The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
CVE-2026-76461:Critical Cisco Secure Email Gateway Vulnerability Exploited in the Wild
CVE-2026-85706:Critical GitLab Path Traversal Exploited in the Wild
CVE-2026-83548:Critical SonicWall SMA1000 Vulnerabilities CVE-2026-83548, CVE-2026-83549 Exploited in the Wild
CVE-2026-81578:PaperCut NG/MF Critical Zero-Day Exploited in the Wild
CVE-2026-63520:Rapid7 Analysis: Microsoft SharePoint Remote Code Execution (CVE-2026-63520)
CVE-2026-19490:Critical Vulnerability Affecting Citrix NetScaler ADC and NetScaler Gateway
TitleEitWModules
CVE-2025-49676: Heap-based Buffer Overflow8.8 HighN/A1%Jul 8, 2025
CVE-2025-49674: Heap-based Buffer Overflow8.8 HighN/A1%Jul 8, 2025
CVE-2025-49673: Heap-based Buffer Overflow8.8 HighN/A1%Jul 8, 2025
CVE-2025-49672: Heap-based Buffer Overflow8.8 HighN/A1%Jul 8, 2025
CVE-2025-49671: Exposure of Sensitive Information to an Unauthorized Actor6.5 MediumN/A1%Jul 8, 2025
CVE-2025-49670: Heap-based Buffer Overflow6.5 MediumN/A1%Jul 8, 2025
CVE-2025-49669: Heap-based Buffer Overflow8.8 HighN/A1%Jul 8, 2025
CVE-2025-49668: Heap-based Buffer Overflow8.8 HighN/A1%Jul 8, 2025
CVE-2025-49667: Double Free7.8 HighN/A0%Jul 8, 2025
CVE-2025-49666: Heap-based Buffer Overflow7.2 HighN/A1%Jul 8, 2025
CVE-2025-49664: Exposure of Sensitive Information to an Unauthorized Actor5.5 MediumN/A1%Jul 8, 2025
CVE-2025-49663: Heap-based Buffer Overflow8.8 HighN/A1%Jul 8, 2025
CVE-2025-49661: Untrusted Pointer Dereference7.8 HighN/A0%Jul 8, 2025
CVE-2025-49660: Use After Free7.8 HighN/A0%Jul 8, 2025
CVE-2025-49659: Buffer Over-read7.8 HighN/A0%Jul 8, 2025
CVE-2025-49658: Out-of-bounds Read5.5 MediumN/A0%Jul 8, 2025
CVE-2025-49657: Heap-based Buffer Overflow8.8 HighN/A1%Jul 8, 2025
CVE-2025-48824: Heap-based Buffer Overflow8.8 HighN/A1%Jul 8, 2025
CVE-2025-48823: Inadequate Encryption Strength5.9 MediumN/A1%Jul 8, 2025
CVE-2025-48822: Out-of-bounds Read8.6 HighN/A1%Jul 8, 2025
CVE-2025-48821: Use After Free7.1 HighN/A0%Jul 8, 2025
CVE-2025-48820: Improper Link Resolution Before File Access7.8 HighN/A0%Jul 8, 2025
CVE-2025-48819: Sensitive Data Storage in Improperly Locked Memory7.1 HighN/A0%Jul 8, 2025
CVE-2025-48818: Time-of-check Time-of-use (TOCTOU) Race Condition6.8 MediumN/A0%Jul 8, 2025
CVE-2025-48815: Access of Resource Using Incompatible Type7.8 HighN/A0%Jul 8, 2025
3376-3400 of 16003