The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
TitleEitWModules
CVE-2020-36980: Unquoted Search Path or Element7.8 High8.5 High0%Jan 27, 2026
CVE-2020-36979: Unquoted Search Path or Element7.8 High8.5 High0%Jan 27, 2026
CVE-2026-21408: Uncontrolled Search Path Element7.3 High5.4 Medium0%Jan 27, 2026
CVE-2025-30248: Uncontrolled Search Path ElementN/A8.9 High1%Jan 26, 2026
CVE-2026-24131: Improper Limitation of a Pathname to a Restricted Directory5.5 Medium6.7 Medium0%Jan 26, 2026
CVE-2026-23889: Improper Limitation of a Pathname to a Restricted Directory6.5 MediumN/A0%Jan 26, 2026
CVE-2025-71178: Uncontrolled Search Path ElementN/A7.1 High0%Jan 26, 2026
CVE-2020-36958: Unquoted Search Path or Element7.8 High8.5 High0%Jan 26, 2026
CVE-2025-59105: Cleartext Storage of Sensitive InformationN/A7.0 High0%Jan 26, 2026
CVE-2025-59103: Use of Weak CredentialsN/A9.2 Critical0%Jan 26, 2026
CVE-2020-36937: Unquoted Search Path or Element7.8 High8.5 High0%Jan 25, 2026
CVE-2020-36936: Unquoted Search Path or Element7.8 High8.5 High0%Jan 25, 2026
CVE-2020-36934: Unquoted Search Path or Element7.8 High8.5 High0%Jan 25, 2026
CVE-2021-47881: Stack-based Buffer Overflow8.4 High6.7 Medium0%Jan 23, 2026
CVE-2026-23761: Access of Uninitialized PointerN/A6.9 Medium0%Jan 22, 2026
CVE-2026-23762: Improper Handling of Exceptional ConditionsN/A6.9 Medium0%Jan 22, 2026
CVE-2026-23764: Use of Out-of-range Pointer OffsetN/A6.8 Medium0%Jan 22, 2026
CVE-2026-23518: Improper Verification of Cryptographic Signature9.8 Critical9.3 Critical0%Jan 21, 2026
CVE-2026-22808: Improper Neutralization of Input During Web Page Generation5.4 Medium5.5 Medium0%Jan 21, 2026
CVE-2021-47882: Unquoted Search Path or Element7.8 High8.5 High0%Jan 21, 2026
CVE-2021-47874: Unquoted Search Path or Element7.8 High8.5 High0%Jan 21, 2026
CVE-2021-47863: Unquoted Search Path or Element7.8 High8.5 High0%Jan 21, 2026
CVE-2026-22444: Improper Input Validation7.1 HighN/A1%Jan 21, 2026
CVE-2026-24016: Uncontrolled Search Path Element7.8 High8.4 High0%Jan 21, 2026
CVE-2026-21986: Undefined Security Weakness7.1 HighN/A0%Jan 20, 2026
2601-2625 of 16013