Filtered by vendor Rapid7 Subscriptions
Filtered by product Nexpose Subscriptions
Total 22 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2019-5630 1 Rapid7 1 Nexpose 2024-11-21 N/A
A Cross-Site Request Forgery (CSRF) vulnerability was found in Rapid7 Nexpose InsightVM Security Console versions 6.5.0 through 6.5.68. This issue allows attackers to exploit CSRF vulnerabilities on API endpoints using Flash to circumvent a cross-domain pre-flight OPTIONS request.
CVE-2012-6494 1 Rapid7 1 Nexpose 2024-11-21 6.1 Medium
Rapid7 Nexpose before 5.5.4 contains a session hijacking vulnerability which allows remote attackers to capture a user's session and gain unauthorized access.