The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
TitleEitWModules
CVE-2023-23357: Improper Neutralization of Input During Web Page Generation4.8 MediumN/A0%Dec 19, 2024
CVE-2023-23356: Improper Neutralization of Special Elements used in a Command5.5 MediumN/A1%Dec 19, 2024
CVE-2023-23354: Improper Neutralization of Input During Web Page Generation7.3 HighN/A1%Dec 19, 2024
CVE-2022-27600: Uncontrolled Resource Consumption6.8 MediumN/A1%Dec 19, 2024
CVE-2022-27595: Uncontrolled Search Path Element7.8 HighN/A0%Dec 19, 2024
CVE-2022-33954: Insufficiently Protected Credentials4.6 MediumN/A0%Dec 19, 2024
CVE-2021-39081: Cleartext Transmission of Sensitive Information5.9 MediumN/A0%Dec 19, 2024
CVE-2024-55603: Insufficient Session Expiration6.5 MediumN/A1%Dec 19, 2024
CVE-2023-21586: NULL Pointer Dereference5.5 MediumN/A2%Dec 19, 2024
CVE-2022-44520: Use After Free7.8 HighN/A0%Dec 19, 2024
CVE-2022-44519: Use After Free5.5 MediumN/A0%Dec 19, 2024
CVE-2022-44518: Use After Free7.8 HighN/A0%Dec 19, 2024
CVE-2022-44517: Out-of-bounds Read5.5 MediumN/A0%Dec 19, 2024
CVE-2022-44516: Out-of-bounds Read5.5 MediumN/A0%Dec 19, 2024
CVE-2022-44515: Out-of-bounds Read5.5 MediumN/A0%Dec 19, 2024
CVE-2022-44514: Use After Free7.8 HighN/A0%Dec 19, 2024
CVE-2022-44513: Out-of-bounds Write7.8 HighN/A0%Dec 19, 2024
CVE-2022-44512: Out-of-bounds Write7.8 HighN/A0%Dec 19, 2024
CVE-2021-29827: Improper Restriction of Rendered UI Layers or Frames5.2 MediumN/A0%Dec 19, 2024
CVE-2021-20553: Improper Neutralization of Input During Web Page Generation5.4 MediumN/A0%Dec 19, 2024
CVE-2024-56319: Allocation of Resources Without Limits or Throttling7.5 HighN/A1%Dec 18, 2024
CVE-2024-56318: NULL Pointer Dereference7.5 HighN/A1%Dec 18, 2024
CVE-2024-56317: Improper Preservation of Permissions7.5 HighN/A0%Dec 18, 2024
CVE-2024-56116: Cross-Site Request Forgery (CSRF)8.8 HighN/A0%Dec 18, 2024
CVE-2024-56115: Improper Neutralization of Input During Web Page Generation6.1 MediumN/A0%Dec 18, 2024
122626-122650 of 395809