Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2534▼ 410 respecto a la semana anterior
Críticas / altas1307▲ 25 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)59▼ 467 respecto a la semana anterior
9 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Alta (7.8) | 0.16% | — | Rapid7 InsightvmAIRapid7 NexposeAIRapid7 Insight AgentAI | 24/7/2026 | 30/7/2026 | Rapid7 InsightVM, Nexpose, and the Insight Agent execute discovered executables during authenticated assessment without validating file ownership, allowing a local low-privileged user to run code as the scan credential (Scan Engine) or as root/SYSTEM (Insight Agent). Fixed in Scan Engine content 1.1.3935 and Insight… | |
| Analizada | Alta (8.5) | 0.19% | — | Rapid7 Insight Agent | 17/4/2026 | 17/6/2026 | The Rapid7 Insight Agent (versions > 4.1.0.2) is vulnerable to a local privilege escalation attack that allows users to gain SYSTEM level control of a Windows host. Upon startup the agent service attempts to load an OpenSSL configuration file from a non-existent directory that is writable by standard users. By… | |
| Analizada | Media (6.8) | 0.10% | — | Rapid7 Insight Agent | 10/4/2026 | 17/6/2026 | The installer certificate files in the …/bootstrap/common/ssl folder do not seem to have restricted permissions on Windows systems (users have read and execute access). For the client.key file in particular, this could potentially lead to exploits, as this exposes agent identity material to any locally authenticated… | |
| Analizada | Alta (7.2) | 0.72% | — | Rapid7 Insight Agent | 8/4/2026 | 24/7/2026 | An eval() injection vulnerability in the Rapid7 Insight Agent beaconing logic for Linux versions could theoretically allow an attacker to achieve remote code execution as root via a crafted beacon response. Because the Agent uses mutual TLS (mTLS) to verify commands from the Rapid7 Platform, it is unlikely that the… | |
| Modificada | Alta (7.5) | 0.72% | — | Rapid7 Insight Agent | 26/4/2023 | 17/6/2026 | Rapid7 Insight Agent token handler versions 3.2.6 and below, suffer from a Directory Traversal vulnerability whereby unsanitized input from a CLI argument flows into io.ioutil.WriteFile, where it is used as a path. This can result in a Path Traversal vulnerability and allow an attacker to write arbitrary files. This… | |
| Modificada | Alta (7.8) | 0.48% | — | Rapid7 Insight Agent | 17/3/2022 | 17/6/2026 | Rapid7 Insight Agent versions 3.1.2.38 and earlier suffer from a privilege escalation vulnerability, whereby an attacker can hijack the flow of execution due to an unquoted argument to the runas.exe command used by the ir_agent.exe component, resulting in elevated rights and persistent access to the machine. This… | |
| Modificada | Baja (3.3) | 0.22% | — | Rapid7 Insight Agent | 21/1/2022 | 17/6/2026 | Rapid7 Insight Agent, versions prior to 3.1.3, suffer from an improper access control vulnerability whereby, the user has access to the snapshot directory. An attacker can access, read and copy any of the files in this directory e.g. asset_info.json or file_info.json, leading to a loss of confidentiality. This issue… | |
| Modificada | Alta (7.8) | 0.32% | — | Rapid7 Insight Agent | 14/12/2021 | 17/6/2026 | Rapid7 Insight Agent, versions 3.0.1 to 3.1.2.34, suffer from a local privilege escalation due to an uncontrolled DLL search path. Specifically, when Insight Agent versions 3.0.1 to 3.1.2.34 start, the Python interpreter attempts to load python3.dll at "C:\DLLs\python3.dll," which normally is writable by locally… | |
| Modificada | Alta (7.8) | 0.94% | — | Rapid7 Insight Agent | 13/7/2019 | 17/6/2026 | Rapid7 Insight Agent, version 2.6.3 and prior, suffers from a local privilege escalation due to an uncontrolled DLL search path. Specifically, when Insight Agent 2.6.3 and prior starts, the Python interpreter attempts to load python3.dll at "C:\DLLs\python3.dll," which normally is writable by locally authenticated… |