The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
TitleEitWModules
CVE-2025-58742: Insufficiently Protected Credentials5.9 Medium8.5 High0%Jan 20, 2026
CVE-2025-58740: Use of Hard-coded Cryptographic Key5.5 Medium8.5 High0%Jan 20, 2026
CVE-2025-33231: Uncontrolled Search Path Element6.7 MediumN/A0%Jan 20, 2026
CVE-2025-33229: Uncontrolled Search Path Element7.3 HighN/A0%Jan 20, 2026
CVE-2026-0903: Improper Input Validation5.4 MediumN/A0%Jan 20, 2026
CVE-2025-15032: Improper Restriction of Rendered UI Layers or Frames7.4 HighN/A0%Jan 16, 2026
CVE-2021-47845: Unquoted Search Path or Element7.8 High8.5 High0%Jan 16, 2026
CVE-2021-47828: Unquoted Search Path or Element7.8 High8.5 High0%Jan 16, 2026
CVE-2021-47818: Improper Validation of Specified Quantity in Input7.5 High4.6 Medium0%Jan 16, 2026
CVE-2021-47809: Unquoted Search Path or Element7.8 High8.5 High0%Jan 16, 2026
CVE-2021-47805: Unquoted Search Path or Element7.8 High8.5 High0%Jan 16, 2026
CVE-2020-36929: Unquoted Search Path or Element7.8 High8.5 High0%Jan 16, 2026
CVE-2020-36927: Unquoted Search Path or Element7.8 High8.5 High0%Jan 16, 2026
CVE-2021-47807: Unquoted Search Path or Element7.8 High8.5 High0%Jan 15, 2026
CVE-2021-47806: Unquoted Search Path or Element7.8 High8.5 High0%Jan 15, 2026
CVE-2026-22864: Improper Neutralization of Special Elements used in a Command8.1 HighN/A1%Jan 15, 2026
CVE-2021-47759: Insufficiently Protected Credentials6.2 Medium6.8 Medium0%Jan 15, 2026
CVE-2025-9142: Improper Limitation of a Pathname to a Restricted Directory7.5 HighN/A0%Jan 14, 2026
CVE-2025-71104: Improper LockingN/AN/A0%Jan 14, 2026
CVE-2023-54330: Stack-based Buffer Overflow9.8 Critical9.3 Critical0%Jan 13, 2026
CVE-2022-50935: Unquoted Search Path or Element9.8 Critical8.5 High0%Jan 13, 2026
CVE-2022-50928: Unquoted Search Path or Element7.8 High8.5 High0%Jan 13, 2026
CVE-2022-50920: Unquoted Search Path or Element8.4 High8.5 High0%Jan 13, 2026
CVE-2025-68947: Missing Authorization4.7 Medium5.7 Medium0%Jan 13, 2026
CVE-2026-21265: Reliance on Component That is Not Updateable6.4 MediumN/A1%Jan 13, 2026
2626-2650 of 16011