The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
TitleEitWModules
CVE-2020-19959: Improper Neutralization of Special Elements used in an SQL Command7.5 HighN/A2%Oct 14, 2021
CVE-2020-19960: Improper Neutralization of Special Elements used in an SQL Command7.5 HighN/A2%Oct 14, 2021
CVE-2020-19962: Improper Neutralization of Input During Web Page Generation5.4 MediumN/A1%Oct 14, 2021
CVE-2020-22724: Improper Neutralization of Special Elements used in an OS Command9.8 CriticalN/A6%Oct 14, 2021
CVE-2020-22673: Missing Release of Memory after Effective Lifetime5.5 MediumN/A1%Oct 12, 2021
CVE-2020-22675: Out-of-bounds Write5.5 MediumN/A1%Oct 12, 2021
CVE-2020-22674: NULL Pointer Dereference5.5 MediumN/A1%Oct 12, 2021
CVE-2020-22677: Out-of-bounds Write5.5 MediumN/A1%Oct 12, 2021
CVE-2020-22679: Missing Release of Memory after Effective Lifetime5.5 MediumN/A1%Oct 12, 2021
CVE-2020-22678: Out-of-bounds Write5.5 MediumN/A1%Oct 12, 2021
CVE-2020-28145: Exposure of Resource to Wrong Sphere7.5 HighN/A1%Oct 12, 2021
CVE-2020-27372: Buffer Copy without Checking Size of Input9.8 CriticalN/A1%Oct 11, 2021
CVE-2020-22617: Use After Free9.8 CriticalN/A1%Oct 8, 2021
CVE-2020-4654: Undefined Security Weakness6.5 MediumN/A1%Oct 8, 2021
CVE-2020-21729: Improper Neutralization of Input During Web Page Generation5.4 MediumN/A1%Oct 7, 2021
CVE-2020-21726: Improper Neutralization of Special Elements used in an SQL Command9.8 CriticalN/A1%Oct 7, 2021
CVE-2020-21725: Improper Neutralization of Special Elements used in an SQL Command9.8 CriticalN/A1%Oct 7, 2021
CVE-2020-21865: Undefined Security Weakness9.8 CriticalN/A2%Oct 7, 2021
CVE-2020-21658: Cross-Site Request Forgery (CSRF)6.5 MediumN/A0%Oct 6, 2021
CVE-2020-21656: Improper Neutralization of Input During Web Page Generation5.4 MediumN/A0%Oct 6, 2021
CVE-2020-21654: Undefined Security Weakness7.2 HighN/A1%Oct 6, 2021
CVE-2020-21653: Server-Side Request Forgery (SSRF)9.1 CriticalN/A1%Oct 6, 2021
CVE-2020-21651: Improper Control of Generation of Code9.8 CriticalN/A3%Oct 6, 2021
CVE-2020-21652: Improper Control of Generation of Code9.8 CriticalN/A3%Oct 6, 2021
CVE-2020-21650: Improper Control of Generation of Code8.8 HighN/A3%Oct 6, 2021
2701-2725 of 21077