The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
TitleEitWModules
CVE-2021-42654: Unrestricted Upload of File with Dangerous Type9.8 CriticalN/A2%May 24, 2022
CVE-2021-42659: Improper Restriction of Operations within the Bounds of a Memory Buffer6.5 MediumN/A1%May 24, 2022
CVE-2021-32958: Authentication Bypass Using an Alternate Path or Channel5.5 MediumN/A0%May 23, 2022
CVE-2021-32941: Stack-based Buffer Overflow9.4 CriticalN/A15%May 23, 2022
CVE-2021-32935: Deserialization of Untrusted Data8.8 HighN/A2%May 23, 2022
CVE-2021-42233: Improper Neutralization of Input During Web Page Generation5.4 MediumN/A1%May 23, 2022
CVE-2021-41714: Download of Code Without Integrity Check7.7 HighN/A1%May 23, 2022
CVE-2021-42586: Out-of-bounds Write8.8 HighN/A1%May 23, 2022
CVE-2021-42585: Out-of-bounds Write8.8 HighN/A1%May 23, 2022
CVE-2021-41834: Improper Access Control5.3 MediumN/A1%May 23, 2022
CVE-2021-36833: Improper Neutralization of Input During Web Page Generation4.8 MediumN/A1%May 20, 2022
CVE-2021-39043: Improper Neutralization of Input During Web Page Generation5.4 MediumN/A0%May 20, 2022
CVE-2021-30028: Improper Authentication7.2 HighN/A1%May 20, 2022
CVE-2021-43728: Improper Neutralization of Input During Web Page Generation5.4 MediumN/A1%May 20, 2022
CVE-2021-43729: Improper Neutralization of Input During Web Page Generation5.4 MediumN/A1%May 20, 2022
CVE-2021-34111: Improper Neutralization of Special Elements used in an OS Command9.8 CriticalN/A3%May 20, 2022
CVE-2021-32934: Cleartext Transmission of Sensitive Information9.1 CriticalN/A1%May 19, 2022
CVE-2021-37413: Improper Neutralization of Special Elements used in an SQL Command9.8 CriticalN/A2%May 19, 2022
CVE-2021-26631: Improper Input Validation8.0 HighN/A1%May 19, 2022
CVE-2021-26630: Improper Input Validation7.8 HighN/A1%May 19, 2022
CVE-2021-45730: Improper Access Control6.0 MediumN/A1%May 19, 2022
CVE-2021-41938: Unrestricted Upload of File with Dangerous Type7.2 HighN/A1%May 19, 2022
CVE-2021-38944: Improper Neutralization of Input During Web Page Generation6.1 MediumN/A1%May 18, 2022
CVE-2021-42704: Out-of-bounds Write7.8 HighN/A2%May 18, 2022
CVE-2021-42702: Access of Uninitialized Pointer3.3 LowN/A1%May 18, 2022
3451-3475 of 23470