The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
CVE-2026-63520:Rapid7 Analysis: Microsoft SharePoint Remote Code Execution (CVE-2026-63520)
CVE-2026-19490:Critical Vulnerability Affecting Citrix NetScaler ADC and NetScaler Gateway
CVE-2026-63520:Microsoft SharePoint Remote Code Execution (FIXED)
CVE-2026-55040:Rapid7 Analysis: Microsoft SharePoint JWT Token Authentication Bypass (CVE-2026-55040)
CVE-2026-63077:Rapid7 Analysis: Unauthenticated Remote Code Execution in JetBrains TeamCity (CVE-2026-63077)
CVE-2026-18577:N-able N-central Authentication Bypass Exploited in the Wild
TitleEitWModules
CVE-2019-25742: Improper Neutralization of Input During Web Page Generation5.4 Medium5.1 Medium0%Jun 4, 2026
CVE-2019-25740: Improper Limitation of a Pathname to a Restricted Directory6.5 Medium7.1 High0%Jun 4, 2026
CVE-2019-25739: Improper Neutralization of Input During Web Page Generation5.4 Medium5.1 Medium0%Jun 4, 2026
CVE-2019-25737: Improper Neutralization of Input During Web Page Generation6.1 Medium5.3 Medium0%Jun 4, 2026
CVE-2019-25736: Buffer Copy without Checking Size of Input8.4 High8.6 High0%Jun 4, 2026
CVE-2019-25735: Buffer Copy without Checking Size of Input8.4 High8.6 High0%Jun 4, 2026
CVE-2019-25734: Improper Limitation of a Pathname to a Restricted Directory4.0 Medium5.1 Medium1%Jun 4, 2026
CVE-2019-25733: Buffer Copy without Checking Size of Input8.4 High8.6 High0%Jun 4, 2026
CVE-2019-25732: Improper Neutralization of Special Elements used in an SQL Command8.2 High8.8 High0%Jun 4, 2026
CVE-2019-25731: Improper Neutralization of Input During Web Page Generation6.1 Medium5.3 Medium0%Jun 4, 2026
CVE-2019-25730: Improper Neutralization of Special Elements used in an SQL Command8.2 High8.8 High0%Jun 4, 2026
CVE-2019-25729: Cross-Site Request Forgery (CSRF)9.8 Critical9.3 Critical0%Jun 4, 2026
CVE-2019-25728: Improper Neutralization of Special Elements used in an SQL Command8.2 High8.8 High0%Jun 4, 2026
CVE-2019-25727: Improper Limitation of a Pathname to a Restricted Directory9.8 Critical9.3 Critical0%Jun 4, 2026
CVE-2019-25726: Improper Neutralization of Special Elements used in an SQL Command8.2 High8.8 High0%Jun 4, 2026
CVE-2019-25745: Improper Neutralization of Special Elements used in an SQL Command8.2 High8.8 High0%Jun 4, 2026
CVE-2019-25741: Buffer Copy without Checking Size of Input9.8 Critical9.3 Critical1%Jun 4, 2026
CVE-2019-25738: Missing Authentication for Critical Function9.8 Critical9.3 Critical0%Jun 4, 2026
CVE-2019-25720: Improper Validation of Syntactic Correctness of Input6.5 Medium7.1 High0%Jun 3, 2026
CVE-2019-25724: Uncontrolled Resource Consumption6.5 Medium7.1 High0%Jun 2, 2026
CVE-2019-25723: Improper Validation of Syntactic Correctness of Input4.0 Medium6.3 Medium0%Jun 2, 2026
CVE-2019-25722: Use of Hard-coded Credentials7.6 High7.2 High0%Jun 2, 2026
CVE-2019-25721: Uncontrolled Resource Consumption6.5 Medium7.1 High0%Jun 2, 2026
CVE-2019-25719: Improper Enforcement of Message Integrity During Transmission in a Communication Channel8.6 High8.8 High0%Jun 2, 2026
CVE-2019-25717: Insertion of Sensitive Information into Externally-Accessible File or Directory4.3 Medium5.3 Medium0%Jun 2, 2026
26-50 of 17623