The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
TitleEitWModules
CVE-2021-41396: Out-of-bounds Write7.5 HighN/A1%Jul 11, 2022
CVE-2021-41037: Inclusion of Functionality from Untrusted Control Sphere10.0 CriticalN/A1%Jul 8, 2022
CVE-2021-41042: Improper Restriction of XML External Entity Reference5.3 MediumN/A1%Jul 7, 2022
CVE-2021-29281: Unrestricted Upload of File with Dangerous Type9.8 CriticalN/A3%Jul 7, 2022
CVE-2021-35283: Improper Neutralization of Special Elements used in an SQL Command9.8 CriticalN/A1%Jul 7, 2022
CVE-2021-31645: Allocation of Resources Without Limits or Throttling7.5 HighN/A2%Jul 7, 2022
CVE-2021-44791: Improper Neutralization of Input During Web Page Generation6.1 MediumN/A2%Jul 7, 2022
CVE-2021-46825: Inconsistent Interpretation of HTTP Requests9.1 CriticalN/A2%Jul 7, 2022
CVE-2021-4234: Insufficient Control of Network Message Volume (Network Amplification)7.5 HighN/A1%Jul 6, 2022
CVE-2021-3697: Out-of-bounds Write7.0 HighN/A0%Jul 6, 2022
CVE-2021-3696: Out-of-bounds Write4.5 MediumN/A0%Jul 6, 2022
CVE-2021-3695: Out-of-bounds Write4.5 MediumN/A0%Jul 6, 2022
CVE-2021-37839: Improper Check for Dropped Privileges4.3 MediumN/A1%Jul 6, 2022
CVE-2021-31678: Cross-Site Request Forgery (CSRF)6.5 MediumN/A1%Jul 6, 2022
CVE-2021-31679: Cross-Site Request Forgery (CSRF)6.5 MediumN/A1%Jul 6, 2022
CVE-2021-31677: Cross-Site Request Forgery (CSRF)6.5 MediumN/A1%Jul 6, 2022
CVE-2021-31676: Improper Neutralization of Input During Web Page Generation6.1 MediumN/A1%Jul 6, 2022
CVE-2021-23163: Cross-Site Request Forgery (CSRF)3.1 LowN/A0%Jul 6, 2022
CVE-2021-46687: Exposure of Private Personal Information to an Unauthorized Actor4.9 MediumN/A1%Jul 6, 2022
CVE-2021-45721: Improper Neutralization of Input During Web Page Generation6.1 MediumN/A1%Jul 6, 2022
CVE-2021-44915: Improper Neutralization of Special Elements used in an SQL Command7.2 HighN/A1%Jul 5, 2022
CVE-2021-43702: Improper Neutralization of Input During Web Page Generation9.0 CriticalN/A1%Jul 5, 2022
CVE-2021-43116: Improper Authentication8.8 HighN/A7%Jul 5, 2022
CVE-2021-25066: Improper Neutralization of Input During Web Page Generation4.8 MediumN/A1%Jul 4, 2022
CVE-2021-25056: Improper Neutralization of Input During Web Page Generation4.8 MediumN/A1%Jul 4, 2022
3076-3100 of 23470