The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
CVE-2026-76461:Critical Cisco Secure Email Gateway Vulnerability Exploited in the Wild
CVE-2026-85706:Critical GitLab Path Traversal Exploited in the Wild
CVE-2026-83548:Critical SonicWall SMA1000 Vulnerabilities CVE-2026-83548, CVE-2026-83549 Exploited in the Wild
CVE-2026-81578:PaperCut NG/MF Critical Zero-Day Exploited in the Wild
CVE-2026-63520:Rapid7 Analysis: Microsoft SharePoint Remote Code Execution (CVE-2026-63520)
CVE-2026-19490:Critical Vulnerability Affecting Citrix NetScaler ADC and NetScaler Gateway
TitleEitWModules
CVE-2024-10834: External Control of File Name or Path9.1 CriticalN/A1%Mar 20, 2025
CVE-2024-10831: Absolute Path Traversal9.1 CriticalN/A1%Mar 20, 2025
CVE-2025-30234: Use of Hard-coded Cryptographic Key8.3 HighN/A0%Mar 19, 2025
CVE-2019-17659: Use of Hard-coded Credentials3.7 LowN/A1%Mar 17, 2025
CVE-2025-2277: Exposure of Sensitive Information to an Unauthorized Actor7.5 HighN/A1%Mar 13, 2025
CVE-2025-0115: Improper Resolution of Path EquivalenceN/A6.8 Medium0%Mar 12, 2025
CVE-2025-26701: Use of Default Password10.0 CriticalN/A0%Mar 11, 2025
CVE-2025-27256: Missing Authentication for Critical Function8.3 HighN/A0%Mar 10, 2025
CVE-2024-53458: Uncontrolled Resource Consumption7.5 HighN/A1%Mar 5, 2025
CVE-2025-26466: Allocation of Resources Without Limits or Throttling5.9 MediumN/A40%Feb 28, 2025
CVE-2025-27414: Improper AuthenticationN/A4.6 Medium1%Feb 28, 2025
CVE-2025-22869: Allocation of Resources Without Limits or Throttling7.5 HighN/A1%Feb 26, 2025
CVE-2022-49335: NULL Pointer Dereference5.5 MediumN/A0%Feb 26, 2025
CVE-2025-26618: Memory Allocation with Excessive Size ValueN/A7.0 High0%Feb 20, 2025
CVE-2025-20158: Exposure of Sensitive Information to an Unauthorized Actor4.4 MediumN/A0%Feb 19, 2025
CVE-2025-26465: Detection of Error Condition Without Action6.8 MediumN/A8%Feb 18, 2025
CVE-2024-4282: Use of a Broken or Risky Cryptographic Algorithm9.8 Critical8.2 High0%Feb 15, 2025
CVE-2024-57790: Use of Hard-coded Credentials5.4 MediumN/A0%Feb 14, 2025
CVE-2025-24888: Improper Limitation of a Pathname to a Restricted Directory8.1 HighN/A1%Feb 13, 2025
CVE-2025-1100: Use of Hard-coded Password9.8 CriticalN/A1%Feb 12, 2025
CVE-2025-1143: Use of Hard-coded Credentials8.4 HighN/A0%Feb 11, 2025
CVE-2025-24366: Improper Neutralization of Special Elements used in an OS Command7.5 HighN/A1%Feb 7, 2025
CVE-2024-47857: Improper Input Validation9.8 CriticalN/A0%Jan 31, 2025
CVE-2024-26155: Cleartext Transmission of Sensitive Information6.8 Medium6.1 Medium0%Jan 17, 2025
CVE-2024-48460: Improper Certificate Validation4.3 MediumN/A0%Jan 16, 2025
651-675 of 1961