The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
TitleEitWModules
CVE-2021-46872: Improper Neutralization of Input During Web Page Generation6.1 MediumN/A1%Jan 13, 2023
CVE-2021-3966: Heap-based Buffer Overflow9.6 CriticalN/A0%Jan 11, 2023
CVE-2021-46791: Out-of-bounds Write5.5 MediumN/A0%Jan 10, 2023
CVE-2021-46779: Out-of-bounds Write7.1 HighN/A0%Jan 10, 2023
CVE-2021-46768: Out-of-bounds Read5.5 MediumN/A0%Jan 10, 2023
CVE-2021-46767: Improper Input Validation6.1 MediumN/A0%Jan 10, 2023
CVE-2021-26409: Buffer Copy without Checking Size of Input7.8 HighN/A0%Jan 10, 2023
CVE-2021-26407: Use of Insufficiently Random Values5.5 MediumN/A0%Jan 10, 2023
CVE-2021-26404: Improper Input Validation5.5 MediumN/A0%Jan 10, 2023
CVE-2021-26403: Insufficient Verification of Data Authenticity6.5 MediumN/A0%Jan 10, 2023
CVE-2021-26402: Out-of-bounds Write7.1 HighN/A0%Jan 10, 2023
CVE-2021-26398: Out-of-bounds Write7.8 HighN/A0%Jan 10, 2023
CVE-2021-26396: Insufficient Verification of Data Authenticity4.4 MediumN/A0%Jan 10, 2023
CVE-2021-26355: Protection Mechanism Failure5.5 MediumN/A0%Jan 10, 2023
CVE-2021-26343: Exposure of Resource to Wrong Sphere5.5 MediumN/A0%Jan 10, 2023
CVE-2021-26328: Improperly Implemented Security Check for Standard4.4 MediumN/A0%Jan 10, 2023
CVE-2021-46795: Time-of-check Time-of-use (TOCTOU) Race Condition4.7 MediumN/A0%Jan 10, 2023
CVE-2021-26346: Integer Overflow or Wraparound5.5 MediumN/A0%Jan 10, 2023
CVE-2021-26316: Improper Input Validation7.8 HighN/A0%Jan 10, 2023
CVE-2021-46871: Improper Neutralization of Input During Web Page Generation6.1 MediumN/A0%Jan 10, 2023
CVE-2021-4311: Improper Restriction of XML External Entity Reference5.5 MediumN/A0%Jan 9, 2023
CVE-2021-4310: Improper Neutralization of Input During Web Page Generation3.5 LowN/A0%Jan 9, 2023
CVE-2021-36603: Improper Neutralization of Input During Web Page Generation6.1 MediumN/A0%Jan 9, 2023
CVE-2021-4309: Improper Neutralization of Input During Web Page Generation3.5 LowN/A0%Jan 8, 2023
CVE-2021-4308: Improper Neutralization of Special Elements used in an SQL Command5.5 MediumN/A0%Jan 8, 2023
2226-2250 of 23470