The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
TitleEitWModules
CVE-2021-27861: Improper Handling of Length Parameter Inconsistency4.7 MediumN/A1%Sep 27, 2022
CVE-2021-27854: Authentication Bypass by Spoofing4.7 MediumN/A1%Sep 27, 2022
CVE-2021-27853: Authentication Bypass by Spoofing4.7 MediumN/A1%Sep 27, 2022
CVE-2021-28052: Missing Authorization7.5 HighN/A1%Sep 26, 2022
CVE-2021-41437: Improper Neutralization of Special Elements in Output Used by a Downstream Component6.5 MediumN/A1%Sep 26, 2022
CVE-2021-24890: Missing Authorization8.8 HighN/A1%Sep 26, 2022
CVE-2021-3782: Integer Overflow or Wraparound6.6 MediumN/A0%Sep 23, 2022
CVE-2021-45035: Improper Authentication6.3 MediumN/A0%Sep 23, 2022
CVE-2021-41803: Missing Authorization7.1 HighN/A1%Sep 23, 2022
CVE-2021-27774: Generation of Error Message Containing Sensitive Information3.1 LowN/A0%Sep 22, 2022
CVE-2021-39190: Exposure of Sensitive Information to an Unauthorized Actor5.3 MediumN/A1%Sep 22, 2022
CVE-2021-43310: Authentication Bypass by Spoofing9.8 CriticalN/A2%Sep 21, 2022
CVE-2021-46835: Authentication Bypass by Capture-replay4.3 MediumN/A0%Sep 20, 2022
CVE-2021-46834: Incorrect Default Permissions5.5 MediumN/A0%Sep 20, 2022
CVE-2021-33081: Protection Mechanism Failure7.9 HighN/A0%Sep 20, 2022
CVE-2021-33076: Improper Authentication5.3 MediumN/A0%Sep 20, 2022
CVE-2021-33079: Protection Mechanism Failure4.1 MediumN/A0%Sep 20, 2022
CVE-2021-40019: Out-of-bounds Read9.1 CriticalN/A1%Sep 16, 2022
CVE-2021-40023: Undefined Security Weakness7.5 HighN/A1%Sep 16, 2022
CVE-2021-46836: Undefined Security Weakness7.5 HighN/A1%Sep 16, 2022
CVE-2021-40024: Undefined Security Weakness7.5 HighN/A1%Sep 16, 2022
CVE-2021-42597: Improper Neutralization of Input During Web Page Generation5.4 MediumN/A0%Sep 16, 2022
CVE-2021-41731: Improper Neutralization of Input During Web Page Generation4.8 MediumN/A1%Sep 16, 2022
CVE-2021-42948: Cleartext Transmission of Sensitive Information3.7 LowN/A1%Sep 16, 2022
CVE-2021-42949: Improper Authentication9.8 CriticalN/A7%Sep 16, 2022
2701-2725 of 23470