The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
TitleEitWModules
CVE-2021-36863: Improper Neutralization of Input During Web Page Generation5.4 MediumN/A0%Oct 28, 2022
CVE-2021-36858: Improper Neutralization of Input During Web Page Generation4.8 MediumN/A0%Oct 28, 2022
CVE-2021-38397: Unrestricted Upload of File with Dangerous Type10.0 CriticalN/A1%Oct 28, 2022
CVE-2021-38395: Improper Neutralization of Special Elements in Output Used by a Downstream Component9.1 CriticalN/A1%Oct 28, 2022
CVE-2021-38399: Relative Path Traversal7.5 HighN/A1%Oct 28, 2022
CVE-2021-36206: Improper Neutralization of Input During Web Page Generation10.0 CriticalN/A0%Oct 28, 2022
CVE-2021-38731: Improper Neutralization of Special Elements used in an SQL Command9.8 CriticalN/A1%Oct 28, 2022
CVE-2021-35388: Improper Neutralization of Input During Web Page Generation5.4 MediumN/A0%Oct 28, 2022
CVE-2021-38217: Improper Neutralization of Special Elements used in an SQL Command9.8 CriticalN/A1%Oct 28, 2022
CVE-2021-38729: Improper Neutralization of Special Elements used in an SQL Command9.8 CriticalN/A1%Oct 28, 2022
CVE-2021-38730: Improper Neutralization of Special Elements used in an SQL Command9.8 CriticalN/A1%Oct 28, 2022
CVE-2021-38732: Improper Neutralization of Special Elements used in an SQL Command9.8 CriticalN/A1%Oct 28, 2022
CVE-2021-38733: Improper Neutralization of Special Elements used in an SQL Command9.8 CriticalN/A1%Oct 28, 2022
CVE-2021-38734: Improper Neutralization of Special Elements used in an SQL Command9.8 CriticalN/A1%Oct 28, 2022
CVE-2021-37782: Improper Neutralization of Special Elements used in an SQL Command9.8 CriticalN/A1%Oct 28, 2022
CVE-2021-35387: Improper Neutralization of Special Elements used in an SQL Command8.8 HighN/A1%Oct 28, 2022
CVE-2021-37781: Improper Neutralization of Input During Web Page Generation5.4 MediumN/A0%Oct 28, 2022
CVE-2021-38728: Improper Neutralization of Input During Web Page Generation6.1 MediumN/A0%Oct 28, 2022
CVE-2021-38736: Improper Neutralization of Special Elements used in an SQL Command9.8 CriticalN/A1%Oct 28, 2022
CVE-2021-38737: Improper Neutralization of Special Elements used in an SQL Command9.8 CriticalN/A1%Oct 28, 2022
CVE-2021-45476: Improper Neutralization of Input During Web Page Generation4.7 MediumN/A0%Oct 27, 2022
CVE-2021-45475: Exposure of Sensitive Information to an Unauthorized Actor5.3 MediumN/A1%Oct 27, 2022
CVE-2021-26727: Improper Control of Generation of Code10.0 CriticalN/A2%Oct 24, 2022
CVE-2021-26728: Improper Control of Generation of Code10.0 CriticalN/A2%Oct 24, 2022
CVE-2021-26729: Improper Control of Generation of Code10.0 CriticalN/A2%Oct 24, 2022
2626-2650 of 23470