The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
CVE-2026-76461:Critical Cisco Secure Email Gateway Vulnerability Exploited in the Wild
CVE-2026-85706:Critical GitLab Path Traversal Exploited in the Wild
CVE-2026-83548:Critical SonicWall SMA1000 Vulnerabilities CVE-2026-83548, CVE-2026-83549 Exploited in the Wild
CVE-2026-81578:PaperCut NG/MF Critical Zero-Day Exploited in the Wild
CVE-2026-63520:Rapid7 Analysis: Microsoft SharePoint Remote Code Execution (CVE-2026-63520)
CVE-2026-19490:Critical Vulnerability Affecting Citrix NetScaler ADC and NetScaler Gateway
TitleEitWModules
CVE-2025-59210: Use After Free7.4 HighN/A0%Oct 14, 2025
CVE-2025-59209: Exposure of Sensitive Information to an Unauthorized Actor5.5 MediumN/A0%Oct 14, 2025
CVE-2025-59208: Out-of-bounds Read7.1 HighN/A0%Oct 14, 2025
CVE-2025-59207: Untrusted Pointer Dereference7.8 HighN/A0%Oct 14, 2025
CVE-2025-59206: Use After Free7.4 HighN/A0%Oct 14, 2025
CVE-2025-59204: Use of Uninitialized Resource5.5 MediumN/A1%Oct 14, 2025
CVE-2025-59203: Insertion of Sensitive Information into Log File5.5 MediumN/A0%Oct 14, 2025
CVE-2025-59202: Use After Free7.0 HighN/A0%Oct 14, 2025
CVE-2025-59198: Improper Input Validation5.0 MediumN/A0%Oct 14, 2025
CVE-2025-59197: Insertion of Sensitive Information into Log File5.5 MediumN/A0%Oct 14, 2025
CVE-2025-59196: Concurrent Execution using Shared Resource with Improper Synchronization7.0 HighN/A0%Oct 14, 2025
CVE-2025-59194: Use of Uninitialized Resource7.0 HighN/A3%Oct 14, 2025
CVE-2025-59193: Concurrent Execution using Shared Resource with Improper Synchronization7.0 HighN/A0%Oct 14, 2025
CVE-2025-59190: Improper Input Validation5.5 MediumN/A1%Oct 14, 2025
CVE-2025-59188: Exposure of Sensitive Information to an Unauthorized Actor5.5 MediumN/A0%Oct 14, 2025
CVE-2025-59187: Improper Input Validation7.8 HighN/A0%Oct 14, 2025
CVE-2025-59186: Exposure of Sensitive Information to an Unauthorized Actor5.5 MediumN/A1%Oct 14, 2025
CVE-2025-59185: External Control of File Name or Path6.5 MediumN/A1%Oct 14, 2025
CVE-2025-59184: Exposure of Sensitive Information to an Unauthorized Actor5.5 MediumN/A0%Oct 14, 2025
CVE-2025-58739: Exposure of Sensitive Information to an Unauthorized Actor6.5 MediumN/A1%Oct 14, 2025
CVE-2025-58737: Use After Free7.0 HighN/A0%Oct 14, 2025
CVE-2025-58729: Improper Validation of Specified Type of Input6.5 MediumN/A1%Oct 14, 2025
CVE-2025-58728: Use After Free7.8 HighN/A0%Oct 14, 2025
CVE-2025-58727: Concurrent Execution using Shared Resource with Improper Synchronization7.0 HighN/A0%Oct 14, 2025
CVE-2025-58726: Improper Access Control7.5 HighN/A1%Oct 14, 2025
3001-3025 of 16008