The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
CVE-2026-76461:Critical Cisco Secure Email Gateway Vulnerability Exploited in the Wild
CVE-2026-85706:Critical GitLab Path Traversal Exploited in the Wild
CVE-2026-83548:Critical SonicWall SMA1000 Vulnerabilities CVE-2026-83548, CVE-2026-83549 Exploited in the Wild
CVE-2026-81578:PaperCut NG/MF Critical Zero-Day Exploited in the Wild
CVE-2026-63520:Rapid7 Analysis: Microsoft SharePoint Remote Code Execution (CVE-2026-63520)
CVE-2026-19490:Critical Vulnerability Affecting Citrix NetScaler ADC and NetScaler Gateway
TitleEitWModules
CVE-2023-6004: Improper Neutralization of Special Elements in Output Used by a Downstream Component4.8 MediumN/A0%Jan 3, 2024
CVE-2022-3010: Use of Weak Credentials7.5 HighN/A1%Jan 2, 2024
CVE-2023-40236: Use of Hard-coded Credentials5.3 MediumN/A0%Dec 25, 2023
CVE-2023-51767: Undefined Security Weakness7.0 HighN/A1%Dec 24, 2023
CVE-2023-6918: Unchecked Return Value3.7 LowN/A1%Dec 18, 2023
CVE-2023-51385: Improper Neutralization of Special Elements used in an OS Command6.5 MediumN/A20%Dec 18, 2023
CVE-2023-48795: Improper Validation of Integrity Check Value5.9 MediumN/A93%Dec 18, 2023
CVE-2023-28053: Use of a Broken or Risky Cryptographic Algorithm5.3 MediumN/A0%Dec 18, 2023
CVE-2023-51384: Improper Access ControlN/AN/A0%Dec 18, 2023
CVE-2023-36654: Improper Limitation of a Pathname to a Restricted Directory6.5 MediumN/A1%Dec 12, 2023
CVE-2023-45285: Undefined Security Weakness7.5 HighN/A1%Dec 6, 2023
CVE-2023-6269: Improper Neutralization of Argument Delimiters in a Command10.0 CriticalN/A2%Dec 5, 2023
CVE-2023-48712: Incorrect Authorization7.1 HighN/A1%Nov 24, 2023
CVE-2023-6174: Out-of-bounds Read6.3 MediumN/A1%Nov 16, 2023
CVE-2023-34060: Missing Authentication for Critical Function9.8 CriticalN/A1%Nov 14, 2023
CVE-2023-46446: Authorization Bypass Through User-Controlled Key6.8 MediumN/A1%Nov 14, 2023
CVE-2023-46445: Insufficient Verification of Data Authenticity5.9 MediumN/A1%Nov 14, 2023
CVE-2023-45140: Missing Authentication for Critical Function4.8 MediumN/A0%Nov 8, 2023
CVE-2023-38994: Exposure of Resource to Wrong Sphere7.9 HighN/A0%Oct 31, 2023
CVE-2023-35794: Improper Authentication8.8 HighN/A1%Oct 27, 2023
CVE-2023-46122: Improper Limitation of a Pathname to a Restricted Directory3.9 LowN/A0%Oct 23, 2023
CVE-2023-46322: Improper Output Neutralization for Logs9.8 CriticalN/A1%Oct 22, 2023
CVE-2023-44184: Improper Restriction of Operations within the Bounds of a Memory Buffer6.5 MediumN/A1%Oct 12, 2023
CVE-2023-45226: Use of Hard-coded Credentials7.4 HighN/A0%Oct 10, 2023
CVE-2023-36380: Use of Hard-coded Credentials9.8 CriticalN/A0%Oct 10, 2023
826-850 of 1969