Home / CVEs we hold for Rapid7 CVEs we hold for Rapid7 Records whose assigning authority named Rapid7 as the affected vendor. Newest identifiers first, capped at 200.
CVE-2026-9155 OS Command Injection in Rapid7 InsightConnect Sed Plugin via expression parameter. Rapid7 InsightConnect Sed Plugin CVE-2026-9154 Arbitrary File Write in Rapid7 InsightConnect Sed Plugin Rapid7 InsightConnect Sed Plugin CVE-2026-9153 Arbitrary File Read in Rapid7 InsightConnect Sed Plugin Rapid7 InsightConnect Sed Plugin CVE-2026-8666 OS Command Injection in Rapid7 InsightConnect Traceroute Plugin Rapid7 InsightConnect Traceroute Plugin CVE-2026-8665 OS Command Injection in Rapid7 InsightConnect Translate Plugin Rapid7 InsightConnect TR Plugin CVE-2026-8664 OS Command Injection in Rapid7 InsightConnect Finger Plugin Rapid7 InsightConnect Finger Plugin CVE-2026-8663 OS Command Injection in Rapid7 InsightConnect RPM Plugin Rapid7 InsightConnect RPM Plugin CVE-2026-8662 Path Traversal in Rapid7 InsightConnect Compression Plugin Rapid7 InsightConnect Compression Plugin CVE-2026-8661 Server-Side Cross-Site Scripting and SSRF in Rapid7 InsightConnect Markdown to PDF Plugin Rapid7 InsightConnect Markdown Plugin CVE-2026-8660 OS Command Injection in Rapid7 InsightConnect Ping Plugin Rapid7 InsightConnect Ping Plugin CVE-2026-8659 OS Command Injection in Rapid7 InsightConnect SQLmap Plugin Rapid7 InsightConnect SQLmap Plugin CVE-2026-8658 OS Command Injection in Rapid7 InsightConnect Tcpdump Plugin Rapid7 InsightConnect Tcpdump Plugin CVE-2026-8592 OS Command Injection in Rapid7 InsightConnect AWK Plugin Rapid7 InsightConnect AWK Plugin CVE-2026-7373 Metasploit Pro on Windows: Local Privilege Escalation via OpenSSL Configuration File Loading Rapid7 Metasploit Pro CVE-2026-6948 Unbounded Memory Allocation in VQLResponse Result-Set Writer Rapid7 Velociraptor CVE-2026-6863 HTTP Filestore Endpoints Misapply Permissions Across Organizations Rapid7 Velociraptor CVE-2026-64955 Velociraptor CSV Formula Injection in Export Pipeline Rapid7 Velociraptor CVE-2026-64954 Velociraptor collect_client() Permissions Bypass Rapid7 Velociraptor CVE-2026-64952 Velociraptor Hunt Deletion With Insufficient Permission Check Rapid7 Velociraptor CVE-2026-64951 Velociraptor DoS triggered by Divide by Zero panic Rapid7 Velociraptor CVE-2026-6482 Local Privilege Escalation via OpenSSL configuration file in Insight Agent Rapid7 Insight Agent CVE-2026-6290 Velociraptor Query() Plugin Misapplies Permissions To Orgs Rapid7 Velociraptor CVE-2026-5329 Rapid7 Velociraptor Improper Input Validation in Client Message Handler Rapid7 Velociraptor CVE-2026-4837 Eval Injection in Rapid7 Insight Agent Rapid7 Insight Agent CVE-2026-4482 Insight Agent Private Key Information Disclosure via Inherited File Permissions Rapid7 Insight Agent CVE-2026-19584 Velociraptor VQL injection during notebook restore from backup Rapid7 Velociraptor CVE-2026-19583 Velociraptor Required Permissions bypass by using client monitoring queries Rapid7 Velociraptor CVE-2026-19200 Velociraptor Analyst overwrites live built-in artifacts through verify() Rapid7 Velociraptor CVE-2026-18972 Velociraptor authenticated identity-spoofing vulnerability Rapid7 Velociraptor CVE-2026-18860 Velociraptor incorrect Org deletion permissions check Rapid7 Velociraptor CVE-2026-18652 Velociraptor STACK Type Download Path Bypasses Denied Prefix Check Rapid7 Velociraptor CVE-2026-18640 Velociraptor directory traversal via the NewNotebook API Rapid7 Velociraptor CVE-2026-18639 Velociraptor OIDC Authenticator susceptible to email spoofing Rapid7 Velociraptor CVE-2026-18638 Velociraptor server crash via the SetPassword API Rapid7 Velociraptor CVE-2026-18636 Velociraptor VFSGetBuffer API path deny list bypass Rapid7 Velociraptor CVE-2026-18635 Velociraptor query plugin allows impersonation in other orgs Rapid7 Velociraptor CVE-2026-18348 Velociraptor NETWORK ACL bypass via upload_azure / upload_sftp / upload_smb VQL plugins Rapid7 Velociraptor CVE-2026-1814 Rapid7 Nexpose Insecure Java Keystore Password Generation Rapid7 InsightVM/Nexpose CVE-2026-17535 Velociraptor Multiple Crashes in NTFS Parser when applied to invalid NTFS Volumes Rapid7 Velociraptor CVE-2026-16895 Authentication Bypass in Metasploit JSON-RPC Service When DB Health Check Fails Rapid7 Metasploit-framework CVE-2026-1568 Rapid7 InsightVM Signature Validation Vulnerability Rapid7 Vulnerability Management CVE-2026-15371 Velociraptor Stored XSS in URL column types Rapid7 Velociraptor CVE-2026-14172 Rapid7 InsightVM, Nexpose, and Insight Agent Local Privilege Escalation via Unvalidated Executable Invocation Rapid7 Insight Agent CVE-2025-6264 Velociraptor priviledge escalation via UpdateConfig artifact Rapid7 Velociraptor CVE-2025-36857 Rapid7 Appspider Broken Access Control Vulnerability Rapid7 Appspider Pro CVE-2025-14728 Rapid7 Velociraptor Directory Traversal Vulnerability Rapid7 Velociraptor CVE-2025-11195 Rapid7 AppSpider Project Name Validation Bypass Rapid7 AppSpider Pro CVE-2025-0914 Velociraptor Shell Plugin Prevent_execve Bypass Rapid7 Velociraptor CVE-2024-8042 Rapid7 Insight Platform Unauthorized Empty Group Creation Rapid7 Insight Platform CVE-2024-6504 Rapid7 InsightVM Protection Mechanism Failure Rapid7 InsightVM CVE-2024-3185 Rapid7 Insight Agent Sensitive Key Exposed To Local Users Rapid7 Insight Agent CVE-2024-2745 Rapid7 InsightVM Sensitive Information Exposure via URL Rapid7 InsightVM CVE-2024-11401 Rapid7 Insight Platform Privilege Escalation Vulnerability Rapid7 Insight Platform CVE-2024-10526 Rapid7 Velociraptor Local Privilege Escalation In Windows Velociraptor Service Rapid7 Velociraptor CVE-2024-0394 Rapid7 Minerva Armor Privilege Escalation Rapid7 Minerva CVE-2023-5950 Rapid7 Velociraptor Reflected XSS Rapid7 Velociraptor CVE-2023-2273 Rapid7 Insight Agent Directory Traversal Rapid7 Insight Agent CVE-2023-2226 Velociraptor crashes while parsing some malformed PE or OLE files. Rapid7 Velociraptor CVE-2023-1306 Rapid7 InsightCloudSec resource.db() method access Rapid7 InsightCloudSec CVE-2023-1305 Rapid7 InsightCloudSec box object access Rapid7 InsightCloudSec CVE-2023-1304 Rapid7 InsightCloudSec getattr() method access Rapid7 InsightCloudSec CVE-2023-0681 Rapid7 Nexpose Uncontrolled URL Redirect Rapid7 Nexpose CVE-2023-0599 Rapid7 Metasploit Pro Stored XSS Rapid7 Metasploit Pro CVE-2023-0290 Rapid7 Velociraptor directory traversal in client ID parameter Rapid7 Velociraptor CVE-2023-0242 Insufficient permission check in the VQL copy() function Rapid7 Velociraptor CVE-2022-4261 Rapid7 Nexpose Update Validation Issue Rapid7 InsightVM CVE-2022-3913 Rapid7 Nexpose Certificate Validation Issue Rapid7 InsightVM CVE-2022-35630 Unsafe HTML Injection in Artifact Collection Report Rapid7 Velociraptor CVE-2022-0237 Rapid7 Insight Agent Privilege Escalation Rapid7 Insight Agent CVE-2021-4016 Rapid7 Insight Agent Improper Access Control Rapid7 Insight Agent CVE-2021-4007 Rapid7 Insight Agent Privilege Escalation Rapid7 Insight Agent CVE-2021-3844 Rapid7 InsightVM Insufficient Session Expiration Rapid7 InsightVM CVE-2021-3619 Rapid7 Velociraptor Notebooks Authenticated Persistent XSS Rapid7 Velociraptor CVE-2021-31868 Rapid7 Nexpose Security Console Ticket Access Authentication Vulnerability Rapid7 Nexpose CVE-2020-7385 Metasploit Framework 'drb_remote_codeexec' code execution Rapid7 Metasploit Framework CVE-2020-7384 Client-Side Command Injection in Rapid7 Metasploit Rapid7 Metasploit CVE-2020-7382 Unquoted Path in Rapid7 Nexpose Installer Rapid7 Nexpose CVE-2020-7381 Code Injection in Rapid7 Nexpose Installer Rapid7 Nexpose CVE-2020-7377 Rapid7 Metasploit Framework Relative Path Traversal in telpho10_credential_dump module Rapid7 Metasploit Framework CVE-2020-7376 Rapid7 Metasploit Framework Relative Path Traversal in enum_osx module Rapid7 Metasploit Framework CVE-2020-7358 Code Injection in Rapid7 AppSpider Pro Installer Rapid7 AppSpider CVE-2020-7355 Rapid7 Metasploit Pro Stored XSS in 'notes' field Rapid7 Metasploit Pro CVE-2020-7354 Rapid7 Metasploit Pro Stored XSS in 'host' field Rapid7 Metasploit Pro CVE-2020-7350 Metasploit Framework Plugin Libnotify Command Injection Rapid7 Metasploit Framework CVE-2019-5647 Rapid7 AppSpider Chrome Plugin Insufficient Session Expiration Rapid7 AppSpider CVE-2019-5645 Rapid7 Metasploit HTTP Handler Denial of Service Rapid7 Metasploit Framework CVE-2019-5641 Rapid7 InsightVM Information Disclosure after Logout Rapid7 InsightVM CVE-2019-5640 Rapid7 Nexpose Information Disclosure after logout Rapid7 Nexpose CVE-2019-5638 Rapid7 Nexpose Insufficient Session Management Rapid7 Nexpose CVE-2019-5631 Rapid7 InsightAppSec Local Privilege Escalation Rapid7 InsightAppSec CVE-2019-5630 Rapid7 Nexpose/InsightVM Security Console CSRF Rapid7 Nexpose/InsightVM Security Console CVE-2019-5624 Rapid7 Metasploit Framework Zip Import Directory Traversal Rapid7 Metasploit Framework CVE-2019-5615 Rapid7 InsightVM Stored Credential Exposure Rapid7 InsightVM CVE-2017-5244 no title held Rapid7 Metasploit (Pro, Express, and Community editions) CVE-2017-5242 Rapid7 Nexpose Virtual Appliance Duplicate SSH Host Key Rapid7 InsightVM Virtual Appliance 121 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.
Everything on this page is free. Public data. Withholding it protects nothing.