The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
CVE-2026-76461:Critical Cisco Secure Email Gateway Vulnerability Exploited in the Wild
CVE-2026-85706:Critical GitLab Path Traversal Exploited in the Wild
CVE-2026-83548:Critical SonicWall SMA1000 Vulnerabilities CVE-2026-83548, CVE-2026-83549 Exploited in the Wild
CVE-2026-81578:PaperCut NG/MF Critical Zero-Day Exploited in the Wild
CVE-2026-63520:Rapid7 Analysis: Microsoft SharePoint Remote Code Execution (CVE-2026-63520)
CVE-2026-19490:Critical Vulnerability Affecting Citrix NetScaler ADC and NetScaler Gateway
TitleEitWModules
CVE-2026-33724: Authorization Bypass Through User-Controlled Key7.4 High6.3 Medium0%Mar 25, 2026
CVE-2026-20083: Improper Handling of Extra Parameters6.5 MediumN/A0%Mar 25, 2026
CVE-2026-4433: Undefined Security Weakness4.3 Medium1.9 Low0%Mar 24, 2026
CVE-2026-33353: Exposure of Sensitive Information to an Unauthorized Actor6.5 Medium7.1 High0%Mar 24, 2026
CVE-2026-30932: Improper Neutralization of Special Elements in Output Used by a Downstream Component8.8 High8.6 High1%Mar 24, 2026
CVE-2026-24516: Improper Control of Generation of Code8.8 HighN/A3%Mar 23, 2026
CVE-2019-25607: Out-of-bounds Write8.4 High8.6 High0%Mar 22, 2026
CVE-2019-25590: Assumed-Immutable Data is Stored in Writable Memory6.2 Medium6.9 Medium0%Mar 22, 2026
CVE-2026-4115: Improper Verification of Cryptographic Signature3.7 Low2.9 Low1%Mar 22, 2026
CVE-2026-4541: Improper Verification of Cryptographic Signature2.5 Low1.1 Low0%Mar 22, 2026
CVE-2026-3554: Improper Neutralization of Input During Web Page Generation6.4 MediumN/A0%Mar 21, 2026
CVE-2026-32733: Improper Limitation of a Pathname to a Restricted Directory6.5 Medium8.7 High0%Mar 20, 2026
CVE-2026-32771: Improper Limitation of a Pathname to a Restricted Directory9.8 Critical8.8 High1%Mar 20, 2026
CVE-2026-22321: Stack-based Buffer Overflow5.3 MediumN/A0%Mar 18, 2026
CVE-2026-22320: Stack-based Buffer Overflow6.5 MediumN/A0%Mar 18, 2026
CVE-2026-28500: Insufficient Verification of Data Authenticity9.1 CriticalN/A0%Mar 18, 2026
CVE-2026-23759: Improper Neutralization of Special Elements used in an OS Command7.2 High8.6 High2%Mar 17, 2026
CVE-2026-23943: Improper Handling of Highly Compressed Data (Data Amplification)5.3 Medium6.9 Medium1%Mar 13, 2026
CVE-2026-23942: Improper Limitation of a Pathname to a Restricted Directory5.4 Medium5.3 Medium0%Mar 13, 2026
CVE-2026-3497: Use of Uninitialized ResourceN/A6.9 Medium2%Mar 12, 2026
CVE-2026-32116: Improper Limitation of a Pathname to a Restricted Directory8.1 High8.2 High0%Mar 12, 2026
CVE-2026-21670: Insufficiently Protected Credentials7.7 HighN/A0%Mar 12, 2026
CVE-2025-67035: Improper Neutralization of Special Elements used in an OS Command7.2 High8.6 High0%Mar 11, 2026
CVE-2026-22628: Improper Access Control5.3 MediumN/A0%Mar 10, 2026
CVE-2026-26148: External Initialization of Trusted Variables or Data Stores8.1 HighN/A0%Mar 10, 2026
401-425 of 1961