- What is the rapid7 CNA?
- rapid7 is a CVE Numbering Authority (CNA) — an organization authorized to assign CVE IDs to vulnerabilities in its scope. It has published 242 CVE records since 2016.
- How many CVEs has rapid7 published?
- rapid7 has published 242 CVE records, including 51 in the last two years.
- What is rapid7's CVE data quality grade?
- RadicalNotion.AI grades rapid7's CVE data quality as B, with an overall completeness score of 87.9%. This reflects how consistently its CVE records include vendor (99.2%), product (99.2%), CVSS (61.6%), and CWE (91.7%) information.
- What products does rapid7 publish CVEs for?
- rapid7 most frequently publishes CVEs for Velociraptor, linux kernel, Metasploit-framework, Nexpose, Metasploit.
- Which vendors does rapid7 cover?
- rapid7 publishes CVEs across 78 distinct vendors, most often Rapid7, linux, Velocidex, Microsoft, Cambium Networks.
- Is rapid7 actively publishing CVEs?
- rapid7 is currently active, based on 51 CVEs in the last two years.
- What is the average severity of rapid7's CVEs?
- The average CVSS base score across rapid7's scored CVEs is 6.4.
- How many critical CVEs has rapid7 published?
- rapid7 has published 49 critical-severity CVEs and 123 high-severity CVEs.
- Are any of rapid7's CVEs in CISA's Known Exploited Vulnerabilities catalog?
- Yes. 1 of rapid7's CVEs are listed in CISA's Known Exploited Vulnerabilities (KEV) catalog, meaning they are confirmed to be exploited in the wild.
- What are the most common weakness types in rapid7's CVEs?
- rapid7's CVEs most often map to these CWE weakness types: CWE-79 (Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')), CWE-78 (Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')), CWE-22 (Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')), CWE-89 (Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')).
- How does rapid7 rank among CNAs?
- By total CVE volume, rapid7 ranks #79 of 370 CNAs, and it reports more complete CVE records than 34% of all CNAs.