vciy

CVEs we hold for Rapid7

Records whose assigning authority named Rapid7 as the affected vendor. Newest identifiers first, capped at 200.

CVE-2026-9155OS Command Injection in Rapid7 InsightConnect Sed Plugin via expression parameter.Rapid7 InsightConnect Sed Plugin
CVE-2026-9154Arbitrary File Write in Rapid7 InsightConnect Sed PluginRapid7 InsightConnect Sed Plugin
CVE-2026-9153Arbitrary File Read in Rapid7 InsightConnect Sed PluginRapid7 InsightConnect Sed Plugin
CVE-2026-8795no title heldRapid7 Velociraptor
CVE-2026-8666OS Command Injection in Rapid7 InsightConnect Traceroute PluginRapid7 InsightConnect Traceroute Plugin
CVE-2026-8665OS Command Injection in Rapid7 InsightConnect Translate PluginRapid7 InsightConnect TR Plugin
CVE-2026-8664OS Command Injection in Rapid7 InsightConnect Finger PluginRapid7 InsightConnect Finger Plugin
CVE-2026-8663OS Command Injection in Rapid7 InsightConnect RPM PluginRapid7 InsightConnect RPM Plugin
CVE-2026-8662Path Traversal in Rapid7 InsightConnect Compression PluginRapid7 InsightConnect Compression Plugin
CVE-2026-8661Server-Side Cross-Site Scripting and SSRF in Rapid7 InsightConnect Markdown to PDF PluginRapid7 InsightConnect Markdown Plugin
CVE-2026-8660OS Command Injection in Rapid7 InsightConnect Ping PluginRapid7 InsightConnect Ping Plugin
CVE-2026-8659OS Command Injection in Rapid7 InsightConnect SQLmap PluginRapid7 InsightConnect SQLmap Plugin
CVE-2026-8658OS Command Injection in Rapid7 InsightConnect Tcpdump PluginRapid7 InsightConnect Tcpdump Plugin
CVE-2026-8592OS Command Injection in Rapid7 InsightConnect AWK PluginRapid7 InsightConnect AWK Plugin
CVE-2026-7373Metasploit Pro on Windows: Local Privilege Escalation via OpenSSL Configuration File LoadingRapid7 Metasploit Pro
CVE-2026-6948Unbounded Memory Allocation in VQLResponse Result-Set WriterRapid7 Velociraptor
CVE-2026-6863HTTP Filestore Endpoints Misapply Permissions Across OrganizationsRapid7 Velociraptor
CVE-2026-64955Velociraptor CSV Formula Injection in Export PipelineRapid7 Velociraptor
CVE-2026-64954Velociraptor collect_client() Permissions BypassRapid7 Velociraptor
CVE-2026-64952Velociraptor Hunt Deletion With Insufficient Permission CheckRapid7 Velociraptor
CVE-2026-64951Velociraptor DoS triggered by Divide by Zero panicRapid7 Velociraptor
CVE-2026-6482Local Privilege Escalation via OpenSSL configuration file in Insight AgentRapid7 Insight Agent
CVE-2026-6290Velociraptor Query() Plugin Misapplies Permissions To OrgsRapid7 Velociraptor
CVE-2026-5329Rapid7 Velociraptor Improper Input Validation in Client Message HandlerRapid7 Velociraptor
CVE-2026-4837Eval Injection in Rapid7 Insight AgentRapid7 Insight Agent
CVE-2026-4482Insight Agent Private Key Information Disclosure via Inherited File PermissionsRapid7 Insight Agent
CVE-2026-19584Velociraptor VQL injection during notebook restore from backupRapid7 Velociraptor
CVE-2026-19583Velociraptor Required Permissions bypass by using client monitoring queriesRapid7 Velociraptor
CVE-2026-19200Velociraptor Analyst overwrites live built-in artifacts through verify()Rapid7 Velociraptor
CVE-2026-18972Velociraptor authenticated identity-spoofing vulnerabilityRapid7 Velociraptor
CVE-2026-18860Velociraptor incorrect Org deletion permissions checkRapid7 Velociraptor
CVE-2026-18652Velociraptor STACK Type Download Path Bypasses Denied Prefix CheckRapid7 Velociraptor
CVE-2026-18640Velociraptor directory traversal via the NewNotebook APIRapid7 Velociraptor
CVE-2026-18639Velociraptor OIDC Authenticator susceptible to email spoofingRapid7 Velociraptor
CVE-2026-18638Velociraptor server crash via the SetPassword APIRapid7 Velociraptor
CVE-2026-18636Velociraptor VFSGetBuffer API path deny list bypassRapid7 Velociraptor
CVE-2026-18635Velociraptor query plugin allows impersonation in other orgsRapid7 Velociraptor
CVE-2026-18348Velociraptor NETWORK ACL bypass via upload_azure / upload_sftp / upload_smb VQL pluginsRapid7 Velociraptor
CVE-2026-1814Rapid7 Nexpose Insecure Java Keystore Password GenerationRapid7 InsightVM/Nexpose
CVE-2026-17535Velociraptor Multiple Crashes in NTFS Parser when applied to invalid NTFS VolumesRapid7 Velociraptor
CVE-2026-16895Authentication Bypass in Metasploit JSON-RPC Service When DB Health Check FailsRapid7 Metasploit-framework
CVE-2026-1568Rapid7 InsightVM Signature Validation VulnerabilityRapid7 Vulnerability Management
CVE-2026-15371Velociraptor Stored XSS in URL column typesRapid7 Velociraptor
CVE-2026-14172Rapid7 InsightVM, Nexpose, and Insight Agent Local Privilege Escalation via Unvalidated Executable InvocationRapid7 Insight Agent
CVE-2025-6264Velociraptor priviledge escalation via UpdateConfig artifactRapid7 Velociraptor
CVE-2025-4951no title heldRapid7 AppSpider Pro
CVE-2025-36857Rapid7 Appspider Broken Access Control VulnerabilityRapid7 Appspider Pro
CVE-2025-14728Rapid7 Velociraptor Directory Traversal VulnerabilityRapid7 Velociraptor
CVE-2025-11195Rapid7 AppSpider Project Name Validation BypassRapid7 AppSpider Pro
CVE-2025-0914Velociraptor Shell Plugin Prevent_execve BypassRapid7 Velociraptor
CVE-2024-8042Rapid7 Insight Platform Unauthorized Empty Group CreationRapid7 Insight Platform
CVE-2024-6504Rapid7 InsightVM Protection Mechanism FailureRapid7 InsightVM
CVE-2024-3185Rapid7 Insight Agent Sensitive Key Exposed To Local UsersRapid7 Insight Agent
CVE-2024-2745Rapid7 InsightVM Sensitive Information Exposure via URLRapid7 InsightVM
CVE-2024-11401Rapid7 Insight Platform Privilege Escalation VulnerabilityRapid7 Insight Platform
CVE-2024-10526Rapid7 Velociraptor Local Privilege Escalation In Windows Velociraptor ServiceRapid7 Velociraptor
CVE-2024-0394Rapid7 Minerva Armor Privilege EscalationRapid7 Minerva
CVE-2023-5950Rapid7 Velociraptor Reflected XSSRapid7 Velociraptor
CVE-2023-2273Rapid7 Insight Agent Directory TraversalRapid7 Insight Agent
CVE-2023-2226Velociraptor crashes while parsing some malformed PE or OLE files.Rapid7 Velociraptor
CVE-2023-1699Rapid7 Nexpose Forced BrowsingRapid7 Nexpose
CVE-2023-1306Rapid7 InsightCloudSec resource.db() method accessRapid7 InsightCloudSec
CVE-2023-1305Rapid7 InsightCloudSec box object accessRapid7 InsightCloudSec
CVE-2023-1304Rapid7 InsightCloudSec getattr() method accessRapid7 InsightCloudSec
CVE-2023-0681Rapid7 Nexpose Uncontrolled URL RedirectRapid7 Nexpose
CVE-2023-0599Rapid7 Metasploit Pro Stored XSSRapid7 Metasploit Pro
CVE-2023-0290Rapid7 Velociraptor directory traversal in client ID parameterRapid7 Velociraptor
CVE-2023-0242Insufficient permission check in the VQL copy() functionRapid7 Velociraptor
CVE-2022-4261Rapid7 Nexpose Update Validation IssueRapid7 InsightVM
CVE-2022-3913Rapid7 Nexpose Certificate Validation IssueRapid7 InsightVM
CVE-2022-35632XSS in User InterfaceRapid7 Velociraptor
CVE-2022-35631Filesystem race on temporary filesRapid7 Velociraptor
CVE-2022-35630Unsafe HTML Injection in Artifact Collection ReportRapid7 Velociraptor
CVE-2022-35629Velociraptor Client ID SpoofingRapid7 Velociraptor
CVE-2022-0758Rapid7 Nexpose Reflected XSSRapid7 Nexpose
CVE-2022-0757Rapid7 Nexpose SQL InjectionRapid7 Nexpose
CVE-2022-0237Rapid7 Insight Agent Privilege EscalationRapid7 Insight Agent
CVE-2021-4016Rapid7 Insight Agent Improper Access ControlRapid7 Insight Agent
CVE-2021-4007Rapid7 Insight Agent Privilege EscalationRapid7 Insight Agent
CVE-2021-3844Rapid7 InsightVM Insufficient Session ExpirationRapid7 InsightVM
CVE-2021-3619Rapid7 Velociraptor Notebooks Authenticated Persistent XSSRapid7 Velociraptor
CVE-2021-3535no title heldRapid7 Nexpose
CVE-2021-31868Rapid7 Nexpose Security Console Ticket Access Authentication VulnerabilityRapid7 Nexpose
CVE-2020-7385Metasploit Framework 'drb_remote_codeexec' code executionRapid7 Metasploit Framework
CVE-2020-7384Client-Side Command Injection in Rapid7 MetasploitRapid7 Metasploit
CVE-2020-7383SQL Injection in Rapid7 NexposeRapid7 Nexpose
CVE-2020-7382Unquoted Path in Rapid7 Nexpose InstallerRapid7 Nexpose
CVE-2020-7381Code Injection in Rapid7 Nexpose InstallerRapid7 Nexpose
CVE-2020-7377Rapid7 Metasploit Framework Relative Path Traversal in telpho10_credential_dump moduleRapid7 Metasploit Framework
CVE-2020-7376Rapid7 Metasploit Framework Relative Path Traversal in enum_osx moduleRapid7 Metasploit Framework
CVE-2020-7358Code Injection in Rapid7 AppSpider Pro InstallerRapid7 AppSpider
CVE-2020-7355Rapid7 Metasploit Pro Stored XSS in 'notes' fieldRapid7 Metasploit Pro
CVE-2020-7354Rapid7 Metasploit Pro Stored XSS in 'host' fieldRapid7 Metasploit Pro
CVE-2020-7350Metasploit Framework Plugin Libnotify Command InjectionRapid7 Metasploit Framework
CVE-2019-5647Rapid7 AppSpider Chrome Plugin Insufficient Session ExpirationRapid7 AppSpider
CVE-2019-5645Rapid7 Metasploit HTTP Handler Denial of ServiceRapid7 Metasploit Framework
CVE-2019-5642MAGICKRapid7 Metasploit Pro
CVE-2019-5641Rapid7 InsightVM Information Disclosure after LogoutRapid7 InsightVM
CVE-2019-5640Rapid7 Nexpose Information Disclosure after logoutRapid7 Nexpose
CVE-2019-5638Rapid7 Nexpose Insufficient Session ManagementRapid7 Nexpose
CVE-2019-5631Rapid7 InsightAppSec Local Privilege EscalationRapid7 InsightAppSec
CVE-2019-5630Rapid7 Nexpose/InsightVM Security Console CSRFRapid7 Nexpose/InsightVM Security Console
CVE-2019-5629no title heldRapid7 Insight Agent
CVE-2019-5624Rapid7 Metasploit Framework Zip Import Directory TraversalRapid7 Metasploit Framework
CVE-2019-5615Rapid7 InsightVM Stored Credential ExposureRapid7 InsightVM
CVE-2018-5559no title heldRapid7 Komand
CVE-2017-5264no title heldRapid7 Nexpose
CVE-2017-5244no title heldRapid7 Metasploit (Pro, Express, and Community editions)
CVE-2017-5243no title heldRapid7 Nexpose hardware appliance
CVE-2017-5242Rapid7 Nexpose Virtual Appliance Duplicate SSH Host KeyRapid7 InsightVM Virtual Appliance
CVE-2017-5240no title heldRapid7 AppSpider Pro
CVE-2017-5236no title heldRapid7 AppSpider Pro
CVE-2017-5235no title heldRapid7 Metasploit Pro
CVE-2017-5234no title heldRapid7 Insight Collector
CVE-2017-5233no title heldRapid7 AppSpider Pro
CVE-2017-5232no title heldRapid7 Nexpose
CVE-2017-5231no title heldRapid7 Metasploit
CVE-2017-5230no title heldRapid7 Nexpose
CVE-2017-5229no title heldRapid7 Metasploit
CVE-2017-5228no title heldRapid7 Metasploit
CVE-2016-9757no title heldRapid7 Nexpose

121 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.

Everything on this page is free. Public data. Withholding it protects nothing.