Rapid7, Inc.
First CVE: Dec 20, 2016Active for: 10 years
269
CVEs Published
More CVEs Published than 82% of tracked CNAs
24.5
Avg CVEs / Year
More Avg CVEs / Year than 73% of tracked CNAs
7.2
Avg CVSS Score
Higher Avg CVSS Score than 51% of tracked CNAs
0.4%
In CISA KEV
Higher KEV Rate than 83% of tracked CNAs
Self-Reporting Analysis
Of all the CVEs published by Rapid7, Inc. as a CNA, 34.2% affect products that Rapid7, Inc. develops as a vendor.
34.2%
65.8%
Self-reported: 92Third-party: 177
Of all the CVEs published that affect products developed by Rapid7, Inc., 96.8% are self-published by Rapid7, Inc. as a CNA.
96.8%
Self-published: 92Published by other CNAs: 3
Trends Over Time
The number and severity of CVEs published by Rapid7, Inc. over time
Volume of CVEsAvg CVSS Base Score
First CVE
Dec 20, 2016
9 years ago
Most Recent CVE
Jun 26, 2026
28 days ago
Top CVEs
All CVEs published by Rapid7, Inc. as a CNA, regardless of affected vendor or product.
269 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-0669HIGH Fortra (formerly, HelpSystems) GoAnywhere MFT suffers from a pre-authentication command injection vulnerability in the License Response Servlet due to deserializing an arbitrary at | Feb 6, 2023 | 7.2 | 98 | YES | YES |
CVE-2017-5255HIGH In version 3.5 and prior of Cambium Networks ePMP firmware, a lack of input sanitation for certain parameters on the web management console allows any authenticated user (including | Dec 20, 2017 | 8.8 | 84 | NO | YES |
CVE-2022-3218CRITICAL Due to a reliance on client-side authentication, the WiFi Mouse (Mouse Server) from Necta LLC's authentication mechanism is trivially bypassed, which can result in remote code exec | Sep 19, 2022 | 9.8 | 81 | NO | YES |
CVE-2024-51977MEDIUM An unauthenticated attacker who can access either the HTTP service (TCP port 80), the HTTPS service (TCP port 443), or the IPP service (TCP port 631), can leak several pieces of se | Jun 25, 2025 | 5.3 | 80 | NO | YES |
CVE-2020-7388CRITICAL Sage X3 Unauthenticated Remote Command Execution (RCE) as SYSTEM in AdxDSrv.exe component. By editing the client side authentication request, an attacker can bypass credential vali | Jul 22, 2021 | 9.8 | 78 | NO | YES |
CVE-2019-5620CRITICAL ABB MicroSCADA Pro SYS600 version 9.3 suffers from an instance of CWE-306: Missing Authentication for Critical Function. | Apr 29, 2020 | 9.8 | 78 | NO | YES |
CVE-2022-3229CRITICAL Because the web management interface for Unified Intents' Unified Remote solution does not itself require authentication, a remote, unauthenticated attacker can change or disable a | Feb 6, 2023 | 9.8 | 76 | NO | YES |
CVE-2023-28503CRITICAL Rocket Software UniData versions prior to 8.2.4 build 3003 and UniVerse versions prior to 11.3.5 build 1001 or 12.2.1 build 2002 suffer from an authentication bypass vulnerability, | Mar 29, 2023 | 9.8 | 75 | NO | YES |
CVE-2025-13315CRITICAL Twonky Server 8.5.2 on Linux and Windows is vulnerable to an access control flaw. An unauthenticated attacker can bypass web service API authentication controls to leak a log file | Nov 19, 2025 | 9.8 | 74 | NO | YES |
CVE-2023-28502CRITICAL Rocket Software UniData versions prior to 8.2.4 build 3003 and UniVerse versions prior to 11.3.5 build 1001 or 12.2.1 build 2002 suffer from a stack-based buffer overflow in the "u | Mar 29, 2023 | 9.8 | 74 | NO | YES |
CVE Severity & Scoring
Severity distribution of CVEs published by this CNA269 CVEs
38%
41%
17%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local51 (19.0%)
Network211 (78.4%)
Unknown0 (0.0%)
Physical2 (0.7%)
Adjacent Network5 (1.9%)
Attack Complexity
Low253 (94.1%)
High16 (5.9%)
Unknown0 (0.0%)
User Interaction
None190 (70.6%)
Unknown0 (0.0%)
Required77 (28.6%)
Privileges Required
Low95 (35.3%)
High39 (14.5%)
None135 (50.2%)
Unknown0 (0.0%)
Exploit Exposure
Signals from CVEs in this cna scope (269 CVEs).
CISA KEV
1 CVE
0.4% of CVEs· 83rd percentile
Metasploit
38 CVEs
14.1% of CVEs· 99th percentile
Nuclei
8 CVEs
3.0% of CVEs· 89th percentile
ExploitDB
4 CVEs
1.5% of CVEs· 85th percentile
Social Chatter
An overview of all social media posts that mention a CVE ID published by Rapid7, Inc. as a CNA.
Media Mentions
Media articles that mention a CVE ID published by Rapid7, Inc. as a CNA — matched by CVE ID, not by organization name.