CVE-2026-1568
- EPSS 0.02%
- Veröffentlicht 03.02.2026 16:47:03
- Zuletzt bearbeitet 04.02.2026 16:34:21
Rapid7 InsightVM versions before 8.34.0 contain a signature verification issue on the Assertion Consumer Service (ACS) cloud endpoint that could allow an attacker to gain unauthorized access to InsightVM accounts setup via "Security Console" installa...
CVE-2026-1814
- EPSS 0.01%
- Veröffentlicht 03.02.2026 15:16:14
- Zuletzt bearbeitet 09.02.2026 20:15:56
Rapid7 Nexpose versions 6.4.50 and later are vulnerable to an insufficient entropy issue in the CredentialsKeyStorePassword.generateRandomPassword() method. When updating legacy keystore passwords, the application generates a new password with insuff...
CVE-2024-6504
- EPSS 0.24%
- Veröffentlicht 18.07.2024 10:15:03
- Zuletzt bearbeitet 05.09.2025 09:15:31
Rapid7 InsightVM Console versions below 6.6.260 suffer from a protection mechanism failure whereby an attacker with network access to the InsightVM Console can cause it to overload or crash by sending repeated invalid REST requests in a short timefra...
CVE-2024-3185
- EPSS 0.03%
- Veröffentlicht 23.04.2024 09:15:07
- Zuletzt bearbeitet 21.11.2024 09:29:06
A key used in logging.json does not follow the least privilege principle by default and is exposed to local users in the Rapid7 Platform. This allows an attacker with local access to a machine with the logging.json file to use that key to authentic...
CVE-2024-2745
- EPSS 0.08%
- Veröffentlicht 02.04.2024 10:15:09
- Zuletzt bearbeitet 25.02.2025 18:36:41
Rapid7's InsightVM maintenance mode login page suffers from a sensitive information exposure vulnerability whereby, sensitive information is exposed through query strings in the URL when login is attempted before the page is fully loaded. This vulne...
CVE-2021-3844
- EPSS 0.07%
- Veröffentlicht 24.03.2023 17:15:07
- Zuletzt bearbeitet 21.11.2024 06:22:37
Rapid7 InsightVM suffers from insufficient session expiration when an administrator performs a security relevant edit on an existing, logged on user. For example, if a user's password is changed by an administrator due to an otherwise unrelated crede...
CVE-2023-0681
- EPSS 0.07%
- Veröffentlicht 20.03.2023 20:15:52
- Zuletzt bearbeitet 21.11.2024 07:37:37
Rapid7 InsightVM versions 6.6.178 and lower suffers from an open redirect vulnerability, whereby an attacker has the ability to redirect the user to a site of the attacker’s choice using the ‘page’ parameter of the ‘data/console/redirect’ component o...
CVE-2017-5242
- EPSS 0.23%
- Veröffentlicht 12.01.2023 22:15:09
- Zuletzt bearbeitet 08.04.2025 15:15:45
Nexpose and InsightVM virtual appliances downloaded between April 5th, 2017 and May 3rd, 2017 contain identical SSH host keys. Normally, a unique SSH host key should be generated the first time a virtual appliance boots.
CVE-2022-4261
- EPSS 0.1%
- Veröffentlicht 08.12.2022 00:15:10
- Zuletzt bearbeitet 21.11.2024 07:34:53
Rapid7 Nexpose and InsightVM versions prior to 6.6.172 failed to reliably validate the authenticity of update contents. This failure could allow an attacker to provide a malicious update and alter the functionality of Rapid7 Nexpose. The attacker wou...
CVE-2019-5641
- EPSS 0.13%
- Veröffentlicht 21.09.2022 15:15:10
- Zuletzt bearbeitet 21.11.2024 04:45:17
Rapid7 InsightVM suffers from an information exposure issue whereby, when the user's session has ended due to inactivity, an attacker can use the Inspect Element browser feature to remove the login panel and view the details available in the last web...