The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
CVE-2026-76461:Critical Cisco Secure Email Gateway Vulnerability Exploited in the Wild
CVE-2026-85706:Critical GitLab Path Traversal Exploited in the Wild
CVE-2026-83548:Critical SonicWall SMA1000 Vulnerabilities CVE-2026-83548, CVE-2026-83549 Exploited in the Wild
CVE-2026-81578:PaperCut NG/MF Critical Zero-Day Exploited in the Wild
CVE-2026-63520:Rapid7 Analysis: Microsoft SharePoint Remote Code Execution (CVE-2026-63520)
CVE-2026-19490:Critical Vulnerability Affecting Citrix NetScaler ADC and NetScaler Gateway
TitleEitWModules
CVE-2025-21413: Heap-based Buffer Overflow8.8 HighN/A1%Jan 14, 2025
CVE-2025-21411: Heap-based Buffer Overflow8.8 HighN/A1%Jan 14, 2025
CVE-2024-50564: Use of Hard-coded Cryptographic Key3.3 LowN/A0%Jan 14, 2025
CVE-2025-0069: Uncontrolled Search Path Element7.8 HighN/A0%Jan 14, 2025
CVE-2025-0055: Exposure of Sensitive System Information to an Unauthorized Control Sphere6.0 MediumN/A0%Jan 14, 2025
CVE-2025-22134: Heap-based Buffer Overflow5.5 MediumN/A0%Jan 13, 2025
CVE-2024-40679: Insertion of Sensitive Information into Log File5.5 MediumN/A0%Jan 8, 2025
CVE-2024-9950: Creation of Temporary File in Directory with Insecure Permissions7.8 High8.5 High0%Jan 2, 2025
CVE-2024-12746: Improper Neutralization of Special Elements used in an SQL Command8.0 High8.6 High0%Dec 24, 2024
CVE-2024-12902: Use of Default Credentials8.4 HighN/A0%Dec 23, 2024
CVE-2024-38864: Incorrect Permission Assignment for Critical Resource3.3 Low4.8 Medium0%Dec 19, 2024
CVE-2024-4230: External Control of File Name or Path7.8 HighN/A0%Dec 19, 2024
CVE-2024-4229: Incorrect Default Permissions7.8 HighN/A0%Dec 19, 2024
CVE-2023-30443: Allocation of Resources Without Limits or Throttling5.3 MediumN/A0%Dec 19, 2024
CVE-2022-27595: Uncontrolled Search Path Element7.8 HighN/A0%Dec 19, 2024
CVE-2022-40733: NULL Pointer Dereference5.0 MediumN/A1%Dec 18, 2024
CVE-2022-40732: NULL Pointer Dereference5.0 MediumN/A1%Dec 18, 2024
CVE-2024-50570: Cleartext Storage of Sensitive Information5.0 MediumN/A0%Dec 18, 2024
CVE-2024-52065: Buffer Copy without Checking Size of Input7.1 High6.9 Medium0%Dec 13, 2024
CVE-2024-49071: Improper Authorization of Index Containing Sensitive Information6.5 MediumN/A1%Dec 12, 2024
CVE-2024-12363: Incorrect Permission Assignment for Critical Resource7.1 HighN/A0%Dec 11, 2024
CVE-2024-49105: Improper Access Control8.4 HighN/A2%Dec 10, 2024
CVE-2024-49138: Heap-based Buffer Overflow7.8 HighN/A26%Dec 10, 2024
CVE-2024-49128: Sensitive Data Storage in Improperly Locked Memory8.1 HighN/A1%Dec 10, 2024
CVE-2024-49127: Use After Free8.1 HighN/A1%Dec 10, 2024
4001-4025 of 15999