The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
CVE-2026-76461:Critical Cisco Secure Email Gateway Vulnerability Exploited in the Wild
CVE-2026-85706:Critical GitLab Path Traversal Exploited in the Wild
CVE-2026-83548:Critical SonicWall SMA1000 Vulnerabilities CVE-2026-83548, CVE-2026-83549 Exploited in the Wild
CVE-2026-81578:PaperCut NG/MF Critical Zero-Day Exploited in the Wild
CVE-2026-63520:Rapid7 Analysis: Microsoft SharePoint Remote Code Execution (CVE-2026-63520)
CVE-2026-19490:Critical Vulnerability Affecting Citrix NetScaler ADC and NetScaler Gateway
TitleEitWModules
CVE-2025-26679: Use After Free7.8 HighN/A1%Apr 8, 2025
CVE-2025-26678: Improper Access Control8.4 HighN/A1%Apr 8, 2025
CVE-2025-26676: Buffer Over-read6.5 MediumN/A2%Apr 8, 2025
CVE-2025-26675: Out-of-bounds Read7.8 HighN/A1%Apr 8, 2025
CVE-2025-26673: Uncontrolled Resource Consumption7.5 HighN/A3%Apr 8, 2025
CVE-2025-26672: Buffer Over-read6.5 MediumN/A2%Apr 8, 2025
CVE-2025-26674: Heap-based Buffer Overflow7.8 HighN/A1%Apr 8, 2025
CVE-2025-26671: Use After Free8.1 HighN/A1%Apr 8, 2025
CVE-2025-26670: Use After Free8.1 HighN/A11%Apr 8, 2025
CVE-2025-26652: Uncontrolled Resource Consumption7.5 HighN/A2%Apr 8, 2025
CVE-2025-26651: Exposed Dangerous Method or Function6.5 MediumN/A3%Apr 8, 2025
CVE-2025-26647: Improper Input Validation8.8 HighN/A2%Apr 8, 2025
CVE-2025-26649: Concurrent Execution using Shared Resource with Improper Synchronization7.0 HighN/A0%Apr 8, 2025
CVE-2025-26648: Sensitive Data Storage in Improperly Locked Memory7.8 HighN/A0%Apr 8, 2025
CVE-2025-26644: Automated Recognition Mechanism with Inadequate Detection or Handling of Adversarial Input Perturbations5.1 MediumN/A1%Apr 8, 2025
CVE-2025-26641: Uncontrolled Resource Consumption7.5 HighN/A2%Apr 8, 2025
CVE-2025-26640: Use After Free7.0 HighN/A0%Apr 8, 2025
CVE-2025-26637: Protection Mechanism Failure6.8 MediumN/A1%Apr 8, 2025
CVE-2025-26635: Weak Authentication6.5 MediumN/A1%Apr 8, 2025
CVE-2025-26639: Integer Overflow or Wraparound7.8 HighN/A1%Apr 8, 2025
CVE-2025-24058: Improper Input Validation7.8 HighN/A1%Apr 8, 2025
CVE-2025-21222: Heap-based Buffer Overflow8.8 HighN/A1%Apr 8, 2025
CVE-2025-21221: Heap-based Buffer Overflow8.8 HighN/A1%Apr 8, 2025
CVE-2025-21204: Improper Link Resolution Before File Access7.8 HighN/A7%Apr 8, 2025
CVE-2025-21203: Buffer Over-read6.5 MediumN/A2%Apr 8, 2025
3651-3675 of 15999