Vulnerabilities > Rapid7

DATE CVE VULNERABILITY TITLE RISK
2019-04-09 CVE-2019-5615 Insufficiently Protected Credentials vulnerability in Rapid7 Insightvm
Users with Site-level permissions can access files containing the username-encrypted passwords of Security Console Global Administrators and clear-text passwords for restoring backups, as well as the salt for those passwords.
network
low complexity
rapid7 CWE-522
6.5
2018-11-28 CVE-2018-5559 Cleartext Storage of Sensitive Information vulnerability in Rapid7 Komand
In Rapid7 Komand version 0.41.0 and prior, certain endpoints that are able to list the always encrypted-at-rest connection data could return some configurations of connection data without obscuring sensitive data from the API response sent over an encrypted channel.
network
low complexity
rapid7 CWE-312
4.9
2017-12-14 CVE-2017-5264 Cross-Site Request Forgery (CSRF) vulnerability in Rapid7 Nexpose
Versions of Nexpose prior to 6.4.66 fail to adequately validate the source of HTTP requests intended for the Automated Actions administrative web application, and are susceptible to a cross-site request forgery (CSRF) attack.
network
low complexity
rapid7 CWE-352
8.8
2017-10-06 CVE-2017-15084 Cross-Site Request Forgery (CSRF) vulnerability in Rapid7 Metasploit
The web UI in Rapid7 Metasploit before 4.14.1-20170828 allows logout CSRF, aka R7-2017-22.
network
low complexity
rapid7 CWE-352
6.5
2017-06-15 CVE-2017-5244 Cross-Site Request Forgery (CSRF) vulnerability in Rapid7 Metasploit
Routes used to stop running Metasploit tasks (either particular ones or all tasks) allowed GET requests.
network
low complexity
rapid7 CWE-352
3.5
2017-06-06 CVE-2017-5243 Use of a Broken or Risky Cryptographic Algorithm vulnerability in Rapid7 Nexpose
The default SSH configuration in Rapid7 Nexpose hardware appliances shipped before June 2017 does not specify desired algorithms for key exchange and other important functions.
network
high complexity
rapid7 CWE-327
8.5
2017-05-03 CVE-2017-5240 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Rapid7 Appspider PRO
Editions of Rapid7 AppSpider Pro prior to version 6.14.060 contain a heap-based buffer overflow in the FLAnalyzer.exe component.
network
low complexity
rapid7 CWE-119
7.5
2017-05-03 CVE-2017-5236 Untrusted Search Path vulnerability in Rapid7 Appspider PRO
Editions of Rapid7 AppSpider Pro installers prior to version 6.14.060 contain a DLL preloading vulnerability, wherein it is possible for the installer to load a malicious DLL located in the current working directory of the installer.
local
low complexity
rapid7 CWE-426
7.8
2017-03-02 CVE-2017-5235 Untrusted Search Path vulnerability in Rapid7 Metasploit 4.11.7/4.12.40/4.13.0
Rapid7 Metasploit Pro installers prior to version 4.13.0-2017022101 contain a DLL preloading vulnerability, wherein it is possible for the installer to load a malicious DLL located in the current working directory of the installer.
local
low complexity
rapid7 CWE-426
7.8
2017-03-02 CVE-2017-5234 Untrusted Search Path vulnerability in Rapid7 Insight Collector 1.0.15
Rapid7 Insight Collector installers prior to version 1.0.16 contain a DLL preloading vulnerability, wherein it is possible for the installer to load a malicious DLL located in the current working directory of the installer.
local
low complexity
rapid7 CWE-426
7.8