Skip to main content

Vendor/product archive

rapid7 / appspider_pro CVEs

Beta · best-effort

6 CVEs tagged to rapid7 / appspider_pro0 Critical, 3 High, 1 Medium, 2 Low, 0 Unrated.

CVE-2025-11195

Published Sep 30, 2025

Rapid7 AppSpider Pro versions below 7.5.021 suffer from a project name validation vulnerability, whereby an attacker can change the project name directly in the configuration file…

CVSS 3.3 · Low
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-36857

Published Sep 25, 2025

Rapid7 Appspider Pro versions below 7.5.021, suffer from a broken access control vulnerability in the application's configuration file loading mechanism, whereby an attacker can p…

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-4951

Published May 20, 2025

Editions of Rapid7 AppSpider Pro before version 7.5.018 is vulnerable to a stored cross-site scripting vulnerability in the "ScanName" field. Despite the application preventing th…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-5240

Published May 3, 2017

Editions of Rapid7 AppSpider Pro prior to version 6.14.060 contain a heap-based buffer overflow in the FLAnalyzer.exe component. A malicious or malformed Flash source file can cau…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2017-5236

Published May 3, 2017

Editions of Rapid7 AppSpider Pro installers prior to version 6.14.060 contain a DLL preloading vulnerability, wherein it is possible for the installer to load a malicious DLL loca…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-5233

Published Mar 2, 2017

Rapid7 AppSpider Pro installers prior to version 6.14.053 contain a DLL preloading vulnerability, wherein it is possible for the installer to load a malicious DLL located in the c…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort
Showing 1-6 of 6 CVEsPage 1 of 1