Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Rapid7 — Vulnerabilities & Security Advisories 116

Browse all 116 CVE security advisories affecting Rapid7. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Rapid7 operates primarily as a provider of security analytics and vulnerability management solutions, focusing on helping organizations identify, prioritize, and remediate security risks. Historically, its software products have exhibited vulnerabilities typical of complex enterprise applications, including remote code execution, cross-site scripting, and privilege escalation flaws. These issues often stem from improper input validation or insecure default configurations within its InsightVM and Metasploit frameworks. While the company maintains a robust security posture and actively patches disclosed issues, the high volume of recorded CVEs reflects the extensive attack surface inherent in its comprehensive toolset. Notable incidents have generally been resolved through prompt updates, though the frequency of findings underscores the challenges of securing large-scale, feature-rich security platforms. Continuous monitoring and strict access controls remain critical for mitigating these persistent risks.

CVE IDTitleCVSSSeverityPublished
CVE-2026-18652 Velociraptor STACK Type Download Path Bypasses Denied Prefix Check — VelociraptorCWE-862 4.9 Medium2026-08-12
CVE-2026-64951 Velociraptor DoS triggered by Divide by Zero panic — VelociraptorCWE-369 3.5 Low2026-08-12
CVE-2026-64952 Velociraptor Hunt Deletion With Insufficient Permission Check — VelociraptorCWE-863 6.5 Medium2026-08-12
CVE-2026-64955 Velociraptor CSV Formula Injection in Export Pipeline — VelociraptorCWE-1236 6.1 Medium2026-08-12
CVE-2026-64954 Velociraptor collect_client() Permissions Bypass — VelociraptorCWE-862 8.2 High2026-08-12
CVE-2026-18639 Velociraptor OIDC Authenticator susceptible to email spoofing — VelociraptorCWE-290 7.3 High2026-08-11
CVE-2026-18638 Velociraptor server crash via the SetPassword API — VelociraptorCWE-476 6.5 Medium2026-08-11
CVE-2026-18640 Velociraptor directory traversal via the NewNotebook API — VelociraptorCWE-22 7.1 High2026-08-11
CVE-2026-18860 Velociraptor incorrect Org deletion permissions check — VelociraptorCWE-280 8.7 High2026-08-11
CVE-2026-17535 Velociraptor Multiple Crashes in NTFS Parser when applied to invalid NTFS Volumes — VelociraptorCWE-125 6.2 Medium2026-08-11
CVE-2026-18636 Velociraptor VFSGetBuffer API path deny list bypass — VelociraptorCWE-288 6.8 Medium2026-08-11
CVE-2026-18635 Velociraptor query plugin allows impersonation in other orgs — VelociraptorCWE-863 7.2 High2026-08-11
CVE-2026-18972 Velociraptor authenticated identity-spoofing vulnerability — VelociraptorCWE-290 9.6 Critical2026-08-11
CVE-2026-18348 Velociraptor NETWORK ACL bypass via upload_azure / upload_sftp / upload_smb VQL plugins — VelociraptorCWE-863 4.1 Medium2026-08-11
CVE-2026-14172 Rapid7 InsightVM, Nexpose, and Insight Agent Local Privilege Escalation via Unvalidated Executable Invocation — InsightVMCWE-250 7.8 High2026-07-24
CVE-2026-8661 Server-Side Cross-Site Scripting and SSRF in Rapid7 InsightConnect Markdown to PDF Plugin — InsightConnect Markdown PluginCWE-79 4.8 Medium2026-06-26
CVE-2026-8658 OS Command Injection in Rapid7 InsightConnect Tcpdump Plugin — InsightConnect Tcpdump PluginCWE-78 6.0 Medium2026-06-25
CVE-2026-8662 Path Traversal in Rapid7 InsightConnect Compression Plugin — InsightConnect Compression PluginCWE-22 3.3 Low2026-06-25
CVE-2026-8666 OS Command Injection in Rapid7 InsightConnect Traceroute Plugin — InsightConnect Traceroute PluginCWE-78 7.7 High2026-06-25
CVE-2026-8592 OS Command Injection in Rapid7 InsightConnect AWK Plugin — InsightConnect AWK PluginCWE-78 7.7 High2026-06-25
CVE-2026-8664 OS Command Injection in Rapid7 InsightConnect Finger Plugin — InsightConnect Finger PluginCWE-78 6.0 Medium2026-06-25
CVE-2026-8665 OS Command Injection in Rapid7 InsightConnect Translate Plugin — InsightConnect TR PluginCWE-78 7.7 High2026-06-25
CVE-2026-8660 OS Command Injection in Rapid7 InsightConnect Ping Plugin — InsightConnect Ping PluginCWE-78 7.7 High2026-06-25
CVE-2026-9153 Arbitrary File Read in Rapid7 InsightConnect Sed Plugin — InsightConnect Sed PluginCWE-22 6.5 Medium2026-06-25
CVE-2026-9154 Arbitrary File Write in Rapid7 InsightConnect Sed Plugin — InsightConnect Sed PluginCWE-22 7.1 High2026-06-25
CVE-2026-9155 OS Command Injection in Rapid7 InsightConnect Sed Plugin via expression parameter. — InsightConnect Sed PluginCWE-78 8.8 High2026-06-25
CVE-2026-8659 OS Command Injection in Rapid7 InsightConnect SQLmap Plugin — InsightConnect SQLmap PluginCWE-78 6.0 Medium2026-06-25
CVE-2026-8663 OS Command Injection in Rapid7 InsightConnect RPM Plugin — InsightConnect RPM PluginCWE-78 6.0 Medium2026-06-24
CVE-2026-8795 Rapid7 Velociraptor 注入漏洞 — VelociraptorCWE-74 7.8 High2026-06-09
CVE-2026-7373 Metasploit Pro on Windows: Local Privilege Escalation via OpenSSL Configuration File Loading — Metasploit ProCWE-829--2026-05-15

This page lists every published CVE security advisory associated with Rapid7. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.