The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
CVE-2026-94127:Critical Unauthenticated RCE in F5 BIG-IP APM
CVE-2026-76461:Critical Cisco Secure Email Gateway Vulnerability Exploited in the Wild
CVE-2026-85706:Critical GitLab Path Traversal Exploited in the Wild
CVE-2026-83548:Critical SonicWall SMA1000 Vulnerabilities CVE-2026-83548, CVE-2026-83549 Exploited in the Wild
CVE-2026-81578:PaperCut NG/MF Critical Zero-Day Exploited in the Wild
CVE-2026-63520:Rapid7 Analysis: Microsoft SharePoint Remote Code Execution (CVE-2026-63520)
TitleEitWModules
CVE-2026-20848: Concurrent Execution using Shared Resource with Improper Synchronization7.5 HighN/A1%Jan 13, 2026
CVE-2026-20847: Exposure of Sensitive Information to an Unauthorized Actor6.5 MediumN/A1%Jan 13, 2026
CVE-2026-20844: Use After Free7.4 HighN/A0%Jan 13, 2026
CVE-2026-20843: Improper Access Control7.8 HighN/A3%Jan 13, 2026
CVE-2026-20842: Use After Free7.0 HighN/A0%Jan 13, 2026
CVE-2026-20840: Heap-based Buffer Overflow7.8 HighN/A5%Jan 13, 2026
CVE-2026-20839: Improper Access Control5.5 MediumN/A0%Jan 13, 2026
CVE-2026-20838: Generation of Error Message Containing Sensitive Information5.5 MediumN/A1%Jan 13, 2026
CVE-2026-20837: Heap-based Buffer Overflow7.8 HighN/A1%Jan 13, 2026
CVE-2026-20836: Concurrent Execution using Shared Resource with Improper Synchronization7.0 HighN/A0%Jan 13, 2026
CVE-2026-20835: Out-of-bounds Read5.5 MediumN/A1%Jan 13, 2026
CVE-2026-20834: Absolute Path Traversal4.6 MediumN/A1%Jan 13, 2026
CVE-2026-20832: Double Free7.8 HighN/A0%Jan 13, 2026
CVE-2026-20831: Time-of-check Time-of-use (TOCTOU) Race Condition7.0 HighN/A0%Jan 13, 2026
CVE-2026-20829: Out-of-bounds Read5.5 MediumN/A1%Jan 13, 2026
CVE-2026-20828: Out-of-bounds Read4.6 MediumN/A1%Jan 13, 2026
CVE-2026-20827: Exposure of Sensitive Information to an Unauthorized Actor5.5 MediumN/A1%Jan 13, 2026
CVE-2026-20826: Concurrent Execution using Shared Resource with Improper Synchronization7.0 HighN/A0%Jan 13, 2026
CVE-2026-20825: Improper Access Control4.4 MediumN/A1%Jan 13, 2026
CVE-2026-20824: Protection Mechanism Failure5.5 MediumN/A1%Jan 13, 2026
CVE-2026-20823: Exposure of Sensitive Information to an Unauthorized Actor5.5 MediumN/A1%Jan 13, 2026
CVE-2026-20822: Use After Free7.8 HighN/A0%Jan 13, 2026
CVE-2026-20821: Exposure of Sensitive Information to an Unauthorized Actor6.2 MediumN/A1%Jan 13, 2026
CVE-2026-20820: Heap-based Buffer Overflow7.8 HighN/A3%Jan 13, 2026
CVE-2026-20819: Untrusted Pointer Dereference5.5 MediumN/A1%Jan 13, 2026
2701-2725 of 16011