Nexpose
Rapid7- Software type
- —
- Catalog vulnerabilities
- 22
Severity across 17 analyzed records
Verify to analyze this security profile
A short verification protects source data and prevents automated AI requests.
en
Severity across 17 analyzed records
A short verification protects source data and prevents automated AI requests.
As of 09/11/2026, within CyStack's analyzed data, Nexpose has 1 security vulnerability published in the last 90 days. Of these, 1 is rated High or Critical. None of these vulnerabilities is listed in the CISA KEV catalog. CyStack recommends that organizations and individual users remediate applicable vulnerabilities as soon as possible.
CyStack does not yet have sufficient official-source data to identify the latest version of Nexpose and determine which vulnerabilities affect that version.
| CVE | Exploitation status | Fix | Published | Severity |
|---|---|---|---|---|
CVE-2026-14172Rapid7 InsightVM, Nexpose, and Insight Agent Local Privilege Escalation via Unvalidated Executable Invocation | Exploitation statusNot known exploited | FixYes | Published07/24/2026 | SeverityHigh |
CVE-2023-1699Rapid7 Nexpose Forced Browsing | Exploitation statusNot known exploited | FixYes | Published03/30/2023 | SeverityMedium |
CVE-2023-0681Rapid7 Nexpose Uncontrolled URL Redirect | Exploitation statusNot known exploited | FixYes | Published03/20/2023 | SeverityMedium |
CVE-2022-3913Rapid7 Nexpose Certificate Validation Issue | Exploitation statusNot known exploited | FixYes | Published02/01/2023 | SeverityMedium |
CVE-2022-4261Rapid7 Nexpose Update Validation Issue | Exploitation statusNot known exploited | FixYes | Published12/07/2022 | SeverityMedium |
CVE-2022-0758Rapid7 Nexpose Reflected XSS | Exploitation statusNot confirmed | FixYes | Published03/17/2022 | SeverityLow |
CVE-2022-0757Rapid7 Nexpose SQL Injection | Exploitation statusNot confirmed | FixYes | Published03/17/2022 | SeverityMedium |
CVE-2019-5640Rapid7 Nexpose Information Disclosure after logout | Exploitation statusNot confirmed | FixYes | Published11/22/2021 | SeverityLow |
CVE-2021-31868Rapid7 Nexpose Security Console Ticket Access Authentication Vulnerability | Exploitation statusNot confirmed | FixYes | Published08/19/2021 | SeverityMedium |
CVE-2021-3535CVE-2021-3535 | Exploitation statusNot confirmed | FixYes | Published06/16/2021 | SeverityMedium |
CVE-2020-7383SQL Injection in Rapid7 Nexpose | Exploitation statusNot confirmed | FixYes | Published10/14/2020 | SeverityMedium |
CVE-2020-7382Unquoted Path in Rapid7 Nexpose Installer | Exploitation statusNot confirmed | FixYes | Published09/03/2020 | SeverityMedium |
CVE-2020-7381Code Injection in Rapid7 Nexpose Installer | Exploitation statusNot confirmed | FixYes | Published09/03/2020 | SeverityMedium |
CVE-2012-6494CVE-2012-6494 | Exploitation statusNot confirmed | FixNot confirmed | Published01/25/2020 | SeverityUnknown |
CVE-2019-5638Rapid7 Nexpose Insufficient Session Management | Exploitation statusNot confirmed | FixYes | Published08/21/2019 | SeverityHigh |
CVE-2019-5630Rapid7 Nexpose/InsightVM Security Console CSRF | Exploitation statusNot confirmed | FixYes | Published07/03/2019 | SeverityMedium |
CVE-2017-5264CVE-2017-5264 | Exploitation statusPublic exploit | FixNot confirmed | Published12/14/2017 | SeverityUnknown |
CVE-2017-5243CVE-2017-5243 | Exploitation statusNot confirmed | FixNot confirmed | Published06/06/2017 | SeverityUnknown |
CVE-2017-5232CVE-2017-5232 | Exploitation statusNot confirmed | FixNot confirmed | Published03/02/2017 | SeverityUnknown |
CVE-2017-5230CVE-2017-5230 | Exploitation statusNot confirmed | FixNot confirmed | Published03/02/2017 | SeverityUnknown |
CVE-2016-9757CVE-2016-9757 | Exploitation statusNot confirmed | FixNot confirmed | Published12/20/2016 | SeverityUnknown |
CVE-2012-6493CVE-2012-6493 | Exploitation statusPublic exploit | FixNot confirmed | Published02/04/2014 | SeverityUnknown |
CyStack VulnScan continuously discovers assets, validates vulnerabilities, and helps security teams prioritize remediation across the organization.
Explore CyStack VulnScan