The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
TitleEitWModules
CVE-2021-4315: Improper Neutralization of Special Elements Used in a Template Engine5.5 MediumN/A1%Jan 28, 2023
CVE-2021-41231: Improper Neutralization of Special Elements used in a Command7.2 HighN/A1%Jan 27, 2023
CVE-2021-41144: Improper Neutralization of Special Elements used in a Command8.8 HighN/A1%Jan 27, 2023
CVE-2021-41143: Improper Neutralization of Special Elements used in a Command7.2 HighN/A1%Jan 27, 2023
CVE-2021-39217: Improper Neutralization of Special Elements used in a Command7.2 HighN/A1%Jan 27, 2023
CVE-2021-21395: Cross-Site Request Forgery (CSRF)4.2 MediumN/A0%Jan 27, 2023
CVE-2021-36686: Improper Neutralization of Input During Web Page Generation5.4 MediumN/A0%Jan 26, 2023
CVE-2021-41989: Exposure of Resource to Wrong Sphere7.8 HighN/A0%Jan 26, 2023
CVE-2021-41988: Exposure of Resource to Wrong Sphere7.8 HighN/A0%Jan 26, 2023
CVE-2021-36539: Authorization Bypass Through User-Controlled Key6.5 MediumN/A0%Jan 26, 2023
CVE-2021-28510: Uncontrolled Resource Consumption5.3 MediumN/A1%Jan 24, 2023
CVE-2021-24837: Undefined Security Weakness5.4 MediumN/A0%Jan 23, 2023
CVE-2021-24881: Undefined Security Weakness7.5 HighN/A1%Jan 23, 2023
CVE-2021-43444: Improper Authentication7.5 HighN/A2%Jan 23, 2023
CVE-2021-43445: Improper Authentication9.8 CriticalN/A2%Jan 23, 2023
CVE-2021-43446: Improper Neutralization of Input During Web Page Generation6.1 MediumN/A6%Jan 23, 2023
CVE-2021-43447: Missing Authentication for Critical Function7.5 HighN/A0%Jan 23, 2023
CVE-2021-43448: Improper Input Validation5.3 MediumN/A0%Jan 23, 2023
CVE-2021-43449: Server-Side Request Forgery (SSRF)8.1 HighN/A1%Jan 23, 2023
CVE-2021-39089: Exposure of Sensitive Information to an Unauthorized Actor4.3 MediumN/A0%Jan 20, 2023
CVE-2021-39011: Insertion of Sensitive Information into Log File4.2 MediumN/A0%Jan 20, 2023
CVE-2021-37500: Improper Limitation of a Pathname to a Restricted Directory8.1 HighN/A1%Jan 20, 2023
CVE-2021-37499: Improper Neutralization of Special Elements in Output Used by a Downstream Component6.5 MediumN/A1%Jan 20, 2023
CVE-2021-37498: Server-Side Request Forgery (SSRF)6.5 MediumN/A1%Jan 20, 2023
CVE-2021-33641: Use After Free7.8 HighN/A0%Jan 20, 2023
2176-2200 of 23470