The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
TitleEitWModules
CVE-2021-41074: Cross-Site Request Forgery (CSRF)5.4 MediumN/A0%Jan 12, 2026
CVE-2021-47747: Improper Neutralization of Special Elements used in an OS Command8.8 High8.6 High0%Dec 31, 2025
CVE-2021-47745: Improper Neutralization of Special Elements used in an OS Command8.8 High8.6 High0%Dec 31, 2025
CVE-2021-47744: Use of Hard-coded Credentials7.5 High9.3 Critical0%Dec 31, 2025
CVE-2021-47742: Incorrect Permission Assignment for Critical Resource8.8 High8.5 High0%Dec 31, 2025
CVE-2021-47741: Insufficiently Protected Credentials7.5 High8.7 High0%Dec 31, 2025
CVE-2021-47740: Insufficient Session Expiration7.5 High6.9 Medium0%Dec 31, 2025
CVE-2021-47726: Insufficiently Protected Credentials7.5 High8.7 High0%Dec 31, 2025
CVE-2021-47743: Improper Neutralization of Input During Web Page Generation6.1 Medium5.1 Medium0%Dec 31, 2025
CVE-2021-47725: Improper Neutralization of Input During Web Page Generation5.4 Medium4.8 Medium0%Dec 31, 2025
CVE-2021-47739: Unquoted Search Path or Element8.4 High8.5 High0%Dec 23, 2025
CVE-2021-47738: Improper Neutralization of Input During Web Page Generation5.4 Medium5.1 Medium0%Dec 23, 2025
CVE-2021-47737: Improper Neutralization of Input During Web Page Generation5.4 Medium5.1 Medium0%Dec 23, 2025
CVE-2021-47736: Improper Control of Generation of Code7.2 High8.6 High1%Dec 23, 2025
CVE-2021-47735: Improper Control of Generation of Code8.8 High8.6 High0%Dec 23, 2025
CVE-2021-47734: Improper Control of Filename for Include/Require Statement in PHP Program7.8 High8.6 High0%Dec 23, 2025
CVE-2021-47733: Improper Neutralization of Input During Web Page Generation6.1 Medium5.1 Medium0%Dec 23, 2025
CVE-2021-47732: Improper Neutralization of Input During Web Page Generation6.1 Medium5.1 Medium0%Dec 23, 2025
CVE-2021-47722: Cross-Site Request Forgery (CSRF)3.5 Low5.1 Medium0%Dec 23, 2025
CVE-2021-47721: Authorization Bypass Through User-Controlled Key8.8 High8.7 High0%Dec 23, 2025
CVE-2021-47720: Improper Neutralization of Special Elements used in an SQL Command7.1 High8.7 High0%Dec 23, 2025
CVE-2021-47716: Improper Neutralization of Input During Web Page Generation5.4 Medium5.1 Medium0%Dec 23, 2025
CVE-2021-47714: Improper Neutralization of Special Elements used in an SQL Command5.5 Medium6.9 Medium0%Dec 22, 2025
CVE-2021-47713: Allocation of Resources Without Limits or Throttling7.5 High8.7 High0%Dec 22, 2025
CVE-2021-47715: Server-Side Request Forgery (SSRF)5.3 Medium6.9 Medium0%Dec 22, 2025
301-325 of 23470