The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
TitleEitWModules
CVE-2021-45036: Authentication Bypass by Spoofing8.7 HighN/A1%Nov 28, 2022
CVE-2021-25059: Undefined Security Weakness4.3 MediumN/A1%Nov 28, 2022
CVE-2021-35246: Cleartext Transmission of Sensitive Information5.3 MediumN/A0%Nov 23, 2022
CVE-2021-35284: Improper Neutralization of Special Elements used in an SQL Command9.8 CriticalN/A1%Nov 23, 2022
CVE-2021-46849: Undefined Security Weakness9.8 CriticalN/AN/ANov 23, 2022
CVE-2021-29334: Cross-Site Request Forgery (CSRF)8.8 HighN/A0%Nov 23, 2022
CVE-2021-46854: Missing Release of Memory after Effective Lifetime7.5 HighN/A1%Nov 23, 2022
CVE-2021-43258: Unrestricted Upload of File with Dangerous Type8.8 HighN/A12%Nov 23, 2022
CVE-2021-3942: Improper Restriction of Operations within the Bounds of a Memory Buffer9.8 CriticalN/A2%Nov 22, 2022
CVE-2021-3919: Improper Privilege Management9.8 CriticalN/A1%Nov 21, 2022
CVE-2021-3821: Uncontrolled Resource Consumption9.8 CriticalN/A1%Nov 21, 2022
CVE-2021-3661: Improper Control of Generation of Code8.4 HighN/A0%Nov 21, 2022
CVE-2021-3437: Incorrect Default Permissions9.8 CriticalN/A16%Nov 21, 2022
CVE-2021-24649: Undefined Security Weakness9.8 CriticalN/A1%Nov 21, 2022
CVE-2021-22141: URL Redirection to Untrusted Site6.1 MediumN/A1%Nov 18, 2022
CVE-2021-33621: Improper Neutralization of Special Elements in Output Used by a Downstream Component8.8 HighN/A2%Nov 18, 2022
CVE-2021-37936: Improper Neutralization of Input During Web Page Generation5.4 MediumN/A0%Nov 18, 2022
CVE-2021-31739: Improper Neutralization of Input During Web Page Generation6.1 MediumN/A0%Nov 18, 2022
CVE-2021-36905: Improper Neutralization of Input During Web Page Generation5.4 MediumN/A0%Nov 17, 2022
CVE-2021-33897: Buffer Copy without Checking Size of Input5.5 MediumN/A0%Nov 17, 2022
CVE-2021-31608: Protection Mechanism Failure4.3 MediumN/A0%Nov 17, 2022
CVE-2021-38819: Improper Neutralization of Special Elements used in an SQL Command8.8 HighN/A1%Nov 16, 2022
CVE-2021-4241: Insufficient Entropy2.6 LowN/A1%Nov 15, 2022
CVE-2021-4240: Insufficient Entropy2.6 LowN/A1%Nov 15, 2022
CVE-2021-38827: Authentication Bypass by Capture-replay7.5 HighN/A1%Nov 14, 2022
2551-2575 of 23470