The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
TitleEitWModules
CVE-2021-37524: Improper Neutralization of Input During Web Page Generation6.1 MediumN/A1%Jul 1, 2022
CVE-2021-32428: Improper Neutralization of Special Elements used in an SQL Command9.8 CriticalN/A1%Jun 30, 2022
CVE-2021-41995: Authentication Bypass Using an Alternate Path or Channel7.7 HighN/A1%Jun 30, 2022
CVE-2021-38954: Undefined Security Weakness4.3 MediumN/A1%Jun 30, 2022
CVE-2021-38941: Undefined Security Weakness8.1 HighN/A1%Jun 30, 2022
CVE-2021-37791: Undefined Security Weakness4.9 MediumN/A1%Jun 30, 2022
CVE-2021-37778: Buffer Copy without Checking Size of Input9.8 CriticalN/A2%Jun 30, 2022
CVE-2021-37770: Unrestricted Upload of File with Dangerous Type7.2 HighN/A1%Jun 30, 2022
CVE-2021-41506: Improper Authentication9.8 CriticalN/A2%Jun 30, 2022
CVE-2021-40663: Improperly Controlled Modification of Object Prototype Attributes9.8 CriticalN/A2%Jun 30, 2022
CVE-2021-40643: Undefined Security Weakness9.8 CriticalN/A3%Jun 30, 2022
CVE-2021-40597: Use of Hard-coded Credentials9.8 CriticalN/A2%Jun 29, 2022
CVE-2021-39074: Improper Neutralization of Input During Web Page Generation6.1 MediumN/A1%Jun 29, 2022
CVE-2021-40642: Missing Encryption of Sensitive Data4.3 MediumN/A1%Jun 29, 2022
CVE-2021-41559: Improper Restriction of Recursive Entity References in DTDs6.5 MediumN/A1%Jun 28, 2022
CVE-2021-3435: Use of Uninitialized Resource4.0 MediumN/A0%Jun 28, 2022
CVE-2021-3434: Stack-based Buffer Overflow4.9 MediumN/A0%Jun 28, 2022
CVE-2021-3433: Improper Check or Handling of Exceptional Conditions4.0 MediumN/A0%Jun 28, 2022
CVE-2021-3432: Divide By Zero4.3 MediumN/A1%Jun 28, 2022
CVE-2021-3431: Reachable Assertion4.3 MediumN/A1%Jun 28, 2022
CVE-2021-3430: Reachable Assertion6.5 MediumN/A1%Jun 28, 2022
CVE-2021-3779: Externally Controlled Reference to a Resource in Another Sphere6.5 MediumN/A1%Jun 28, 2022
CVE-2021-40553: Improper Control of Generation of Code8.8 HighN/A2%Jun 28, 2022
CVE-2021-41460: Improper Neutralization of Special Elements used in an SQL Command7.5 HighN/A7%Jun 28, 2022
CVE-2021-40607: Allocation of Resources Without Limits or Throttling5.5 MediumN/A1%Jun 28, 2022
3101-3125 of 23470