The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
CVE-2026-76461:Critical Cisco Secure Email Gateway Vulnerability Exploited in the Wild
CVE-2026-85706:Critical GitLab Path Traversal Exploited in the Wild
CVE-2026-83548:Critical SonicWall SMA1000 Vulnerabilities CVE-2026-83548, CVE-2026-83549 Exploited in the Wild
CVE-2026-81578:PaperCut NG/MF Critical Zero-Day Exploited in the Wild
CVE-2026-63520:Rapid7 Analysis: Microsoft SharePoint Remote Code Execution (CVE-2026-63520)
CVE-2026-19490:Critical Vulnerability Affecting Citrix NetScaler ADC and NetScaler Gateway
TitleEitWModules
CVE-2024-32044: Improper Access Control6.8 Medium5.4 Medium0%Nov 13, 2024
CVE-2024-28952: Uncontrolled Search Path Element6.7 Medium5.4 Medium0%Nov 13, 2024
CVE-2024-28950: Uncontrolled Search Path Element6.7 Medium5.4 Medium0%Nov 13, 2024
CVE-2024-25647: Incorrect Default Permissions6.7 Medium5.4 Medium0%Nov 13, 2024
CVE-2024-24984: Improper Input Validation6.5 Medium6.8 Medium0%Nov 13, 2024
CVE-2024-23312: Uncontrolled Search Path Element6.7 Medium5.4 Medium0%Nov 13, 2024
CVE-2024-47574: Authentication Bypass Using an Alternate Path or Channel7.8 HighN/A0%Nov 13, 2024
CVE-2024-11114: Undefined Security Weakness8.3 HighN/A0%Nov 12, 2024
CVE-2024-11112: Use After Free8.8 HighN/A0%Nov 12, 2024
CVE-2024-36513: Privilege Context Switching Error8.2 HighN/A0%Nov 12, 2024
CVE-2024-36507: Untrusted Search Path7.3 HighN/A0%Nov 12, 2024
CVE-2024-8068: Improper Privilege Management8.0 High5.1 Medium1%Nov 12, 2024
CVE-2024-49046: Time-of-check Time-of-use (TOCTOU) Race Condition7.8 HighN/A0%Nov 12, 2024
CVE-2024-49039: Improper Authentication8.8 HighN/A14%Nov 12, 2024
CVE-2024-43646: Untrusted Pointer Dereference6.7 MediumN/A1%Nov 12, 2024
CVE-2024-43645: Protection Mechanism Failure6.7 MediumN/A1%Nov 12, 2024
CVE-2024-43644: Out-of-bounds Read7.8 HighN/A1%Nov 12, 2024
CVE-2024-43643: Out-of-bounds Read6.8 MediumN/A1%Nov 12, 2024
CVE-2024-43642: Use After Free7.5 HighN/A63%Nov 12, 2024
CVE-2024-43641: Integer Overflow or Wraparound7.8 HighN/A1%Nov 12, 2024
CVE-2024-43640: Double Free7.8 HighN/A1%Nov 12, 2024
CVE-2024-43639: Numeric Truncation Error9.8 CriticalN/A9%Nov 12, 2024
CVE-2024-43638: Out-of-bounds Read6.8 MediumN/A1%Nov 12, 2024
CVE-2024-43637: Out-of-bounds Read6.8 MediumN/A1%Nov 12, 2024
CVE-2024-43635: Integer Overflow or Wraparound8.8 HighN/A2%Nov 12, 2024
4126-4150 of 16003