasploit > Critical

DATE CVE VULNERABILITY TITLE RISK
2020-10-29 CVE-2020-7384 Command Injection vulnerability in Rapid7 Metasploit
Rapid7's Metasploit msfvenom framework handles APK files in a way that allows for a malicious user to craft and publish a file that would execute arbitrary commands on a victim's machine.
network
rapid7 CWE-77
critical
9.3
2020-08-24 CVE-2020-7376 Path Traversal vulnerability in Rapid7 Metasploit
The Metasploit Framework module "post/osx/gather/enum_osx module" is affected by a relative path traversal vulnerability in the get_keychains method which can be exploited to write arbitrary files to arbitrary locations on the host filesystem when the module is run on a malicious host.
network
low complexity
rapid7 CWE-22
critical
10.0