The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
CVE-2026-76461:Critical Cisco Secure Email Gateway Vulnerability Exploited in the Wild
CVE-2026-85706:Critical GitLab Path Traversal Exploited in the Wild
CVE-2026-83548:Critical SonicWall SMA1000 Vulnerabilities CVE-2026-83548, CVE-2026-83549 Exploited in the Wild
CVE-2026-81578:PaperCut NG/MF Critical Zero-Day Exploited in the Wild
CVE-2026-63520:Rapid7 Analysis: Microsoft SharePoint Remote Code Execution (CVE-2026-63520)
CVE-2026-19490:Critical Vulnerability Affecting Citrix NetScaler ADC and NetScaler Gateway
TitleEitWModules
CVE-2024-0131: Buffer Access with Incorrect Length Value4.4 MediumN/A0%Feb 2, 2025
CVE-2025-0145: Untrusted Search Path4.6 MediumN/A0%Jan 30, 2025
CVE-2025-23007: Improper Privilege Management5.5 MediumN/A0%Jan 30, 2025
CVE-2025-24479: Incorrect AuthorizationN/A8.6 High0%Jan 28, 2025
CVE-2025-0065: Improper Neutralization of Argument Delimiters in a Command7.8 HighN/A1%Jan 28, 2025
CVE-2025-23084: Improper Limitation of a Pathname to a Restricted Directory5.5 MediumN/A2%Jan 28, 2025
CVE-2024-0150: Out-of-bounds Write7.1 HighN/A0%Jan 28, 2025
CVE-2024-0147: Use After Free5.5 MediumN/A0%Jan 28, 2025
CVE-2024-52012: Relative Path Traversal5.4 MediumN/A45%Jan 27, 2025
CVE-2024-45077: Improper Control of Filename for Include/Require Statement in PHP Program6.5 MediumN/A0%Jan 24, 2025
CVE-2024-9495: Uncontrolled Search Path Element8.6 HighN/A0%Jan 24, 2025
CVE-2025-0651: Improper Privilege Management7.1 High6.1 Medium0%Jan 22, 2025
CVE-2024-55957: Incorrect Default Permissions7.8 HighN/A0%Jan 22, 2025
CVE-2024-42013: Incorrect Authorization6.4 MediumN/A0%Jan 22, 2025
CVE-2024-42012: Insufficiently Protected Credentials5.7 MediumN/A0%Jan 22, 2025
CVE-2024-37284: Improper Handling of Exceptional Conditions5.5 MediumN/A0%Jan 21, 2025
CVE-2024-13524: Untrusted Search Path4.5 Medium2.0 Low0%Jan 20, 2025
CVE-2025-21325: Incorrect Permission Assignment for Critical Resource7.8 HighN/A0%Jan 17, 2025
CVE-2024-5198: NULL Pointer Dereference3.3 LowN/A0%Jan 15, 2025
CVE-2025-0440: Authentication Bypass by Spoofing6.5 MediumN/A0%Jan 15, 2025
CVE-2025-23042: Improper Authorization7.5 High8.7 High1%Jan 14, 2025
CVE-2025-21245: Heap-based Buffer Overflow8.8 HighN/A2%Jan 14, 2025
CVE-2025-21409: Heap-based Buffer Overflow8.8 HighN/A1%Jan 14, 2025
CVE-2025-21223: Heap-based Buffer Overflow8.8 HighN/A2%Jan 14, 2025
CVE-2025-21238: Heap-based Buffer Overflow8.8 HighN/A2%Jan 14, 2025
3851-3875 of 15999