Vulnerabilities > Rapid7 > Nexpose > Medium

DATE CVE VULNERABILITY TITLE RISK
2023-02-01 CVE-2022-3913 Improper Certificate Validation vulnerability in Rapid7 Nexpose
Rapid7 Nexpose and InsightVM versions 6.6.82 through 6.6.177 fail to validate the certificate of the update server when downloading updates.
network
high complexity
rapid7 CWE-295
5.3
2022-12-08 CVE-2022-4261 Download of Code Without Integrity Check vulnerability in Rapid7 Insightvm
Rapid7 Nexpose and InsightVM versions prior to 6.6.172 failed to reliably validate the authenticity of update contents.
network
low complexity
rapid7 CWE-494
6.5
2022-03-17 CVE-2022-0758 Cross-site Scripting vulnerability in Rapid7 Nexpose
Rapid7 Nexpose versions 6.6.129 and earlier suffer from a reflected cross site scripting vulnerability, within the shared scan configuration component of the tool.
network
low complexity
rapid7 CWE-79
6.1
2021-11-22 CVE-2019-5640 Information Exposure vulnerability in Rapid7 Nexpose
Rapid7 Nexpose versions prior to 6.6.114 suffer from an information exposure issue whereby, when the user's session has ended due to inactivity, an attacker can use the inspect element browser feature to remove the login panel and view the details available in the last webpage visited by previous user
network
low complexity
rapid7 CWE-200
5.3
2021-08-19 CVE-2021-31868 Missing Authentication for Critical Function vulnerability in Rapid7 Nexpose
Rapid7 Nexpose version 6.6.95 and earlier allows authenticated users of the Security Console to view and edit any ticket in the legacy ticketing feature, regardless of the assignment of the ticket.
network
low complexity
rapid7 CWE-306
5.4
2021-06-16 CVE-2021-3535 Cross-site Scripting vulnerability in Rapid7 Nexpose
Rapid7 Nexpose is vulnerable to a non-persistent cross-site scripting vulnerability affecting the Security Console's Filtered Asset Search feature.
network
low complexity
rapid7 CWE-79
6.1
2020-09-03 CVE-2020-7382 Unquoted Search Path or Element vulnerability in Rapid7 Nexpose
Rapid7 Nexpose installer version prior to 6.6.40 contains an Unquoted Search Path which may allow an attacker on the local machine to insert an arbitrary file into the executable path.
local
low complexity
rapid7 CWE-428
6.5
2020-01-25 CVE-2012-6494 Cross-site Scripting vulnerability in Rapid7 Nexpose
Rapid7 Nexpose before 5.5.4 contains a session hijacking vulnerability which allows remote attackers to capture a user's session and gain unauthorized access.
network
low complexity
rapid7 CWE-79
6.1
2016-12-20 CVE-2016-9757 Cross-site Scripting vulnerability in Rapid7 Nexpose 6.4.12
In the Create Tags page of the Rapid7 Nexpose version 6.4.12 user interface, any authenticated user who has the capability to create tags can inject cross-site scripting (XSS) elements in the tag name field.
network
low complexity
rapid7 CWE-79
5.4