The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
TitleEitWModules
CVE-2021-21158: Undefined Security WeaknessN/AN/AN/AJan 17, 2025
CVE-2021-0447: Undefined Security WeaknessN/AN/AN/AJan 17, 2025
CVE-2021-0323: Undefined Security WeaknessN/AN/AN/AJan 17, 2025
CVE-2021-35685: Undefined Security WeaknessN/AN/AN/AJan 16, 2025
CVE-2021-35684: Undefined Security WeaknessN/AN/AN/AJan 16, 2025
CVE-2021-29669: Improper Neutralization of Input During Web Page Generation5.4 MediumN/A0%Jan 12, 2025
CVE-2021-20455: Generation of Error Message Containing Sensitive Information3.7 LowN/A0%Jan 7, 2025
CVE-2021-27285: Incorrect Default Permissions8.4 HighN/A0%Jan 6, 2025
CVE-2021-37000: Incorrect Default Permissions7.7 HighN/A0%Dec 28, 2024
CVE-2021-22484: Improper Input Validation7.5 HighN/A0%Dec 28, 2024
CVE-2021-40959: Improper Neutralization of Input During Web Page Generation6.1 MediumN/A0%Dec 20, 2024
CVE-2021-22501: Improper Restriction of XML External Entity ReferenceN/A5.3 Medium0%Dec 19, 2024
CVE-2021-26102: Authentication Bypass by Primary Weakness9.8 CriticalN/A20%Dec 19, 2024
CVE-2021-32589: Use After Free8.1 HighN/A9%Dec 19, 2024
CVE-2021-26115: Improper Neutralization of Special Elements used in an OS Command7.8 HighN/A1%Dec 19, 2024
CVE-2021-26093: Access of Uninitialized Pointer7.3 HighN/A0%Dec 19, 2024
CVE-2021-39081: Cleartext Transmission of Sensitive Information5.9 MediumN/A0%Dec 19, 2024
CVE-2021-29827: Improper Restriction of Rendered UI Layers or Frames5.2 MediumN/A0%Dec 19, 2024
CVE-2021-20553: Improper Neutralization of Input During Web Page Generation5.4 MediumN/A0%Dec 19, 2024
CVE-2021-26281: Exposure of Sensitive Information to an Unauthorized Actor5.5 MediumN/A0%Dec 17, 2024
CVE-2021-26280: Missing Authentication for Critical Function7.9 HighN/A0%Dec 17, 2024
CVE-2021-26279: Exposure of Sensitive Information to an Unauthorized Actor5.9 MediumN/A0%Dec 17, 2024
CVE-2021-26278: Missing Authentication for Critical Function6.3 MediumN/A0%Dec 17, 2024
CVE-2021-32007: Exposure of Sensitive Information to an Unauthorized Actor3.5 LowN/A0%Dec 13, 2024
CVE-2021-0937: Undefined Security WeaknessN/AN/AN/ADec 5, 2024
526-550 of 23470