The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
TitleEitWModules
CVE-2021-39369: Improper Limitation of a Pathname to a Restricted Directory6.5 MediumN/A1%Dec 26, 2022
CVE-2021-35954: Undefined Security Weakness8.1 HighN/A0%Dec 26, 2022
CVE-2021-43395: Improper Locking5.5 MediumN/A0%Dec 26, 2022
CVE-2021-35065: Inefficient Regular Expression Complexity7.5 HighN/A2%Dec 26, 2022
CVE-2021-38561: Out-of-bounds Read7.5 HighN/A1%Dec 26, 2022
CVE-2021-45466: Incorrect Authorization9.8 CriticalN/A55%Dec 26, 2022
CVE-2021-35952: Undefined Security Weakness5.3 MediumN/A1%Dec 26, 2022
CVE-2021-35953: Undefined Security Weakness7.5 HighN/A1%Dec 26, 2022
CVE-2021-44856: Improper Check for Unusual or Exceptional Conditions5.3 MediumN/A1%Dec 26, 2022
CVE-2021-4280: Improper Resource Shutdown or Release4.3 MediumN/A1%Dec 25, 2022
CVE-2021-4279: Improperly Controlled Modification of Object Prototype Attributes6.3 MediumN/A1%Dec 25, 2022
CVE-2021-4278: Improperly Controlled Modification of Object Prototype Attributes5.5 MediumN/A0%Dec 25, 2022
CVE-2021-4277: Predictable from Observable State2.6 LowN/A0%Dec 25, 2022
CVE-2021-4276: Improper Neutralization of Special Elements used in an SQL Command4.1 MediumN/A1%Dec 25, 2022
CVE-2021-32692: Improper Neutralization of Special Elements used in a Command9.6 CriticalN/A1%Dec 23, 2022
CVE-2021-36631: Uncontrolled Search Path Element6.7 MediumN/A0%Dec 22, 2022
CVE-2021-4126: Undefined Security Weakness6.5 MediumN/A0%Dec 22, 2022
CVE-2021-4127: Undefined Security Weakness9.8 CriticalN/A1%Dec 22, 2022
CVE-2021-4129: Out-of-bounds Write9.8 CriticalN/A1%Dec 22, 2022
CVE-2021-4140: XML Injection (aka Blind XPath Injection)10.0 CriticalN/A1%Dec 22, 2022
CVE-2021-4221: Insufficient Visual Distinction of Homoglyphs Presented to User4.3 MediumN/A0%Dec 22, 2022
CVE-2021-43657: Improper Neutralization of Input During Web Page Generation5.4 MediumN/A1%Dec 22, 2022
CVE-2021-4128: Use After Free6.5 MediumN/A1%Dec 22, 2022
CVE-2021-4266: Improper Neutralization3.5 LowN/A1%Dec 21, 2022
CVE-2021-4270: Improper Neutralization3.5 LowN/A0%Dec 21, 2022
2401-2425 of 23470