The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
CVE-2026-76461:Critical Cisco Secure Email Gateway Vulnerability Exploited in the Wild
CVE-2026-85706:Critical GitLab Path Traversal Exploited in the Wild
CVE-2026-83548:Critical SonicWall SMA1000 Vulnerabilities CVE-2026-83548, CVE-2026-83549 Exploited in the Wild
CVE-2026-81578:PaperCut NG/MF Critical Zero-Day Exploited in the Wild
CVE-2026-63520:Rapid7 Analysis: Microsoft SharePoint Remote Code Execution (CVE-2026-63520)
CVE-2026-19490:Critical Vulnerability Affecting Citrix NetScaler ADC and NetScaler Gateway
TitleEitWModules
CVE-2024-13944: Time-of-check Time-of-use (TOCTOU) Race Condition7.8 HighN/A0%May 9, 2025
CVE-2024-13759: Improper Link Resolution Before File Access7.8 HighN/A0%May 9, 2025
CVE-2025-26169: Incorrect Permission Assignment for Critical Resource8.1 HighN/A0%May 7, 2025
CVE-2025-46735: Improper Neutralization of Special Elements used in a CommandN/A1.1 Low1%May 6, 2025
CVE-2025-1493: Concurrent Execution using Shared Resource with Improper Synchronization5.3 MediumN/A0%May 5, 2025
CVE-2025-1000: Allocation of Resources Without Limits or Throttling5.3 MediumN/A0%May 5, 2025
CVE-2025-0915: Allocation of Resources Without Limits or Throttling5.3 MediumN/A0%May 5, 2025
CVE-2025-46335: Improper Neutralization of Input During Web Page Generation5.4 Medium8.6 High0%May 5, 2025
CVE-2025-1992: Missing Release of Memory after Effective Lifetime5.3 MediumN/A0%May 5, 2025
CVE-2024-52903: Uncaught Exception5.3 MediumN/A0%May 1, 2025
CVE-2025-4178: Improper Limitation of a Pathname to a Restricted Directory5.4 Medium5.3 Medium1%May 1, 2025
CVE-2025-23246: Uncontrolled Resource Consumption5.5 MediumN/A0%May 1, 2025
CVE-2025-23245: Incorrect Permission Assignment for Critical Resource5.5 MediumN/A0%May 1, 2025
CVE-2025-46619: Improper Access Control7.6 HighN/A0%Apr 30, 2025
CVE-2025-3599: Time-of-check Time-of-use (TOCTOU) Race Condition6.5 MediumN/A0%Apr 30, 2025
CVE-2025-3224: Improper Privilege Management7.8 High7.3 High0%Apr 28, 2025
CVE-2025-42598: Incorrect Default Permissions7.8 High8.4 High0%Apr 28, 2025
CVE-2025-31144: Improper Restriction of Communication Channel to Intended Endpoints5.8 Medium6.9 Medium0%Apr 28, 2025
CVE-2025-26692: Improper Limitation of a Pathname to a Restricted Directory8.1 High9.2 Critical1%Apr 28, 2025
CVE-2025-3928: Undefined Security Weakness8.8 High8.7 High2%Apr 25, 2025
CVE-2025-43858: Improper Neutralization of Special Elements used in a Command9.2 CriticalN/A0%Apr 24, 2025
CVE-2025-23253: Use of Hard-coded, Security-relevant Constants2.5 LowN/A0%Apr 22, 2025
CVE-2024-40445: Improper Neutralization of Special Elements used in a Command7.3 HighN/A1%Apr 22, 2025
CVE-2024-57394: External Control of File Name or Path8.8 HighN/A1%Apr 21, 2025
CVE-2025-43922: Incorrect Authorization8.1 HighN/A0%Apr 21, 2025
3576-3600 of 16000