The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
TitleEitWModules
CVE-2021-23265: Improper Privilege Management3.5 LowN/A1%May 16, 2022
CVE-2021-33318: Incorrect Type Conversion or Cast9.8 CriticalN/A2%May 16, 2022
CVE-2021-25119: Unrestricted Upload of File with Dangerous Type7.2 HighN/A1%May 16, 2022
CVE-2021-42870: Out-of-bounds Read7.5 HighN/A1%May 16, 2022
CVE-2021-42966: Undefined Security Weakness9.8 CriticalN/AN/AMay 16, 2022
CVE-2021-41927: Undefined Security WeaknessN/AN/AN/AMay 16, 2022
CVE-2021-42897: Improper Neutralization of Special Elements used in an OS Command9.8 CriticalN/A3%May 16, 2022
CVE-2021-41965: Improper Neutralization of Special Elements used in an SQL Command8.8 HighN/A1%May 15, 2022
CVE-2021-33013: Improper Access Control8.2 HighN/A1%May 13, 2022
CVE-2021-33009: Unrestricted Upload of File with Dangerous Type7.5 HighN/A1%May 13, 2022
CVE-2021-33005: Improper Limitation of a Pathname to a Restricted Directory7.5 HighN/A2%May 13, 2022
CVE-2021-27505: Exposure of Information Through Directory Listing7.5 HighN/A1%May 13, 2022
CVE-2021-46789: Undefined Security Weakness7.5 HighN/A1%May 13, 2022
CVE-2021-46788: Undefined Security Weakness7.5 HighN/A1%May 13, 2022
CVE-2021-46787: Undefined Security Weakness7.5 HighN/A1%May 13, 2022
CVE-2021-46786: Improper Restriction of Operations within the Bounds of a Memory Buffer9.8 CriticalN/A1%May 13, 2022
CVE-2021-46785: Undefined Security Weakness5.3 MediumN/A1%May 13, 2022
CVE-2021-22275: Buffer Copy without Checking Size of Input8.6 HighN/A1%May 13, 2022
CVE-2021-42969: Improper Neutralization of Special Elements used in an OS Command8.8 HighN/A2%May 13, 2022
CVE-2021-42967: Unrestricted Upload of File with Dangerous Type9.8 CriticalN/A1%May 13, 2022
CVE-2021-27777: XML Injection (aka Blind XPath Injection)7.5 HighN/A1%May 12, 2022
CVE-2021-27773: User Interface (UI) Misrepresentation of Critical Information4.2 MediumN/A0%May 12, 2022
CVE-2021-27772: Improper Authorization7.1 HighN/A1%May 12, 2022
CVE-2021-27771: Unrestricted Upload of File with Dangerous Type8.2 HighN/A1%May 12, 2022
CVE-2021-27770: External Control of Assumed-Immutable Web Parameter6.8 MediumN/A1%May 12, 2022
3501-3525 of 23470