The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
CVE-2026-76461:Critical Cisco Secure Email Gateway Vulnerability Exploited in the Wild
CVE-2026-85706:Critical GitLab Path Traversal Exploited in the Wild
CVE-2026-83548:Critical SonicWall SMA1000 Vulnerabilities CVE-2026-83548, CVE-2026-83549 Exploited in the Wild
CVE-2026-81578:PaperCut NG/MF Critical Zero-Day Exploited in the Wild
CVE-2026-63520:Rapid7 Analysis: Microsoft SharePoint Remote Code Execution (CVE-2026-63520)
CVE-2026-19490:Critical Vulnerability Affecting Citrix NetScaler ADC and NetScaler Gateway
TitleEitWModules
CVE-2026-33642: Integer Overflow or Wraparound9.8 CriticalN/A0%May 19, 2026
CVE-2026-25244: Improper Neutralization of Special Elements used in an OS Command9.8 CriticalN/A3%May 18, 2026
CVE-2026-39079: Exposure of Sensitive Information to an Unauthorized Actor7.5 HighN/A0%May 18, 2026
CVE-2026-45037: Incomplete List of Disallowed Inputs7.1 HighN/A0%May 15, 2026
CVE-2026-44426: Authorization Bypass Through User-Controlled Key6.5 MediumN/A0%May 13, 2026
CVE-2026-44425: Improper Input Validation5.4 MediumN/A0%May 13, 2026
CVE-2026-44424: Authorization Bypass Through User-Controlled Key6.5 MediumN/A0%May 13, 2026
CVE-2026-44423: Authorization Bypass Through User-Controlled Key6.5 MediumN/A0%May 13, 2026
CVE-2026-44467: Improper Validation of Certificate with Host Mismatch6.8 Medium7.4 High0%May 13, 2026
CVE-2026-28758: Cleartext Storage of Sensitive Information4.4 Medium6.7 Medium0%May 13, 2026
CVE-2026-44347: Cross-Site Request Forgery (CSRF)6.5 MediumN/A0%May 12, 2026
CVE-2026-44225: Improper Limitation of a Pathname to a Restricted Directory9.3 CriticalN/A1%May 12, 2026
CVE-2026-1185: Incorrect Permission Assignment for Critical Resource8.8 HighN/A0%May 12, 2026
CVE-2026-41489: Incorrect Permission Assignment for Critical Resource8.8 HighN/A0%May 11, 2026
CVE-2026-42454: Improper Neutralization of Special Elements used in an OS Command9.9 CriticalN/A1%May 8, 2026
CVE-2026-42453: Improper Neutralization of Special Elements used in a CommandN/A8.7 High1%May 8, 2026
CVE-2026-42452: Missing Critical Step in Authentication8.1 HighN/A0%May 8, 2026
CVE-2026-42189: Allocation of Resources Without Limits or Throttling7.5 HighN/A0%May 8, 2026
CVE-2026-43944: Improper Input Validation9.6 Critical9.4 Critical0%May 8, 2026
CVE-2026-43943: Improper Neutralization of Special Elements used in an OS Command7.8 HighN/A0%May 8, 2026
CVE-2026-43942: Exposure of Sensitive Information to an Unauthorized Actor5.5 MediumN/A0%May 8, 2026
CVE-2026-43941: Improper Neutralization of Argument Delimiters in a Command9.6 CriticalN/A0%May 8, 2026
CVE-2026-43940: Improper Limitation of a Pathname to a Restricted Directory8.4 HighN/A0%May 8, 2026
CVE-2026-41501: Improper Neutralization of Special Elements used in a Command9.8 CriticalN/A1%May 8, 2026
CVE-2026-41500: Improper Neutralization of Special Elements used in a Command9.8 CriticalN/A2%May 8, 2026
326-350 of 1962