basicsecurity.net
Proof, not just disclosure.
Threats / Contributors / Rapid7 (Metasploit / Labs)
Research org contributor

Rapid7 (Metasploit / Labs)

cited across 315 known-exploited records. Every aggregate on this page is recomputed from the records listed below — each one already cited to its public source.

No vendor advisory domain is cited for this contributor in the corpus — its credit here is as a CNA/finder. Home URL is a stated coverage gap.

315
records cited in
deterministic count
0
finder / reporter credits
CVE.org credits
—
CNA assignments
not a CNA
84%
avg modeled exploit prob.
FIRST EPSS, 314/315
34%
ransomware-associated
106 of 315 · CISA flag
R

Roles across the work

— find / fix / exploit / catalog, computed per record from credit type, the vendor-self-CNA gate, and the linked public exploit catalog
0
Find
record(s)
0
Fix
record(s)
315
Exploit
record(s)
0
Catalog
record(s)

Part of the Rapid7 family — a hard rollup: this sub-unit’s work aggregates under Rapid7.

Each dimension is a count of the listed records where this contributor did that job. A CNA row is fix only when the affected product is the assigner’s own; registries, coordinators, platforms, intel and research houses read as catalog, never fix. Exploit counts records where this contributor is credited as author of a public exploit / detection template in a linked catalog — we link the catalog, never host a payload.

01

Known for

— recomputed from this contributor’s own records
SurfacesApplication / other (150), Operating system / kernel (54), Server / web platform (53), Edge / remote-access infra (30), Browser (17)
WeaknessInjection (91), Memory safety (47), Authorization / access control (39), Path traversal / file (24), Authentication (23)
PortfolioMicrosoft (81), Adobe (22), Oracle (17), Apache (17), Ivanti (12), Linux (10)
02

Narrative reach

— how far this contributor’s records carry an attacker, front door → lights out
1Front door
312reach this stage
→
2Keys to the kingdom
312reach this stage
→
3Lateral reach
297reach this stage
→
4Data at risk
50reach this stage
→
5Lights out
8reach this stage

Furthest any of these records carries an attacker: 5 · Lights out. 50 of 312 narrative-framed records reach data-at-risk or lights-out. (furthest-position idiom, reused from the landing map; the stage mapping is a model output over cited evidence.)

03

Recent highlights

— this contributor’s newest known-exploited records
04

Every record they’re cited in

— all 315, each linked to its cited source

This is the evidence behind every number above. Sorted ransomware-first, then by modeled exploit probability.

CVE-2024-23897Jenkins100%RWKEVCVE-2024-3400Palo Alto Networks100%RWKEVCVE-2024-21893Ivanti100%RWKEVCVE-2024-21887Ivanti100%RWKEVCVE-2023-22518Atlassian100%RWKEVCVE-2022-26134Atlassian100%RWKEVCVE-2022-29464WSO2100%RWKEVCVE-2021-44228Apache100%RWKEVCVE-2017-5638Apache100%RWKEVCVE-2019-11510Ivanti100%RWKEVCVE-2020-5902F5100%RWKEVCVE-2021-21985VMware100%RWKEVCVE-2021-22005VMware100%RWKEVCVE-2021-26084Atlassian100%RWKEVCVE-2021-34473Microsoft100%RWKEVCVE-2021-35464ForgeRock100%RWKEVCVE-2025-53770Microsoft100%RWKEVCVE-2022-22954VMware100%RWKEVCVE-2025-49704Microsoft100%RWKEVCVE-2018-7600Drupal100%RWKEVCVE-2021-34523Microsoft100%RWKEVCVE-2023-42793JetBrains100%RWKEVCVE-2024-4577PHP Group100%RWKEVCVE-2023-46805Ivanti100%RWKEVCVE-2023-22527Atlassian100%RWKEVCVE-2023-29357Microsoft100%RWKEVCVE-2024-1709ConnectWise100%RWKEVCVE-2024-24919Check Point100%RWKEVCVE-2021-45046Apache100%RWKEVCVE-2012-0158Microsoft100%RWKEVCVE-2022-41082Microsoft100%RWKEVCVE-2020-0688Microsoft100%RWKEVCVE-2022-41040Microsoft100%RWKEVCVE-2023-38035Ivanti100%RWKEVCVE-2024-27198JetBrains100%RWKEVCVE-2023-34362Progress100%RWKEVCVE-2021-38647Microsoft100%RWKEVCVE-2021-22986F5100%RWKEVCVE-2023-46604Apache100%RWKEVCVE-2021-21972VMware100%RWKEVCVE-2024-0012Palo Alto Networks100%RWKEVCVE-2020-0796Microsoft100%RWKEVCVE-2021-34527Microsoft100%RWKEVCVE-2021-31207Microsoft100%RWKEVCVE-2019-11043PHP100%RWKEVCVE-2023-3519Citrix100%RWKEVCVE-2019-18935Progress100%RWKEVCVE-2021-22205GitLab100%RWKEVCVE-2019-15107Webmin100%RWKEVCVE-2017-0147Microsoft100%RWKEVCVE-2017-0199Microsoft99%RWKEVCVE-2024-23692Rejetto99%RWKEVCVE-2017-7494Samba99%RWKEVCVE-2020-1472Microsoft99%RWKEVCVE-2017-0148Microsoft99%RWKEVCVE-2022-30190Microsoft99%RWKEVCVE-2017-0144Microsoft99%RWKEVCVE-2023-22515Atlassian99%RWKEVCVE-2025-49706Microsoft99%RWKEVCVE-2020-0618Microsoft99%RWKEVCVE-2021-40539Zoho99%RWKEVCVE-2013-2465Oracle99%RWKEVCVE-2019-11539Ivanti99%RWKEVCVE-2012-4681Oracle99%RWKEVCVE-2023-48788Fortinet98%RWKEVCVE-2012-0507Oracle98%RWKEVCVE-2021-42237Sitecore98%RWKEVCVE-2013-0422Oracle97%RWKEVCVE-2024-57727SimpleHelp 97%RWKEVCVE-2023-46747F597%RWKEVCVE-2024-1708ConnectWise95%RWKEVCVE-2024-9474Palo Alto Networks95%RWKEVCVE-2016-4117Adobe94%RWKEVCVE-2021-4034Red Hat94%RWKEVCVE-2024-55956Cleo94%RWKEVCVE-2012-1723Oracle94%RWKEVCVE-2017-0143Microsoft93%RWKEVCVE-2018-11138Quest92%RWKEVCVE-2021-42321Microsoft92%RWKEVCVE-2022-26352dotCMS92%RWKEVCVE-2013-0431Oracle90%RWKEVCVE-2023-40044Progress90%RWKEVCVE-2017-0146Microsoft90%RWKEVCVE-2017-0145Microsoft90%RWKEVCVE-2010-0188Adobe88%RWKEVCVE-2025-52691SmarterTools86%RWKEVCVE-2023-24955Microsoft85%RWKEVCVE-2021-1675Microsoft85%RWKEVCVE-2023-43208NextGen Healthcare83%RWKEVCVE-2010-0738Red Hat79%RWKEVCVE-2013-0074Microsoft79%RWKEVCVE-2021-1732Microsoft78%RWKEVCVE-2021-21975VMware78%RWKEVCVE-2021-42258BQE74%RWKEVCVE-2019-1458Microsoft74%RWKEVCVE-2013-2551Microsoft74%RWKEVCVE-2018-8453Microsoft70%RWKEVCVE-2021-36942Microsoft66%RWKEVCVE-2022-21882Microsoft59%RWKEVCVE-2015-1701Microsoft56%RWKEVCVE-2023-28252Microsoft49%RWKEVCVE-2020-0787Microsoft43%RWKEVCVE-2019-1405Microsoft30%RWKEVCVE-2019-1322Microsoft19%RWKEVCVE-2018-8440Microsoft18%RWKEVCVE-2023-4966Citrix NetScaler ADC/Gateway “Citrix Bleed”—RWKEVCVE-2014-0160OpenSSL100%KEVCVE-2015-1635Microsoft100%KEVCVE-2014-6271GNU100%KEVCVE-2021-1498Cisco100%KEVCVE-2012-1823PHP100%KEVCVE-2013-2251Apache100%KEVCVE-2020-14882Oracle100%KEVCVE-2022-44877CWP100%KEVCVE-2024-34102Adobe100%KEVCVE-2018-11776Apache100%KEVCVE-2019-9670Synacor100%KEVCVE-2021-22204Perl100%KEVCVE-2025-59287Microsoft100%KEVCVE-2014-8361Realtek100%KEVCVE-2021-3156Sudo100%KEVCVE-2018-2628Oracle100%KEVCVE-2022-30525Zyxel100%KEVCVE-2015-3113Adobe100%KEVCVE-2020-10189Zoho100%KEVCVE-2022-22963VMware Tanzu100%KEVCVE-2021-1497Cisco100%KEVCVE-2025-4427Ivanti100%KEVCVE-2024-32113Apache100%KEVCVE-2015-1427Elastic100%KEVCVE-2020-7961Liferay100%KEVCVE-2014-0497Adobe100%KEVCVE-2022-35914Teclib100%KEVCVE-2021-36260Hikvision100%KEVCVE-2023-23752Joomla!100%KEVCVE-2024-36401OSGeo100%KEVCVE-2020-15505Ivanti100%KEVCVE-2016-10033PHP100%KEVCVE-2024-28995SolarWinds100%KEVCVE-2014-6278GNU100%KEVCVE-2020-16846SaltStack100%KEVCVE-2023-20198Cisco100%KEVCVE-2024-4040CrushFTP100%KEVCVE-2018-20062ThinkPHP100%KEVCVE-2024-38856Apache99%KEVCVE-2011-0611Adobe99%KEVCVE-2017-9805Apache99%KEVCVE-2022-0543Redis99%KEVCVE-2015-5119Adobe99%KEVCVE-2020-14750Oracle99%KEVCVE-2020-0646Microsoft99%KEVCVE-2024-27348Apache99%KEVCVE-2020-10199Sonatype99%KEVCVE-2026-24061GNU99%KEVCVE-2020-7247OpenBSD99%KEVCVE-2008-4250Microsoft99%KEVCVE-2026-1281Ivanti99%KEVCVE-2026-1340Ivanti99%KEVCVE-2024-20767Adobe99%KEVCVE-2018-1000861Jenkins98%KEVCVE-2017-15944Palo Alto Networks98%KEVCVE-2023-20887VMware98%KEVCVE-2020-14883Oracle98%KEVCVE-2020-17519Apache98%KEVCVE-2022-43769Hitachi Vantara98%KEVCVE-2016-3714ImageMagick97%KEVCVE-2024-4358Progress97%KEVCVE-2019-9082ThinkPHP97%KEVCVE-2024-56145Craft CMS97%KEVCVE-2023-27524Apache97%KEVCVE-2017-8291Artifex97%KEVCVE-2010-3962Microsoft97%KEVCVE-2020-25223Sophos97%KEVCVE-2011-3544Oracle97%KEVCVE-2009-0927Adobe97%KEVCVE-2020-11651SaltStack97%KEVCVE-2023-33246Apache97%KEVCVE-2009-1151phpMyAdmin97%KEVCVE-2020-8260Ivanti96%KEVCVE-2010-0840Oracle96%KEVCVE-2021-35587Oracle96%KEVCVE-2017-17562Embedthis96%KEVCVE-2018-14847MikroTik96%KEVCVE-2020-17530Apache96%KEVCVE-2024-1212Progress95%KEVCVE-2019-7609Elastic95%KEVCVE-2015-0313Adobe95%KEVCVE-2023-36845Juniper95%KEVCVE-2014-6332Microsoft95%KEVCVE-2024-47575Fortinet95%KEVCVE-2020-6287SAP95%KEVCVE-2023-7028GitLab95%KEVCVE-2017-1000486Primetek94%KEVCVE-2015-5122Adobe94%KEVCVE-2020-1147Microsoft94%KEVCVE-2021-44077Zoho93%KEVCVE-2022-0847Linux93%KEVCVE-2022-24706Apache93%KEVCVE-2022-43939Hitachi Vantara92%KEVCVE-2017-5689Intel92%KEVCVE-2025-11371Gladinet92%KEVCVE-2019-6340Drupal92%KEVCVE-2010-0249Microsoft92%KEVCVE-2020-8657EyesOfNetwork92%KEVCVE-2025-64446Fortinet92%KEVCVE-2026-20182Cisco92%KEVCVE-2010-2568Microsoft91%KEVCVE-2012-5076Oracle91%KEVCVE-2012-0754Adobe91%KEVCVE-2020-3952VMware90%KEVCVE-2025-37164Hewlett Packard Enterprise (HPE)90%KEVCVE-2017-8464Microsoft90%KEVCVE-2023-20273Cisco90%KEVCVE-2010-3333Microsoft89%KEVCVE-2014-3120Elastic89%KEVCVE-2011-2462Adobe89%KEVCVE-2021-43798Grafana Labs89%KEVCVE-2026-20127Cisco88%KEVCVE-2023-2868Barracuda Networks88%KEVCVE-2013-3893Microsoft88%KEVCVE-2014-6324Microsoft87%KEVCVE-2024-12356BeyondTrust87%KEVCVE-2014-4113Microsoft87%KEVCVE-2009-3459Adobe87%KEVCVE-2015-2426Microsoft87%KEVCVE-2025-4428Ivanti87%KEVCVE-2020-11652SaltStack86%KEVCVE-2015-0311Adobe86%KEVCVE-2013-2423Oracle85%KEVCVE-2014-0322Microsoft85%KEVCVE-2013-3906Microsoft85%KEVCVE-2018-17463Google85%KEVCVE-2020-28949PEAR85%KEVCVE-2020-5722Grandstream84%KEVCVE-2017-11317Telerik84%KEVCVE-2009-3129Microsoft84%KEVCVE-2025-40551SolarWinds84%KEVCVE-2012-1889Microsoft84%KEVCVE-2009-3953Adobe83%KEVCVE-2010-1297Adobe82%KEVCVE-2010-0806Microsoft82%KEVCVE-2009-4324Adobe82%KEVCVE-2014-4114Microsoft82%KEVCVE-2023-4911GNU81%KEVCVE-2010-2883Adobe81%KEVCVE-2019-9621Synacor81%KEVCVE-2012-4969Microsoft80%KEVCVE-2020-14871Oracle80%KEVCVE-2021-21551Dell79%KEVCVE-2013-3346Adobe79%KEVCVE-2012-4792Microsoft79%KEVCVE-2020-6418Google79%KEVCVE-2021-22555Linux79%KEVCVE-2023-49103ownCloud78%KEVCVE-2020-8816Pi-hole78%KEVCVE-2013-1347Microsoft78%KEVCVE-2014-6352Microsoft77%KEVCVE-2014-1761Microsoft77%KEVCVE-2013-3897Microsoft77%KEVCVE-2015-0016Microsoft76%KEVCVE-2012-0391Apache76%KEVCVE-2005-2773Hewlett Packard (HP)75%KEVCVE-2015-3043Adobe74%KEVCVE-2019-1003029Jenkins74%KEVCVE-2013-3918Microsoft74%KEVCVE-2020-5741Plex73%KEVCVE-2019-2215Android72%KEVCVE-2025-40536SolarWinds72%KEVCVE-2010-4344Exim72%KEVCVE-2013-3163Microsoft71%KEVCVE-2012-1535Adobe70%KEVCVE-2013-1690Mozilla69%KEVCVE-2021-30657Apple69%KEVCVE-2013-3896Microsoft68%KEVCVE-2016-4657Apple67%KEVCVE-2019-5786Google62%KEVCVE-2015-7755Juniper61%KEVCVE-2025-32463Sudo61%KEVCVE-2020-8655EyesOfNetwork60%KEVCVE-2019-5825Google56%KEVCVE-2025-58034Fortinet56%KEVCVE-2020-1054Microsoft54%KEVCVE-2019-0808Microsoft53%KEVCVE-2019-13272Linux52%KEVCVE-2013-7331Microsoft50%KEVCVE-2021-3493Linux49%KEVCVE-2019-15752Docker49%KEVCVE-2014-100005D-Link43%KEVCVE-2023-36874Microsoft43%KEVCVE-2013-6282Linux40%KEVCVE-2013-3660Microsoft39%KEVCVE-2014-3153Linux37%KEVCVE-2022-22960VMware36%KEVCVE-2013-5065Microsoft35%KEVCVE-2016-4655Apple33%KEVCVE-2011-2005Microsoft32%KEVCVE-2010-0232Microsoft29%KEVCVE-2024-35250Microsoft25%KEVCVE-2021-3560Red Hat24%KEVCVE-2016-4656Apple24%KEVCVE-2010-4345Exim18%KEVCVE-2026-34197Apache15%KEVCVE-2010-3904Linux14%KEVCVE-2019-3010Oracle13%KEVCVE-2022-22948VMware13%KEVCVE-2021-38648Microsoft11%KEVCVE-2015-1130Apple10%KEVCVE-2015-3246Red Hat9%KEVCVE-2022-0995Linux9%KEVCVE-2020-3950VMware7%KEVCVE-2022-0492Linux6%KEVCVE-2015-5287Red Hat5%KEVCVE-2026-3055Citrix4%KEVCVE-2026-31431Linux3%KEVCVE-2020-9934Apple3%KEV
05

Coverage & confidence

— what this profile claims, and what it does not

Established (cited)

  • Cited in 315 known-exploited records — the list below; every one links to its public source.
  • Coverage gaps — stated, not hidden

  • This profile is an aggregation: it asserts only what the listed records already cite — no new external claim about the contributor is made.
  • The TYPE badge and the narrative-stage mapping are editorial (our call), labeled as such, not a sourced fact.
  • No vendor advisory home domain is cited for this contributor in the corpus.