The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
CVE-2026-76461:Critical Cisco Secure Email Gateway Vulnerability Exploited in the Wild
CVE-2026-85706:Critical GitLab Path Traversal Exploited in the Wild
CVE-2026-83548:Critical SonicWall SMA1000 Vulnerabilities CVE-2026-83548, CVE-2026-83549 Exploited in the Wild
CVE-2026-81578:PaperCut NG/MF Critical Zero-Day Exploited in the Wild
CVE-2026-63520:Rapid7 Analysis: Microsoft SharePoint Remote Code Execution (CVE-2026-63520)
CVE-2026-19490:Critical Vulnerability Affecting Citrix NetScaler ADC and NetScaler Gateway
TitleEitWModules
CVE-2024-41166: Stack-based Buffer Overflow6.1 Medium6.0 Medium0%Feb 12, 2025
CVE-2024-40887: Concurrent Execution using Shared Resource with Improper Synchronization6.1 Medium6.0 Medium0%Feb 12, 2025
CVE-2024-39606: Improper Input Validation6.1 Medium6.0 Medium0%Feb 12, 2025
CVE-2024-39372: Uncontrolled Search Path Element6.7 Medium5.4 Medium0%Feb 12, 2025
CVE-2024-39365: Uncontrolled Search Path Element6.7 Medium5.4 Medium0%Feb 12, 2025
CVE-2024-39356: NULL Pointer Dereference7.4 High7.1 High0%Feb 12, 2025
CVE-2024-36285: Concurrent Execution using Shared Resource with Improper Synchronization5.6 Medium5.7 Medium0%Feb 12, 2025
CVE-2024-32942: Incorrect Default Permissions6.7 Medium5.4 Medium0%Feb 12, 2025
CVE-2024-32938: Uncontrolled Search Path Element6.7 Medium5.4 Medium0%Feb 12, 2025
CVE-2025-1146: Improper Following of a Certificate's Chain of Trust8.1 HighN/A0%Feb 12, 2025
CVE-2025-25199: Missing Release of Memory after Effective Lifetime7.5 HighN/A1%Feb 12, 2025
CVE-2025-21420: Improper Link Resolution Before File Access7.8 HighN/A4%Feb 11, 2025
CVE-2025-21419: Improper Link Resolution Before File Access7.1 HighN/A1%Feb 11, 2025
CVE-2025-21418: Heap-based Buffer Overflow7.8 HighN/A2%Feb 11, 2025
CVE-2025-21414: Heap-based Buffer Overflow7.0 HighN/A1%Feb 11, 2025
CVE-2025-21410: Heap-based Buffer Overflow8.8 HighN/A2%Feb 11, 2025
CVE-2025-21407: Heap-based Buffer Overflow8.8 HighN/A2%Feb 11, 2025
CVE-2025-21406: Use After Free8.8 HighN/A2%Feb 11, 2025
CVE-2025-21391: Improper Link Resolution Before File Access7.1 HighN/A2%Feb 11, 2025
CVE-2025-21376: Concurrent Execution using Shared Resource with Improper Synchronization8.1 HighN/A9%Feb 11, 2025
CVE-2025-21373: Improper Link Resolution Before File Access7.8 HighN/A1%Feb 11, 2025
CVE-2025-21371: Heap-based Buffer Overflow8.8 HighN/A2%Feb 11, 2025
CVE-2025-21367: Use After Free7.8 HighN/A1%Feb 11, 2025
CVE-2025-21359: Improper Access Control7.8 HighN/A1%Feb 11, 2025
CVE-2025-21358: Untrusted Pointer Dereference7.8 HighN/A1%Feb 11, 2025
3801-3825 of 15999