The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
CVE-2026-76461:Critical Cisco Secure Email Gateway Vulnerability Exploited in the Wild
CVE-2026-85706:Critical GitLab Path Traversal Exploited in the Wild
CVE-2026-83548:Critical SonicWall SMA1000 Vulnerabilities CVE-2026-83548, CVE-2026-83549 Exploited in the Wild
CVE-2026-81578:PaperCut NG/MF Critical Zero-Day Exploited in the Wild
CVE-2026-63520:Rapid7 Analysis: Microsoft SharePoint Remote Code Execution (CVE-2026-63520)
CVE-2026-19490:Critical Vulnerability Affecting Citrix NetScaler ADC and NetScaler Gateway
TitleEitWModules
CVE-2025-48040: Uncontrolled Resource ConsumptionN/A6.9 Medium0%Sep 11, 2025
CVE-2025-48039: Allocation of Resources Without Limits or ThrottlingN/A5.3 Medium0%Sep 11, 2025
CVE-2025-48038: Allocation of Resources Without Limits or ThrottlingN/A5.3 Medium0%Sep 11, 2025
CVE-2025-20159: Improper Access Control5.3 MediumN/A0%Sep 10, 2025
CVE-2025-56413: Improper Neutralization of Special Elements used in an OS Command8.8 HighN/A1%Sep 10, 2025
CVE-2025-9997: Improper Neutralization of Special Elements used in an OS CommandN/A5.8 Medium0%Sep 9, 2025
CVE-2025-9996: Improper Neutralization of Special Elements used in an OS CommandN/A5.8 Medium1%Sep 9, 2025
CVE-2025-8277: Missing Release of Memory after Effective Lifetime3.1 LowN/A0%Sep 9, 2025
CVE-2025-35451: Use of Hard-coded Credentials9.8 Critical9.3 Critical1%Sep 5, 2025
CVE-2025-58355: Improper Limitation of a Pathname to a Restricted Directory7.7 HighN/A0%Sep 4, 2025
CVE-2025-47421: Improper Neutralization of Argument Delimiters in a CommandN/A8.6 High0%Sep 3, 2025
CVE-2025-9817: NULL Pointer Dereference7.8 HighN/A0%Sep 3, 2025
CVE-2025-9696: Use of Hard-coded CredentialsN/A9.4 Critical0%Sep 2, 2025
CVE-2025-52548: Inclusion of Undocumented Features or Chicken Bits4.9 Medium6.9 Medium0%Sep 2, 2025
CVE-2025-9654: Improper Neutralization of Special Elements used in a Command6.3 Medium5.3 Medium1%Aug 29, 2025
CVE-2025-50753: Execution with Unnecessary PrivilegesN/AN/A0%Aug 26, 2025
CVE-2025-9358: Stack-based Buffer Overflow8.8 High7.4 High1%Aug 23, 2025
CVE-2025-38640: Undefined Security Weakness7.8 HighN/A0%Aug 22, 2025
CVE-2025-4877: Out-of-bounds Write4.5 MediumN/A0%Aug 20, 2025
CVE-2025-36120: Incorrect Authorization8.8 HighN/A0%Aug 18, 2025
CVE-2025-20265: Improper Neutralization of Special Elements in Output Used by a Downstream Component10.0 CriticalN/A15%Aug 14, 2025
CVE-2012-10060: Stack-based Buffer Overflow9.8 Critical9.3 Critical3%Aug 13, 2025
CVE-2025-43982: Use of Hard-coded Credentials9.8 CriticalN/A0%Aug 13, 2025
CVE-2025-8737: URL Redirection to Untrusted Site3.5 Low2.0 Low0%Aug 8, 2025
CVE-2010-10013: Improper Neutralization of Special Elements used in an OS CommandN/A9.3 Critical1%Aug 8, 2025
551-575 of 1961