The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
CVE-2026-76461:Critical Cisco Secure Email Gateway Vulnerability Exploited in the Wild
CVE-2026-85706:Critical GitLab Path Traversal Exploited in the Wild
CVE-2026-83548:Critical SonicWall SMA1000 Vulnerabilities CVE-2026-83548, CVE-2026-83549 Exploited in the Wild
CVE-2026-81578:PaperCut NG/MF Critical Zero-Day Exploited in the Wild
CVE-2026-63520:Rapid7 Analysis: Microsoft SharePoint Remote Code Execution (CVE-2026-63520)
CVE-2026-19490:Critical Vulnerability Affecting Citrix NetScaler ADC and NetScaler Gateway
TitleEitWModules
CVE-2025-8731: Use of Default Credentials9.8 Critical8.9 High1%Aug 8, 2025
CVE-2013-10065: Uncaught Exception7.5 High8.7 High49%Aug 5, 2025
CVE-2025-43980: Improper Access Control6.5 MediumN/A0%Aug 5, 2025
CVE-2025-54804: Integer Overflow or Wraparound6.5 MediumN/A0%Aug 5, 2025
CVE-2025-38741: Use of Hard-coded Cryptographic Key7.5 HighN/A0%Aug 4, 2025
CVE-2025-44954: Use of Default Cryptographic Key9.0 CriticalN/A1%Aug 4, 2025
CVE-2014-125121: Use of Hard-coded CredentialsN/A10.0 Critical41%Jul 31, 2025
CVE-2023-53158: Improper Neutralization of Special Elements used in an OS Command4.1 MediumN/A0%Jul 28, 2025
CVE-2025-5449: Integer Overflow or Wraparound6.5 MediumN/A1%Jul 25, 2025
CVE-2025-29630: Undefined Security WeaknessN/AN/A0%Jul 25, 2025
CVE-2025-8114: NULL Pointer Dereference4.7 MediumN/A0%Jul 24, 2025
CVE-2025-6018: Incorrect Authorization7.8 HighN/A1%Jul 23, 2025
CVE-2025-4878: Use After Free3.6 LowN/A0%Jul 22, 2025
CVE-2025-7885: Improper Neutralization of Input During Web Page Generation4.3 Medium2.1 Low0%Jul 20, 2025
CVE-2025-34112: Improper Neutralization of Special Elements used in an SQL CommandN/A10.0 Critical3%Jul 15, 2025
CVE-2025-45582: Path Traversal: '../filedir'4.1 MediumN/A0%Jul 11, 2025
CVE-2025-27027: Improper Isolation or Compartmentalization4.1 MediumN/A0%Jul 9, 2025
CVE-2025-4663: Improper Check for Unusual or Exceptional Conditions4.9 Medium6.8 Medium0%Jul 8, 2025
CVE-2025-41224: Protection Mechanism Failure8.8 High7.7 High0%Jul 8, 2025
CVE-2025-24006: Improper Privilege Management7.8 HighN/A0%Jul 8, 2025
CVE-2025-24005: Improper Input Validation7.8 HighN/A0%Jul 8, 2025
CVE-2025-5987: Return of Wrong Status Code8.1 HighN/A1%Jul 7, 2025
CVE-2025-47228: Improper Neutralization of Special Elements used in an OS Command6.7 MediumN/A17%Jul 5, 2025
CVE-2025-5351: Double Free6.5 MediumN/A1%Jul 4, 2025
CVE-2025-5372: Incorrect Calculation8.8 HighN/A0%Jul 4, 2025
576-600 of 1961