The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
CVE-2026-76461:Critical Cisco Secure Email Gateway Vulnerability Exploited in the Wild
CVE-2026-85706:Critical GitLab Path Traversal Exploited in the Wild
CVE-2026-83548:Critical SonicWall SMA1000 Vulnerabilities CVE-2026-83548, CVE-2026-83549 Exploited in the Wild
CVE-2026-81578:PaperCut NG/MF Critical Zero-Day Exploited in the Wild
CVE-2026-63520:Rapid7 Analysis: Microsoft SharePoint Remote Code Execution (CVE-2026-63520)
CVE-2026-19490:Critical Vulnerability Affecting Citrix NetScaler ADC and NetScaler Gateway
TitleEitWModules
CVE-2025-10422: Improper Authorization4.3 Medium2.1 Low0%Sep 15, 2025
CVE-2025-10421: Improper Neutralization of Special Elements used in an SQL Command6.3 Medium2.1 Low0%Sep 15, 2025
CVE-2025-10420: Improper Neutralization of Special Elements used in an SQL Command6.3 Medium2.1 Low0%Sep 15, 2025
CVE-2025-10419: Improper Neutralization of Special Elements used in an SQL Command6.3 Medium2.1 Low0%Sep 15, 2025
CVE-2025-10418: Improper Neutralization of Special Elements used in an SQL Command6.3 Medium2.1 Low0%Sep 15, 2025
CVE-2025-10417: Improper Neutralization of Special Elements used in an SQL Command7.3 High5.5 Medium0%Sep 15, 2025
CVE-2025-10416: Improper Neutralization of Special Elements used in an SQL Command7.3 High5.5 Medium0%Sep 15, 2025
CVE-2025-59364: Uncontrolled Recursion5.3 MediumN/A0%Sep 14, 2025
CVE-2025-10415: Improper Neutralization of Special Elements used in an SQL Command7.3 High5.5 Medium0%Sep 14, 2025
CVE-2025-10414: Improper Neutralization of Special Elements used in an SQL Command7.3 High5.5 Medium0%Sep 14, 2025
CVE-2025-10413: Improper Neutralization of Special Elements used in an SQL Command7.3 High5.5 Medium0%Sep 14, 2025
CVE-2025-10411: Improper Neutralization of Input During Web Page Generation4.3 Medium2.1 Low0%Sep 14, 2025
CVE-2025-10410: Server-Side Request Forgery (SSRF)6.3 Medium2.1 Low0%Sep 14, 2025
CVE-2025-10409: Improper Neutralization of Special Elements used in an SQL Command6.3 Medium2.1 Low0%Sep 14, 2025
CVE-2025-10408: Improper Neutralization of Special Elements used in an SQL Command6.3 Medium2.1 Low0%Sep 14, 2025
CVE-2025-10407: Improper Neutralization of Special Elements used in an SQL Command6.3 Medium2.1 Low0%Sep 14, 2025
CVE-2025-10405: Improper Neutralization of Special Elements used in an SQL Command7.3 High5.5 Medium0%Sep 14, 2025
CVE-2025-10404: Improper Neutralization of Special Elements used in an SQL Command7.3 High5.5 Medium0%Sep 14, 2025
CVE-2025-10403: Improper Neutralization of Special Elements used in an SQL Command7.3 High5.5 Medium0%Sep 14, 2025
CVE-2025-6051: Inefficient Regular Expression Complexity5.3 MediumN/A0%Sep 14, 2025
CVE-2025-10402: Improper Neutralization of Special Elements used in an SQL Command7.3 High5.5 Medium0%Sep 14, 2025
CVE-2025-10401: Improper Neutralization of Special Elements used in a Command6.3 Medium2.1 Low8%Sep 14, 2025
CVE-2025-10400: Improper Neutralization of Special Elements used in an SQL Command6.3 Medium2.1 Low0%Sep 14, 2025
CVE-2025-36035: Allocation of Resources Without Limits or Throttling6.7 MediumN/A0%Sep 14, 2025
CVE-2025-10399: Improper Neutralization of Special Elements used in an SQL Command6.3 Medium2.1 Low0%Sep 14, 2025
86951-86975 of 673429