Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Rapid7, Inc.

First CVE: Feb 4, 2014Active for: 12 yearsTotal CVEs: 95
42.7
VTI Score
High

Rapid7 maintains a modestly sized but highly prominent portfolio of security assessment, penetration-testing, and endpoint-monitoring products including Nexpose, Metasploit, Velociraptor, InsightVM, and the Insight Agent platform. The vendor's vulnerability profile reflects the attack surface of web-facing consoles and agent-based infrastructure: durable weakness classes center on cross-site scripting, path traversal, untrusted search paths, CSRF, and session-management flaws that are endemic to authentication boundaries and file-system interaction in security tools. A moderate share of the vendor's disclosures acquire public exploit code, making timely patching operationally important for environments where these products are internet-reachable or integrated with critical workflows. Defenders should monitor Rapid7's advisories closely, particularly for the widely deployed Insight Agent and InsightVM scanning platform, and prioritize remediation of network-facing instances; live severity and exploitation data are shown alongside this summary.

FAUCET AI Generated
95
Total CVEs
More Total CVEs than 99% of tracked vendors
0.4
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 4% of tracked vendors
6.8
Avg CVSS Score
Higher Avg CVSS Score than 45% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Rapid7, Inc. over time

Volume of CVEsAvg CVSS Base Score
First CVE
Feb 4, 2014
12 years ago
Most Recent CVE
Jun 25, 2026
29 days ago

Self-Reporting Analysis

Of all the CVEs published by Rapid7, Inc. as a CNA, 34.2% affect products that Rapid7, Inc. develops as a vendor.

34.2%
65.8%
Self-reported: 92 (34.2%)
Third-party: 177 (65.8%)

Of all the CVEs published that affect products developed by Rapid7, Inc., 96.8% are self-published by Rapid7, Inc. as a CNA.

96.8%
Self-published: 92 (96.8%)
Other CNAs: 3 (3.2%)

Products(21 total)

Top CVEs

Signals from CVEs in this vendor scope (95 CVEs).

95 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2020-7384HIGH
Rapid7's Metasploit msfvenom framework handles APK files in a way that allows for a malicious user to craft and publish a file that would execute arbitrary commands on a victim's m
Oct 29, 20207.861NOYES
CVE-2019-5645HIGH
By sending a specially crafted HTTP GET request to a listening Rapid7 Metasploit HTTP handler, an attacker can register an arbitrary regular expression. When evaluated, this malici
Sep 1, 20207.559NOYES
CVE-2017-5264HIGH
Versions of Nexpose prior to 6.4.66 fail to adequately validate the source of HTTP requests intended for the Automated Actions administrative web application, and are susceptible t
Dec 14, 20178.839NOYES
CVE-2026-8666CRITICAL
OS Command Injection vulnerability in the traceroute action of Rapid7 InsightConnect Traceroute Plugin on Linux allows remote attackers to execute arbitrary OS commands via the hos
Jun 25, 20269.838NONO
CVE-2026-8665CRITICAL
OS Command Injection vulnerability in the TR action of Rapid7 InsightConnect Translate Plugin on Linux allows remote attackers to execute arbitrary OS commands via the text or expr
Jun 25, 20269.838NONO
CVE-2026-8660CRITICAL
OS Command Injection vulnerability in the ping action of Rapid7 InsightConnect Ping Plugin on Linux allows remote attackers to execute arbitrary OS commands via the host parameter
Jun 25, 20269.838NONO
CVE-2026-8663HIGH
OS Command Injection vulnerability in Rapid7 InsightConnect RPM Plugin on Linux allows authenticated attackers to execute arbitrary OS commands via the repo, key, or name parameter
Jun 25, 20268.837NONO
CVE-2026-8592CRITICAL
OS Command Injection vulnerability in the process_string action of Rapid7 InsightConnect AWK Plugin on Linux allows remote attackers to execute arbitrary OS commands via the text o
Jun 25, 20269.836NONO
CVE-2026-8658HIGH
OS Command Injection vulnerability in Rapid7 InsightConnect Tcpdump Plugin on Linux allows authenticated attackers to execute arbitrary OS commands via the options or filter parame
Jun 25, 20268.836NONO
CVE-2026-8664HIGH
OS Command Injection vulnerability in Rapid7 InsightConnect Finger Plugin on Linux allows authenticated attackers to execute arbitrary OS commands via the user or host parameters d
Jun 25, 20268.835NONO
View all 95 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products95 CVEs
8%
40%
44%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local28 (29.5%)
Network65 (68.4%)
Unknown1 (1.1%)
Physical0 (0.0%)
Adjacent Network1 (1.1%)
Attack Complexity
Low85 (89.5%)
High9 (9.5%)
Unknown1 (1.1%)
User Interaction
None53 (55.8%)
Unknown1 (1.1%)
Required41 (43.2%)
Privileges Required
Low37 (38.9%)
High12 (12.6%)
None45 (47.4%)
Unknown1 (1.1%)

Exploit Exposure

Signals from CVEs in this vendor scope (95 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
3 CVEs
3.2% of CVEs· 98th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
4 CVEs
4.2% of CVEs· 75th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Rapid7, Inc..

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Rapid7, Inc. — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Rapid7, Inc.'s Products

View all 2 CNAs →

Top CWEs