The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
CVE-2026-76461:Critical Cisco Secure Email Gateway Vulnerability Exploited in the Wild
CVE-2026-85706:Critical GitLab Path Traversal Exploited in the Wild
CVE-2026-83548:Critical SonicWall SMA1000 Vulnerabilities CVE-2026-83548, CVE-2026-83549 Exploited in the Wild
CVE-2026-81578:PaperCut NG/MF Critical Zero-Day Exploited in the Wild
CVE-2026-63520:Rapid7 Analysis: Microsoft SharePoint Remote Code Execution (CVE-2026-63520)
CVE-2026-19490:Critical Vulnerability Affecting Citrix NetScaler ADC and NetScaler Gateway
TitleEitWModules
CVE-2026-80217: Hidden Functionality8.8 High8.7 High0%Sep 15, 2026
CVE-2024-58383: Incorrect Permission Assignment for Critical Resource7.3 High8.4 High0%Sep 14, 2026
CVE-2026-90623: Improper Certificate Validation3.7 Low2.9 Low0%Sep 14, 2026
CVE-2026-90621: Improper Neutralization of Special Elements used in an OS Command6.3 Medium2.1 Low1%Sep 14, 2026
CVE-2026-90767: Improper Neutralization of CRLF Sequences6.5 Medium7.1 High0%Sep 13, 2026
CVE-2026-38058: Exposure of Sensitive System Information to an Unauthorized Control Sphere8.1 High8.6 High0%Sep 11, 2026
CVE-2026-77120: Improper Neutralization of Special Elements used in an OS CommandN/A8.7 High0%Sep 9, 2026
CVE-2026-78635: Improper Neutralization of Argument Delimiters in a Command5.0 MediumN/A0%Sep 8, 2026
CVE-2026-78550: Improper Neutralization of Directives in Dynamically Evaluated Code6.6 MediumN/A0%Sep 8, 2026
CVE-2026-82533: Reliance on Untrusted Inputs in a Security Decision9.6 Critical9.4 Critical1%Sep 8, 2026
CVE-2026-69397: Use After Free7.5 HighN/A1%Sep 8, 2026
CVE-2026-86541: Improper Limitation of a Pathname to a Restricted Directory8.3 High7.2 High1%Sep 7, 2026
CVE-2026-80238: Execution with Unnecessary Privileges9.3 CriticalN/A0%Sep 7, 2026
CVE-2026-86060: Improper Neutralization of Argument Delimiters in a Command9.8 Critical9.2 Critical1%Sep 5, 2026
CVE-2026-67279: Improper Enforcement of Behavioral WorkflowN/A6.9 Medium0%Sep 5, 2026
CVE-2026-67278: Improper Verification of Cryptographic SignatureN/A6.3 Medium0%Sep 5, 2026
CVE-2026-67276: Improper Verification of Cryptographic SignatureN/A9.2 Critical0%Sep 5, 2026
CVE-2026-18858: Privilege Defined With Unsafe Actions5.5 MediumN/A0%Sep 4, 2026
CVE-2026-85146: Use of Hard-coded Credentials9.8 Critical9.3 Critical0%Sep 4, 2026
CVE-2026-75754: Missing Authentication for Critical FunctionN/A10.0 Critical0%Sep 4, 2026
CVE-2026-85394: Improper Verification of Cryptographic Signature9.1 Critical9.3 Critical0%Sep 3, 2026
CVE-2026-78662: Allocation of Resources Without Limits or Throttling7.5 HighN/A0%Sep 2, 2026
CVE-2026-56855: Allocation of Resources Without Limits or Throttling7.5 HighN/A0%Sep 2, 2026
CVE-2026-53611: Improper Neutralization of Special Elements used in an OS Command9.8 CriticalN/A1%Sep 2, 2026
CVE-2026-84694: Improper Neutralization of Special Elements used in an OS Command8.8 High8.7 High0%Sep 2, 2026
26-50 of 1969