The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
TitleEitWModules
CVE-2021-41737: Uncontrolled Recursion7.5 HighN/A0%Nov 10, 2024
CVE-2021-35473: Insufficient Session Expiration9.1 CriticalN/A0%Nov 10, 2024
CVE-2021-4452: Improper Neutralization of Input During Web Page Generation7.1 HighN/A0%Oct 16, 2024
CVE-2021-4451: Deserialization of Untrusted Data6.6 MediumN/A1%Oct 16, 2024
CVE-2021-4450: Improper Neutralization of Special Elements used in an SQL Command8.8 HighN/A1%Oct 16, 2024
CVE-2021-4449: Unrestricted Upload of File with Dangerous Type9.8 CriticalN/A82%Oct 16, 2024
CVE-2021-4448: Missing Authorization7.3 HighN/A49%Oct 16, 2024
CVE-2021-4447: Missing Authorization8.8 HighN/A0%Oct 16, 2024
CVE-2021-4446: Missing Authorization6.3 MediumN/A0%Oct 16, 2024
CVE-2021-4445: Missing Authorization6.5 MediumN/A0%Oct 16, 2024
CVE-2021-4444: Missing Authorization7.3 HighN/A0%Oct 16, 2024
CVE-2021-4443: Unrestricted Upload of File with Dangerous Type9.8 CriticalN/A2%Oct 16, 2024
CVE-2021-37577: Authorization Bypass Through User-Controlled Key6.8 MediumN/A0%Oct 1, 2024
CVE-2021-38963: Improper Neutralization of Formula Elements in a CSV File8.0 HighN/A0%Sep 25, 2024
CVE-2021-38023: Use After Free8.8 HighN/A1%Sep 23, 2024
CVE-2021-27917: Improper Neutralization of Input During Web Page Generation7.3 HighN/A0%Sep 18, 2024
CVE-2021-27916: Improper Limitation of a Pathname to a Restricted Directory8.1 HighN/A0%Sep 17, 2024
CVE-2021-27915: Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)7.6 HighN/A0%Sep 17, 2024
CVE-2021-38133: Weak Password Requirements7.4 HighN/A0%Sep 12, 2024
CVE-2021-38132: Server-Side Request Forgery (SSRF)5.3 MediumN/A0%Sep 12, 2024
CVE-2021-38131: Improper Neutralization of Input During Web Page Generation5.4 MediumN/A0%Sep 12, 2024
CVE-2021-22533: Insertion of Sensitive Information into Log File6.5 MediumN/A0%Sep 12, 2024
CVE-2021-22532: Allocation of Resources Without Limits or Throttling7.6 HighN/A0%Sep 12, 2024
CVE-2021-22518: Insertion of Sensitive Information into Log File5.8 MediumN/A0%Sep 12, 2024
CVE-2021-22503: Improper Neutralization of Input During Web Page Generation5.4 MediumN/A0%Sep 12, 2024
601-625 of 23470