The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
CVE-2026-94127:Critical Unauthenticated RCE in F5 BIG-IP APM
CVE-2026-76461:Critical Cisco Secure Email Gateway Vulnerability Exploited in the Wild
CVE-2026-85706:Critical GitLab Path Traversal Exploited in the Wild
CVE-2026-83548:Critical SonicWall SMA1000 Vulnerabilities CVE-2026-83548, CVE-2026-83549 Exploited in the Wild
CVE-2026-81578:PaperCut NG/MF Critical Zero-Day Exploited in the Wild
CVE-2026-63520:Rapid7 Analysis: Microsoft SharePoint Remote Code Execution (CVE-2026-63520)
TitleEitWModules
CVE-2024-43449: Out-of-bounds Read6.8 MediumN/A1%Nov 12, 2024
CVE-2024-43447: Double Free8.1 HighN/A1%Nov 12, 2024
CVE-2024-38203: Protection Mechanism Failure6.2 MediumN/A1%Nov 12, 2024
CVE-2024-47535: Uncontrolled Resource Consumption5.5 MediumN/A0%Nov 12, 2024
CVE-2024-50592: Time-of-check Time-of-use (TOCTOU) Race Condition7.0 HighN/A0%Nov 8, 2024
CVE-2024-50591: Improper Neutralization of Special Elements used in a Command7.8 HighN/A2%Nov 8, 2024
CVE-2024-50590: Incorrect Default Permissions7.8 HighN/A0%Nov 8, 2024
CVE-2024-8424: Improper Privilege ManagementN/A8.5 High0%Nov 8, 2024
CVE-2024-10668: Unrestricted Upload of File with Dangerous Type7.5 High5.9 Medium0%Nov 7, 2024
CVE-2024-51756: Improper Limitation of a Pathname to a Restricted DirectoryN/A2.3 Low1%Nov 5, 2024
CVE-2024-51745: Improper Handling of Windows Device Names10.0 Critical2.3 Low1%Nov 5, 2024
CVE-2024-51514: Improper Input Validation5.3 MediumN/A0%Nov 5, 2024
CVE-2024-48463: URL Redirection to Untrusted Site6.5 MediumN/A1%Nov 4, 2024
CVE-2024-10228: Incorrect Permission Assignment for Critical Resource3.8 LowN/A0%Oct 29, 2024
CVE-2024-0126: Improper Input Validation8.2 HighN/A0%Oct 26, 2024
CVE-2024-0121: Out-of-bounds Read7.8 HighN/A0%Oct 26, 2024
CVE-2024-0120: Out-of-bounds Read7.8 HighN/A0%Oct 26, 2024
CVE-2024-0119: Out-of-bounds Read7.8 HighN/A0%Oct 26, 2024
CVE-2024-0118: Out-of-bounds Read7.8 HighN/A0%Oct 26, 2024
CVE-2024-0117: Out-of-bounds Read7.8 HighN/A0%Oct 26, 2024
CVE-2024-9949: Initialization of a Resource with an Insecure Default6.1 Medium5.8 Medium0%Oct 23, 2024
CVE-2024-31880: Allocation of Resources Without Limits or Throttling5.3 MediumN/A0%Oct 23, 2024
CVE-2023-6080: Creation of Temporary File in Directory with Insecure Permissions7.8 HighN/A0%Oct 18, 2024
CVE-2024-9858: Incorrect Default Permissions7.8 High5.9 Medium0%Oct 16, 2024
CVE-2024-9965: Undefined Security Weakness8.8 HighN/A0%Oct 15, 2024
4176-4200 of 16011