VendorsRapid7metasploitall versions
Vulnerabilities

Rapid7 Metasploit

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

17CVEs
CVE-2020-7376
Rapid7 Metasploit Framework Relative Path Traversal in enum_osx module
Published 2020-08-24 · Modified
10.0EPSS 0.011
CVE-2020-7384
Client-Side Command Injection in Rapid7 Metasploit
Published 2020-10-29 · Modified
9.31 PoCEPSS 0.305
CVE-2020-7385
Metasploit Framework 'drb_remote_codeexec' code execution
Published 2021-04-23 · Modified
8.8EPSS 0.018
CVE-2020-7377
Rapid7 Metasploit Framework Relative Path Traversal in telpho10_credential_dump module
Published 2020-08-24 · Modified
8.1EPSS 0.011
CVE-2020-7350
Metasploit Framework Plugin Libnotify Command Injection
Published 2020-04-22 · Modified
7.8EPSS 0.050
CVE-2017-5235
Rapid7 Metasploit Pro installers prior to version 4.13.0-2017022101 contain a DLL preloading vulnerability, wherein it is possible for the installer to load a malicious DLL located in the current working directory of the installer.
Published 2017-03-02 · Modified
7.8EPSS 0.009
CVE-2019-5645
Rapid7 Metasploit HTTP Handler Denial of Service
Published 2020-09-01 · Modified
7.5EPSS 0.417
CVE-2019-5624
Rapid7 Metasploit Framework Zip Import Directory Traversal
Published 2019-04-30 · Modified
7.4EPSS 0.028
CVE-2017-5228
All editions of Rapid7 Metasploit prior to version 4.13.0-2017020701 contain a directory traversal vulnerability in the Meterpreter stdapi Dir.download() function. By using a specially-crafted build of Meterpreter, it is possible to write to an arbitrary directory on the Metasploit console with the permissions of the running Metasploit instance.
Published 2017-03-02 · Modified
7.1EPSS 0.012
CVE-2017-5231
All editions of Rapid7 Metasploit prior to version 4.13.0-2017020701 contain a directory traversal vulnerability in the Meterpreter stdapi CommandDispatcher.cmd_download() function. By using a specially-crafted build of Meterpreter, it is possible to write to an arbitrary directory on the Metasploit console with the permissions of the running Metasploit instance.
Published 2017-03-02 · Modified
7.1EPSS 0.012
CVE-2017-5229
All editions of Rapid7 Metasploit prior to version 4.13.0-2017020701 contain a directory traversal vulnerability in the Meterpreter extapi Clipboard.parse_dump() function. By using a specially-crafted build of Meterpreter, it is possible to write to an arbitrary directory on the Metasploit console with the permissions of the running Metasploit instance.
Published 2017-03-02 · Modified
7.1EPSS 0.012
CVE-2017-15084
The web UI in Rapid7 Metasploit before 4.14.1-20170828 allows logout CSRF, aka R7-2017-22.
Published 2017-10-06 · Modified
6.51 PoCEPSS 0.015
CVE-2020-7354
Rapid7 Metasploit Pro Stored XSS in 'host' field
Published 2020-06-25 · Modified
6.1EPSS 0.009
CVE-2020-7355
Rapid7 Metasploit Pro Stored XSS in 'notes' field
Published 2020-06-25 · Modified
6.1EPSS 0.009
CVE-2023-0599
Rapid7 Metasploit Pro Stored XSS
Published 2023-02-01 · Modified
6.1EPSS 0.004
CVE-2017-5244
Routes used to stop running Metasploit tasks (either particular ones or all tasks) allowed GET requests. Only POST requests should have been allowed, as the stop/stop_all routes change the state of the service. This could have allowed an attacker to stop currently-running Metasploit tasks by getting an authenticated user to execute JavaScript. As of Metasploit 4.14.0 (Update 2017061301), the routes for stopping tasks only allow POST requests, which validate the presence of a secret token to prevent CSRF attacks.
Published 2017-06-15 · Modified
3.5EPSS 0.007
CVE-2019-5642
MAGICK
Published 2019-11-06 · Modified
3.3EPSS 0.003