The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
CVE-2026-76461:Critical Cisco Secure Email Gateway Vulnerability Exploited in the Wild
CVE-2026-85706:Critical GitLab Path Traversal Exploited in the Wild
CVE-2026-83548:Critical SonicWall SMA1000 Vulnerabilities CVE-2026-83548, CVE-2026-83549 Exploited in the Wild
CVE-2026-81578:PaperCut NG/MF Critical Zero-Day Exploited in the Wild
CVE-2026-63520:Rapid7 Analysis: Microsoft SharePoint Remote Code Execution (CVE-2026-63520)
CVE-2026-19490:Critical Vulnerability Affecting Citrix NetScaler ADC and NetScaler Gateway
TitleEitWModules
CVE-2025-29808: Use of a Cryptographic Primitive with a Risky Implementation5.5 MediumN/A1%Apr 8, 2025
CVE-2025-29809: Insecure Storage of Sensitive Information7.1 HighN/A4%Apr 8, 2025
CVE-2025-27739: Untrusted Pointer Dereference7.8 HighN/A1%Apr 8, 2025
CVE-2025-27738: Improper Access Control6.5 MediumN/A3%Apr 8, 2025
CVE-2025-27737: Improper Input Validation8.6 HighN/A1%Apr 8, 2025
CVE-2025-27736: Exposure of Sensitive Information to an Unauthorized Actor5.5 MediumN/A1%Apr 8, 2025
CVE-2025-27735: Insufficient Verification of Data Authenticity6.0 MediumN/A0%Apr 8, 2025
CVE-2025-27733: Out-of-bounds Read7.8 HighN/A1%Apr 8, 2025
CVE-2025-27732: Sensitive Data Storage in Improperly Locked Memory7.0 HighN/A0%Apr 8, 2025
CVE-2025-27730: Use After Free7.8 HighN/A1%Apr 8, 2025
CVE-2025-27731: Improper Input Validation7.8 HighN/A1%Apr 8, 2025
CVE-2025-27728: Out-of-bounds Read7.8 HighN/A1%Apr 8, 2025
CVE-2025-27729: Use After Free7.8 HighN/A1%Apr 8, 2025
CVE-2025-27727: Improper Link Resolution Before File Access7.8 HighN/A1%Apr 8, 2025
CVE-2025-27490: Heap-based Buffer Overflow7.8 HighN/A1%Apr 8, 2025
CVE-2025-27491: Use After Free7.1 HighN/A2%Apr 8, 2025
CVE-2025-27492: Concurrent Execution using Shared Resource with Improper Synchronization7.0 HighN/A0%Apr 8, 2025
CVE-2025-27486: Uncontrolled Resource Consumption7.5 HighN/A2%Apr 8, 2025
CVE-2025-27487: Heap-based Buffer Overflow8.0 HighN/A1%Apr 8, 2025
CVE-2025-27483: Out-of-bounds Read7.8 HighN/A1%Apr 8, 2025
CVE-2025-27482: Sensitive Data Storage in Improperly Locked Memory8.1 HighN/A2%Apr 8, 2025
CVE-2025-27481: Stack-based Buffer Overflow8.8 HighN/A1%Apr 8, 2025
CVE-2025-27480: Use After Free8.1 HighN/A13%Apr 8, 2025
CVE-2025-27484: Sensitive Data Storage in Improperly Locked Memory7.5 HighN/A1%Apr 8, 2025
CVE-2025-27485: Uncontrolled Resource Consumption7.5 HighN/A2%Apr 8, 2025
3626-3650 of 16000