The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
CVE-2026-76461:Critical Cisco Secure Email Gateway Vulnerability Exploited in the Wild
CVE-2026-85706:Critical GitLab Path Traversal Exploited in the Wild
CVE-2026-83548:Critical SonicWall SMA1000 Vulnerabilities CVE-2026-83548, CVE-2026-83549 Exploited in the Wild
CVE-2026-81578:PaperCut NG/MF Critical Zero-Day Exploited in the Wild
CVE-2026-63520:Rapid7 Analysis: Microsoft SharePoint Remote Code Execution (CVE-2026-63520)
CVE-2026-19490:Critical Vulnerability Affecting Citrix NetScaler ADC and NetScaler Gateway
TitleEitWModules
CVE-2025-22968: Improper Control of Generation of Code9.8 CriticalN/A2%Jan 15, 2025
CVE-2024-57882: NULL Pointer Dereference9.8 CriticalN/A1%Jan 15, 2025
CVE-2024-57811: Use of Hard-coded Credentials9.1 CriticalN/A0%Jan 13, 2025
CVE-2024-53705: Server-Side Request Forgery (SSRF)7.5 HighN/A1%Jan 9, 2025
CVE-2025-22275: Insertion of Sensitive Information into Log File9.3 CriticalN/A1%Jan 3, 2025
CVE-2024-53168: Use After Free7.8 HighN/A0%Dec 27, 2024
CVE-2024-52046: Deserialization of Untrusted Data9.8 Critical10.0 Critical24%Dec 25, 2024
CVE-2024-55947: Improper Limitation of a Pathname to a Restricted Directory8.8 High8.7 High75%Dec 23, 2024
CVE-2024-54148: UNIX Symbolic Link (Symlink) Following9.8 Critical8.7 High1%Dec 23, 2024
CVE-2024-12728: Use of Weak Credentials9.8 CriticalN/A1%Dec 19, 2024
CVE-2024-28980: Use of a Broken or Risky Cryptographic Algorithm6.5 MediumN/A1%Dec 13, 2024
CVE-2024-45337: Undefined Security Weakness9.1 CriticalN/A3%Dec 12, 2024
CVE-2024-12286: Use of Default Credentials9.8 Critical9.3 Critical0%Dec 10, 2024
CVE-2024-55560: Undefined Security Weakness9.8 CriticalN/A1%Dec 8, 2024
CVE-2024-11983: Improper Neutralization of Special Elements used in an OS Command7.2 HighN/A1%Nov 29, 2024
CVE-2024-7517: Improper Neutralization of Special Elements used in an OS Command7.8 High8.5 High1%Nov 21, 2024
CVE-2024-11075: Execution with Unnecessary Privileges8.8 HighN/A0%Nov 19, 2024
CVE-2022-1884: Improper Neutralization of Special Elements used in an OS Command9.8 CriticalN/A2%Nov 15, 2024
CVE-2024-52308: Improper Neutralization of Special Elements used in a Command8.0 HighN/A1%Nov 14, 2024
CVE-2023-34049: Undefined Security Weakness6.7 MediumN/A0%Nov 14, 2024
CVE-2024-7516: Key Exchange without Entity Authentication7.1 High7.0 High0%Nov 12, 2024
CVE-2024-52010: Improper Neutralization of Special Elements used in an OS CommandN/A8.6 High2%Nov 12, 2024
CVE-2024-50560: Improper Input Validation3.1 Low2.3 Low0%Nov 12, 2024
CVE-2024-11068: Incorrect Use of Privileged APIs9.8 CriticalN/A1%Nov 11, 2024
CVE-2024-11065: Improper Neutralization of Special Elements used in an OS Command7.2 HighN/A1%Nov 11, 2024
676-700 of 1961