The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
CVE-2026-76461:Critical Cisco Secure Email Gateway Vulnerability Exploited in the Wild
CVE-2026-85706:Critical GitLab Path Traversal Exploited in the Wild
CVE-2026-83548:Critical SonicWall SMA1000 Vulnerabilities CVE-2026-83548, CVE-2026-83549 Exploited in the Wild
CVE-2026-81578:PaperCut NG/MF Critical Zero-Day Exploited in the Wild
CVE-2026-63520:Rapid7 Analysis: Microsoft SharePoint Remote Code Execution (CVE-2026-63520)
CVE-2026-19490:Critical Vulnerability Affecting Citrix NetScaler ADC and NetScaler Gateway
TitleEitWModules
CVE-2025-68718: Exposure of Sensitive Information to an Unauthorized Actor5.4 MediumN/A0%Jan 8, 2026
CVE-2025-68716: Improper Access Control8.4 HighN/A0%Jan 8, 2026
CVE-2025-62877: Initialization of a Resource with an Insecure Default9.8 CriticalN/A1%Jan 8, 2026
CVE-2025-15224: Improper Authentication3.1 LowN/A0%Jan 8, 2026
CVE-2025-15079: Improper Validation of Certificate with Host Mismatch5.3 MediumN/A1%Jan 8, 2026
CVE-2017-20214: Use of Hard-coded Credentials7.5 High9.3 Critical0%Jan 8, 2026
CVE-2025-61939: Improper Restriction of Communication Channel to Intended Endpoints8.8 High8.7 High0%Jan 7, 2026
CVE-2025-15382: Out-of-bounds Read8.1 High5.1 Medium0%Jan 6, 2026
CVE-2025-14942: Improper Authentication9.8 Critical9.4 Critical0%Jan 6, 2026
CVE-2020-36915: Use of Hard-coded Credentials7.5 High8.7 High0%Jan 6, 2026
CVE-2026-21439: Improper Neutralization of Escape, Meta, or Control Sequences5.3 Medium2.0 Low0%Jan 6, 2026
CVE-2025-64420: Insufficiently Protected Credentials9.9 CriticalN/A1%Jan 5, 2026
CVE-2021-47744: Use of Hard-coded Credentials7.5 High9.3 Critical0%Dec 31, 2025
CVE-2025-23458: Improper Neutralization of Input During Web Page Generation7.1 HighN/A0%Dec 30, 2025
CVE-2025-14175: Use of a Broken or Risky Cryptographic Algorithm6.5 Medium6.0 Medium0%Dec 29, 2025
CVE-2019-25241: Use of Hard-coded Credentials9.8 Critical9.3 Critical1%Dec 24, 2025
CVE-2019-25238: Cross-Site Request Forgery (CSRF)4.3 Medium5.1 Medium0%Dec 24, 2025
CVE-2018-25143: Improper Neutralization of Special Elements used in an OS Command8.8 High8.7 High1%Dec 24, 2025
CVE-2018-25138: Use of Hard-coded Credentials9.8 Critical9.3 Critical1%Dec 24, 2025
CVE-2025-25364: Improper Neutralization of Special Elements used in a Command8.4 HighN/A1%Dec 23, 2025
CVE-2025-14946: Improper Neutralization of Argument Delimiters in a Command4.8 MediumN/A0%Dec 19, 2025
CVE-2025-65000: Improper Removal of Sensitive Information Before Storage or Transfer5.3 Medium2.3 Low0%Dec 18, 2025
CVE-2025-68269: Acceptance of Extraneous Untrusted Data With Trusted Data5.4 MediumN/A0%Dec 16, 2025
CVE-2025-68320: Undefined Security Weakness7.5 HighN/A0%Dec 16, 2025
CVE-2024-58300: Missing Authentication for Critical FunctionN/A8.7 High0%Dec 11, 2025
476-500 of 1961