CVE-2023-1699
- EPSS 0.1%
- Veröffentlicht 30.03.2023 10:15:07
- Zuletzt bearbeitet 21.11.2024 07:39:43
Rapid7 Nexpose versions 6.6.186 and below suffer from a forced browsing vulnerability. This vulnerability allows an attacker to manipulate URLs to forcefully browse to and access administrative pages. This vulnerability is fixed in version 6.6.187. ...
CVE-2022-3913
- EPSS 0.13%
- Veröffentlicht 01.02.2023 22:15:08
- Zuletzt bearbeitet 21.11.2024 07:20:31
Rapid7 Nexpose and InsightVM versions 6.6.82 through 6.6.177 fail to validate the certificate of the update server when downloading updates. This failure could allow an attacker in a privileged position on the network to provide their own HTTPS endpo...
CVE-2022-4261
- EPSS 0.1%
- Veröffentlicht 08.12.2022 00:15:10
- Zuletzt bearbeitet 21.11.2024 07:34:53
Rapid7 Nexpose and InsightVM versions prior to 6.6.172 failed to reliably validate the authenticity of update contents. This failure could allow an attacker to provide a malicious update and alter the functionality of Rapid7 Nexpose. The attacker wou...
CVE-2022-0758
- EPSS 0.44%
- Veröffentlicht 17.03.2022 23:15:07
- Zuletzt bearbeitet 21.11.2024 06:39:20
Rapid7 Nexpose versions 6.6.129 and earlier suffer from a reflected cross site scripting vulnerability, within the shared scan configuration component of the tool. With this vulnerability an attacker could pass literal values as the test credentials,...
CVE-2022-0757
- EPSS 0.16%
- Veröffentlicht 17.03.2022 23:15:07
- Zuletzt bearbeitet 21.11.2024 06:39:20
Rapid7 Nexpose versions 6.6.93 and earlier are susceptible to an SQL Injection vulnerability, whereby valid search operators are not defined. This lack of validation can allow a logged-in, authenticated attacker to manipulate the "ANY" and "OR" opera...
CVE-2019-5640
- EPSS 0.17%
- Veröffentlicht 22.11.2021 17:15:08
- Zuletzt bearbeitet 21.11.2024 04:45:17
Rapid7 Nexpose versions prior to 6.6.114 suffer from an information exposure issue whereby, when the user's session has ended due to inactivity, an attacker can use the inspect element browser feature to remove the login panel and view the details av...
CVE-2021-31868
- EPSS 0.12%
- Veröffentlicht 19.08.2021 16:15:12
- Zuletzt bearbeitet 21.11.2024 06:06:23
Rapid7 Nexpose version 6.6.95 and earlier allows authenticated users of the Security Console to view and edit any ticket in the legacy ticketing feature, regardless of the assignment of the ticket. This issue was resolved in version 6.6.96, released ...
CVE-2021-3535
- EPSS 0.23%
- Veröffentlicht 16.06.2021 02:15:06
- Zuletzt bearbeitet 21.11.2024 06:21:47
Rapid7 Nexpose is vulnerable to a non-persistent cross-site scripting vulnerability affecting the Security Console's Filtered Asset Search feature. A specific search criterion and operator combination in Filtered Asset Search could have allowed a use...
CVE-2020-7383
- EPSS 0.36%
- Veröffentlicht 14.10.2020 20:15:16
- Zuletzt bearbeitet 21.11.2024 05:37:08
A SQL Injection issue in Rapid7 Nexpose version prior to 6.6.49 that may have allowed an authenticated user with a low permission level to access resources & make changes they should not have been able to access.
CVE-2020-7382
- EPSS 0.1%
- Veröffentlicht 03.09.2020 14:15:11
- Zuletzt bearbeitet 21.11.2024 05:37:08
Rapid7 Nexpose installer version prior to 6.6.40 contains an Unquoted Search Path which may allow an attacker on the local machine to insert an arbitrary file into the executable path. This issue affects: Rapid7 Nexpose versions prior to 6.6.40.