Rapid7, Inc.

First CVE: Dec 20, 2016Active for: 10 years
269
CVEs Published
More CVEs Published than 82% of tracked CNAs
24.5
Avg CVEs / Year
More Avg CVEs / Year than 73% of tracked CNAs
7.2
Avg CVSS Score
Higher Avg CVSS Score than 51% of tracked CNAs
0.4%
In CISA KEV
Higher KEV Rate than 83% of tracked CNAs

Self-Reporting Analysis

Of all the CVEs published by Rapid7, Inc. as a CNA, 34.2% affect products that Rapid7, Inc. develops as a vendor.

34.2%
65.8%
Self-reported: 92Third-party: 177

Of all the CVEs published that affect products developed by Rapid7, Inc., 96.8% are self-published by Rapid7, Inc. as a CNA.

96.8%
Self-published: 92Published by other CNAs: 3

Trends Over Time

The number and severity of CVEs published by Rapid7, Inc. over time

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 20, 2016
9 years ago
Most Recent CVE
Jun 26, 2026
28 days ago

Top CVEs

All CVEs published by Rapid7, Inc. as a CNA, regardless of affected vendor or product.

269 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Fortra (formerly, HelpSystems) GoAnywhere MFT suffers from a pre-authentication command injection vulnerability in the License Response Servlet due to deserializing an arbitrary at
Feb 6, 20237.298YESYES
In version 3.5 and prior of Cambium Networks ePMP firmware, a lack of input sanitation for certain parameters on the web management console allows any authenticated user (including
Dec 20, 20178.884NOYES
Due to a reliance on client-side authentication, the WiFi Mouse (Mouse Server) from Necta LLC's authentication mechanism is trivially bypassed, which can result in remote code exec
Sep 19, 20229.881NOYES
An unauthenticated attacker who can access either the HTTP service (TCP port 80), the HTTPS service (TCP port 443), or the IPP service (TCP port 631), can leak several pieces of se
Jun 25, 20255.380NOYES
Sage X3 Unauthenticated Remote Command Execution (RCE) as SYSTEM in AdxDSrv.exe component. By editing the client side authentication request, an attacker can bypass credential vali
Jul 22, 20219.878NOYES
ABB MicroSCADA Pro SYS600 version 9.3 suffers from an instance of CWE-306: Missing Authentication for Critical Function.
Apr 29, 20209.878NOYES
Because the web management interface for Unified Intents' Unified Remote solution does not itself require authentication, a remote, unauthenticated attacker can change or disable a
Feb 6, 20239.876NOYES
Rocket Software UniData versions prior to 8.2.4 build 3003 and UniVerse versions prior to 11.3.5 build 1001 or 12.2.1 build 2002 suffer from an authentication bypass vulnerability,
Mar 29, 20239.875NOYES
Twonky Server 8.5.2 on Linux and Windows is vulnerable to an access control flaw. An unauthenticated attacker can bypass web service API authentication controls to leak a log file
Nov 19, 20259.874NOYES
Rocket Software UniData versions prior to 8.2.4 build 3003 and UniVerse versions prior to 11.3.5 build 1001 or 12.2.1 build 2002 suffer from a stack-based buffer overflow in the "u
Mar 29, 20239.874NOYES

CVE Severity & Scoring

Severity distribution of CVEs published by this CNA269 CVEs
Severity distribution among all CVEs352,231 CVEs
LowMediumHighCritical
Attack Vector
Local51 (19.0%)
Network211 (78.4%)
Unknown0 (0.0%)
Physical2 (0.7%)
Adjacent Network5 (1.9%)
Attack Complexity
Low253 (94.1%)
High16 (5.9%)
Unknown0 (0.0%)
User Interaction
None190 (70.6%)
Unknown0 (0.0%)
Required77 (28.6%)
Privileges Required
Low95 (35.3%)
High39 (14.5%)
None135 (50.2%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this cna scope (269 CVEs).

CISA KEV
1 CVE
0.4% of CVEs· 83rd percentile
Metasploit
38 CVEs
14.1% of CVEs· 99th percentile
Nuclei
8 CVEs
3.0% of CVEs· 89th percentile
ExploitDB
4 CVEs
1.5% of CVEs· 85th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID published by Rapid7, Inc. as a CNA.

Media Mentions

Media articles that mention a CVE ID published by Rapid7, Inc. as a CNA — matched by CVE ID, not by organization name.

Top Affected Vendors

Top Affected Products

Top CWEs