The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
TitleEitWModules
CVE-2021-36913: Improper Access Control7.5 HighN/A1%Oct 11, 2022
CVE-2021-36899: Improper Neutralization of Input During Web Page Generation4.8 MediumN/A0%Oct 11, 2022
CVE-2021-0951: Integer Overflow or Wraparound7.8 HighN/A0%Oct 11, 2022
CVE-2021-0696: Concurrent Execution using Shared Resource with Improper Synchronization7.0 HighN/A0%Oct 11, 2022
CVE-2021-35226: Inadequate Encryption Strength6.5 MediumN/A1%Oct 10, 2022
CVE-2021-25044: Improper Neutralization of Input During Web Page Generation6.1 MediumN/A1%Oct 10, 2022
CVE-2021-44171: Improper Neutralization of Special Elements used in an OS Command9.0 CriticalN/A1%Oct 10, 2022
CVE-2021-40163: Out-of-bounds Write7.8 HighN/A1%Oct 7, 2022
CVE-2021-40166: Use After Free7.8 HighN/A1%Oct 7, 2022
CVE-2021-40164: Out-of-bounds Write7.8 HighN/A1%Oct 7, 2022
CVE-2021-40165: Out-of-bounds Write7.8 HighN/A1%Oct 7, 2022
CVE-2021-40162: Out-of-bounds Read7.8 HighN/A1%Oct 7, 2022
CVE-2021-40556: Out-of-bounds Write8.8 HighN/A2%Oct 6, 2022
CVE-2021-36865: Authorization Bypass Through User-Controlled Key3.8 LowN/A1%Sep 30, 2022
CVE-2021-33354: Improper Limitation of a Pathname to a Restricted Directory8.1 HighN/A2%Sep 30, 2022
CVE-2021-36855: Cross-Site Request Forgery (CSRF)6.1 MediumN/A0%Sep 30, 2022
CVE-2021-36854: Cross-Site Request Forgery (CSRF)5.4 MediumN/A0%Sep 30, 2022
CVE-2021-36830: Improper Neutralization of Input During Web Page Generation4.8 MediumN/A1%Sep 30, 2022
CVE-2021-36839: Improper Neutralization of Input During Web Page Generation4.8 MediumN/A1%Sep 30, 2022
CVE-2021-43362: Improper Neutralization of Special Elements used in an SQL Command9.9 CriticalN/A1%Sep 29, 2022
CVE-2021-43361: Improper Neutralization of Special Elements used in an SQL Command9.9 CriticalN/A1%Sep 29, 2022
CVE-2021-41434: Improper Neutralization of Input During Web Page Generation5.4 MediumN/A1%Sep 28, 2022
CVE-2021-43980: Concurrent Execution using Shared Resource with Improper Synchronization3.7 LowN/A2%Sep 28, 2022
CVE-2021-41433: Improper Neutralization of Special Elements used in an SQL Command9.8 CriticalN/A1%Sep 27, 2022
CVE-2021-27862: Improper Handling of Length Parameter Inconsistency4.7 MediumN/A1%Sep 27, 2022
2676-2700 of 23470