The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
CVE-2026-94127:Critical Unauthenticated RCE in F5 BIG-IP APM
CVE-2026-76461:Critical Cisco Secure Email Gateway Vulnerability Exploited in the Wild
CVE-2026-85706:Critical GitLab Path Traversal Exploited in the Wild
CVE-2026-83548:Critical SonicWall SMA1000 Vulnerabilities CVE-2026-83548, CVE-2026-83549 Exploited in the Wild
CVE-2026-81578:PaperCut NG/MF Critical Zero-Day Exploited in the Wild
CVE-2026-63520:Rapid7 Analysis: Microsoft SharePoint Remote Code Execution (CVE-2026-63520)
TitleEitWModules
CVE-2025-45091: Improper Neutralization of Input During Web Page Generation5.4 MediumN/A0%Sep 15, 2025
CVE-2025-10475: Improper Resource Shutdown or Release5.5 Medium5.4 Medium0%Sep 15, 2025
CVE-2025-59399: Improper Cleanup on Thrown Exception3.1 LowN/A0%Sep 15, 2025
CVE-2025-59398: Missing Report of Error Condition3.1 LowN/A0%Sep 15, 2025
CVE-2025-43800: Improper Neutralization of Input During Web Page Generation6.1 Medium4.8 Medium0%Sep 15, 2025
CVE-2025-10473: Improper Neutralization of Special Elements used in an SQL Command6.3 Medium2.1 Low0%Sep 15, 2025
CVE-2025-10472: Improper Limitation of a Pathname to a Restricted Directory5.3 Medium5.5 Medium1%Sep 15, 2025
CVE-2025-55777: Undefined Security WeaknessN/AN/AN/ASep 15, 2025
CVE-2025-52344: Improper Neutralization of Input During Web Page Generation6.1 MediumN/A0%Sep 15, 2025
CVE-2025-43791: Improper Neutralization of Input During Web Page Generation6.1 Medium4.8 Medium0%Sep 15, 2025
CVE-2025-59328: Deserialization of Untrusted Data6.5 MediumN/A1%Sep 15, 2025
CVE-2025-59155: Server-Side Request Forgery (SSRF)N/A6.9 Medium0%Sep 15, 2025
CVE-2025-58748: Deserialization of Untrusted Data9.8 Critical8.7 High1%Sep 15, 2025
CVE-2025-58177: Improper Neutralization of Input During Web Page Generation5.4 MediumN/A0%Sep 15, 2025
CVE-2025-58172: Improper Neutralization of Input During Web Page GenerationN/A5.3 Medium0%Sep 15, 2025
CVE-2025-57176: Unrestricted Upload of File with Dangerous Type6.5 MediumN/A0%Sep 15, 2025
CVE-2025-57174: Use of Hard-coded Cryptographic Key9.8 CriticalN/A2%Sep 15, 2025
CVE-2025-57104: Improper Neutralization of Special Elements used in an SQL Command5.4 MediumN/A0%Sep 15, 2025
CVE-2025-49089: Improper Limitation of a Pathname to a Restricted Directory6.3 MediumN/A0%Sep 15, 2025
CVE-2025-43792: External Control of System or Configuration Setting5.3 Medium2.3 Low0%Sep 15, 2025
CVE-2025-10471: Server-Side Request Forgery (SSRF)6.3 Medium2.1 Low0%Sep 15, 2025
CVE-2025-10203: Relative Path Traversal7.8 High8.5 High0%Sep 15, 2025
CVE-2025-59397: Improper Neutralization of Special Elements used in an SQL Command5.0 MediumN/A0%Sep 15, 2025
CVE-2025-58046: Deserialization of Untrusted Data9.8 Critical8.7 High1%Sep 15, 2025
CVE-2025-58045: Server-Side Request Forgery (SSRF)9.8 Critical7.1 High1%Sep 15, 2025
86776-86800 of 673429