The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
CVE-2026-76461:Critical Cisco Secure Email Gateway Vulnerability Exploited in the Wild
CVE-2026-85706:Critical GitLab Path Traversal Exploited in the Wild
CVE-2026-83548:Critical SonicWall SMA1000 Vulnerabilities CVE-2026-83548, CVE-2026-83549 Exploited in the Wild
CVE-2026-81578:PaperCut NG/MF Critical Zero-Day Exploited in the Wild
CVE-2026-63520:Rapid7 Analysis: Microsoft SharePoint Remote Code Execution (CVE-2026-63520)
CVE-2026-19490:Critical Vulnerability Affecting Citrix NetScaler ADC and NetScaler Gateway
TitleEitWModules
CVE-2025-54569: Incorrect Authorization4.5 MediumN/A0%Jul 28, 2025
CVE-2025-4056: Improper Control of Generation of Code7.5 HighN/A0%Jul 28, 2025
CVE-2025-6241: Undefined Security Weakness4.4 MediumN/A0%Jul 27, 2025
CVE-2024-13976: Uncontrolled Search Path ElementN/A8.5 High0%Jul 25, 2025
CVE-2024-13975: Improper Privilege ManagementN/A8.5 High0%Jul 25, 2025
CVE-2025-40680: Missing Encryption of Sensitive DataN/A6.9 Medium0%Jul 24, 2025
CVE-2025-8069: Incorrect Default Permissions7.8 High7.3 High0%Jul 23, 2025
CVE-2010-10012: Improper Limitation of a Pathname to a Restricted DirectoryN/A8.7 High2%Jul 23, 2025
CVE-2024-12310: Improper AuthenticationN/A7.0 High0%Jul 23, 2025
CVE-2025-8070: Unquoted Search Path or ElementN/A9.2 Critical0%Jul 23, 2025
CVE-2025-54072: Improper Neutralization of Special Elements used in an OS Command7.5 HighN/A1%Jul 22, 2025
CVE-2025-27210: Improper Limitation of a Pathname to a Restricted Directory7.5 HighN/A15%Jul 18, 2025
CVE-2025-7433: Deserialization of Untrusted Data8.8 HighN/A0%Jul 17, 2025
CVE-2025-7472: Uncontrolled Search Path Element7.5 HighN/A0%Jul 17, 2025
CVE-2024-13972: Incorrect Default Permissions8.8 HighN/A0%Jul 17, 2025
CVE-2025-34105: Improper Input ValidationN/A10.0 Critical1%Jul 15, 2025
CVE-2025-34106: Improper Restriction of Operations within the Bounds of a Memory BufferN/A8.4 High0%Jul 15, 2025
CVE-2025-34110: Improper Limitation of a Pathname to a Restricted DirectoryN/A9.3 Critical2%Jul 15, 2025
CVE-2025-27582: Inclusion of Functionality from Untrusted Control Sphere7.6 HighN/A0%Jul 14, 2025
CVE-2025-7619: Relative Path Traversal8.8 High8.7 High1%Jul 14, 2025
CVE-2025-5028: Improper Privilege ManagementN/A6.8 Medium0%Jul 11, 2025
CVE-2025-34095: Improper Neutralization of Special Elements used in an OS CommandN/A9.3 Critical6%Jul 10, 2025
CVE-2025-49464: Buffer Copy without Checking Size of Input6.5 MediumN/A1%Jul 10, 2025
CVE-2024-43394: Server-Side Request Forgery (SSRF)7.5 HighN/A1%Jul 10, 2025
CVE-2025-46789: Buffer Copy without Checking Size of Input6.5 MediumN/A0%Jul 10, 2025
3326-3350 of 16003