The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
CVE-2026-76461:Critical Cisco Secure Email Gateway Vulnerability Exploited in the Wild
CVE-2026-85706:Critical GitLab Path Traversal Exploited in the Wild
CVE-2026-83548:Critical SonicWall SMA1000 Vulnerabilities CVE-2026-83548, CVE-2026-83549 Exploited in the Wild
CVE-2026-81578:PaperCut NG/MF Critical Zero-Day Exploited in the Wild
CVE-2026-63520:Rapid7 Analysis: Microsoft SharePoint Remote Code Execution (CVE-2026-63520)
CVE-2026-19490:Critical Vulnerability Affecting Citrix NetScaler ADC and NetScaler Gateway
TitleEitWModules
CVE-2025-9067: Improper Privilege Management7.8 High8.5 High0%Oct 14, 2025
CVE-2025-11719: Use After Free9.8 CriticalN/A0%Oct 14, 2025
CVE-2025-61871: Unquoted Search Path or Element6.7 Medium8.4 High0%Oct 10, 2025
CVE-2025-32919: Uncontrolled Search Path Element7.8 High8.8 High0%Oct 9, 2025
CVE-2025-11535: Incorrect Default PermissionsN/A8.8 High0%Oct 8, 2025
CVE-2017-20201: Embedded Malicious CodeN/A9.3 Critical0%Oct 8, 2025
CVE-2025-42706: Origin Validation Error6.5 MediumN/A0%Oct 8, 2025
CVE-2025-42701: Time-of-check Time-of-use (TOCTOU) Race Condition5.6 MediumN/A0%Oct 8, 2025
CVE-2025-61787: Improper Neutralization of Special Elements used in a Command8.1 HighN/A2%Oct 8, 2025
CVE-2025-62187: Relative Path Traversal2.9 LowN/A0%Oct 7, 2025
CVE-2025-62186: Inclusion of Functionality from Untrusted Control Sphere6.7 MediumN/A0%Oct 7, 2025
CVE-2025-10363: Deserialization of Untrusted DataN/A10.0 Critical1%Oct 6, 2025
CVE-2025-61666: Improper Limitation of a Pathname to a Restricted DirectoryN/A8.7 High1%Oct 2, 2025
CVE-2025-23355: Uncontrolled Search Path Element6.7 MediumN/A0%Oct 1, 2025
CVE-2025-23297: Incorrect Default Permissions7.8 HighN/A0%Oct 1, 2025
CVE-2025-41421: Improper Link Resolution Before File Access4.7 MediumN/A0%Oct 1, 2025
CVE-2025-34235: Improper Certificate Validation7.8 High9.5 Critical0%Sep 29, 2025
CVE-2025-34196: Use of Hard-coded Credentials9.8 Critical9.3 Critical0%Sep 29, 2025
CVE-2025-41246: Incorrect Authorization7.6 HighN/A0%Sep 29, 2025
CVE-2025-59938: Heap-based Buffer Overflow6.5 MediumN/A0%Sep 27, 2025
CVE-2025-59844: Improper Neutralization of Special Elements used in an OS CommandN/A7.7 High1%Sep 26, 2025
CVE-2025-9267: Uncontrolled Search Path ElementN/A7.0 High0%Sep 26, 2025
CVE-2025-54081: Unquoted Search Path or Element6.7 MediumN/A0%Sep 23, 2025
CVE-2025-9844: Uncontrolled Search Path Element8.8 HighN/A0%Sep 23, 2025
CVE-2025-36064: Improper Restriction of Excessive Authentication Attempts5.9 MediumN/A1%Sep 22, 2025
3076-3100 of 16003