The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
CVE-2026-94127:Critical Unauthenticated RCE in F5 BIG-IP APM
CVE-2026-76461:Critical Cisco Secure Email Gateway Vulnerability Exploited in the Wild
CVE-2026-85706:Critical GitLab Path Traversal Exploited in the Wild
CVE-2026-83548:Critical SonicWall SMA1000 Vulnerabilities CVE-2026-83548, CVE-2026-83549 Exploited in the Wild
CVE-2026-81578:PaperCut NG/MF Critical Zero-Day Exploited in the Wild
CVE-2026-63520:Rapid7 Analysis: Microsoft SharePoint Remote Code Execution (CVE-2026-63520)
TitleEitWModules
CVE-2025-43307: Incorrect Authorization4.0 MediumN/A0%Sep 15, 2025
CVE-2025-43305: Improper Access Control5.5 MediumN/A0%Sep 15, 2025
CVE-2025-43304: Concurrent Execution using Shared Resource with Improper Synchronization7.0 HighN/A0%Sep 15, 2025
CVE-2025-43303: Insertion of Sensitive Information into Log File5.5 MediumN/A0%Sep 15, 2025
CVE-2025-43302: Out-of-bounds Write5.5 MediumN/A0%Sep 15, 2025
CVE-2025-43301: Exposure of Private Personal Information to an Unauthorized Actor3.3 LowN/A0%Sep 15, 2025
CVE-2025-43299: Improper Input Validation5.5 MediumN/A0%Sep 15, 2025
CVE-2025-43298: Improper Resolution of Path Equivalence7.8 HighN/A0%Sep 15, 2025
CVE-2025-43297: Access of Resource Using Incompatible Type6.2 MediumN/A0%Sep 15, 2025
CVE-2025-43295: Uncontrolled Resource Consumption5.5 MediumN/A0%Sep 15, 2025
CVE-2025-43294: Improper Access Control3.3 LowN/A0%Sep 15, 2025
CVE-2025-43293: Improper Input Validation5.5 MediumN/A0%Sep 15, 2025
CVE-2025-43292: Concurrent Execution using Shared Resource with Improper Synchronization5.5 MediumN/A0%Sep 15, 2025
CVE-2025-43291: Improper Access Control5.5 MediumN/A0%Sep 15, 2025
CVE-2025-43287: Improper Restriction of Operations within the Bounds of a Memory Buffer7.1 HighN/A0%Sep 15, 2025
CVE-2025-43286: Missing Authorization7.8 HighN/A0%Sep 15, 2025
CVE-2025-43285: Improper Access Control5.5 MediumN/A0%Sep 15, 2025
CVE-2025-43283: Out-of-bounds Read3.3 LowN/A0%Sep 15, 2025
CVE-2025-43279: Exposure of Private Personal Information to an Unauthorized Actor6.2 MediumN/A0%Sep 15, 2025
CVE-2025-43272: Improper Restriction of Operations within the Bounds of a Memory Buffer6.5 MediumN/A1%Sep 15, 2025
CVE-2025-43263: Improper Access Control7.1 HighN/A0%Sep 15, 2025
CVE-2025-43262: Improperly Implemented Security Check for Standard5.1 MediumN/A0%Sep 15, 2025
CVE-2025-43231: Improper Authorization5.5 MediumN/A0%Sep 15, 2025
CVE-2025-43208: Improper Access Control5.5 MediumN/A0%Sep 15, 2025
CVE-2025-43207: Improper Access Control5.5 MediumN/A0%Sep 15, 2025
86726-86750 of 775503