The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
TitleEitWModules
CVE-2021-26731: Improper Control of Generation of Code9.1 CriticalN/A2%Oct 24, 2022
CVE-2021-26732: Improper Access Control6.5 MediumN/A0%Oct 24, 2022
CVE-2021-26733: Improper Access Control5.3 MediumN/A1%Oct 24, 2022
CVE-2021-42010: Improper Encoding or Escaping of Output9.8 CriticalN/A2%Oct 24, 2022
CVE-2021-46279: Session Fixation5.8 MediumN/A0%Oct 24, 2022
CVE-2021-4228: Use of Hard-coded Cryptographic Key5.8 MediumN/A10%Oct 24, 2022
CVE-2021-44467: Improper Access Control5.3 MediumN/A1%Oct 24, 2022
CVE-2021-45925: Observable Discrepancy5.3 MediumN/A1%Oct 24, 2022
CVE-2021-46848: Off-by-one Error9.1 CriticalN/A2%Oct 24, 2022
CVE-2021-26730: Stack-based Buffer Overflow10.0 CriticalN/A1%Oct 24, 2022
CVE-2021-46850: Improper Neutralization of Argument Delimiters in a Command7.2 HighN/A6%Oct 24, 2022
CVE-2021-44776: Improper Access Control6.5 MediumN/A0%Oct 24, 2022
CVE-2021-44769: Improper Input Validation4.9 MediumN/A0%Oct 24, 2022
CVE-2021-42553: Buffer Copy without Checking Size of Input9.8 CriticalN/A1%Oct 21, 2022
CVE-2021-33231: Improper Neutralization of Input During Web Page Generation5.4 MediumN/A1%Oct 20, 2022
CVE-2021-3305: Untrusted Search Path7.8 HighN/A0%Oct 18, 2022
CVE-2021-27406: External Control of System or Configuration Setting8.8 HighN/A1%Oct 14, 2022
CVE-2021-22685: Improper Limitation of a Pathname to a Restricted Directory6.2 MediumN/A1%Oct 14, 2022
CVE-2021-46840: Out-of-bounds Read9.1 CriticalN/A0%Oct 14, 2022
CVE-2021-46839: Out-of-bounds Read9.1 CriticalN/A0%Oct 14, 2022
CVE-2021-0699: Out-of-bounds Write7.8 HighN/A0%Oct 14, 2022
CVE-2021-20030: Improper Limitation of a Pathname to a Restricted Directory7.5 HighN/A1%Oct 13, 2022
CVE-2021-36369: Improper Authentication7.5 HighN/A1%Oct 12, 2022
CVE-2021-36201: Observable Response Discrepancy4.3 MediumN/A1%Oct 11, 2022
CVE-2021-36915: Cross-Site Request Forgery (CSRF)4.2 MediumN/A0%Oct 11, 2022
2651-2675 of 23470