The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
CVE-2026-76461:Critical Cisco Secure Email Gateway Vulnerability Exploited in the Wild
CVE-2026-85706:Critical GitLab Path Traversal Exploited in the Wild
CVE-2026-83548:Critical SonicWall SMA1000 Vulnerabilities CVE-2026-83548, CVE-2026-83549 Exploited in the Wild
CVE-2026-81578:PaperCut NG/MF Critical Zero-Day Exploited in the Wild
CVE-2026-63520:Rapid7 Analysis: Microsoft SharePoint Remote Code Execution (CVE-2026-63520)
CVE-2026-19490:Critical Vulnerability Affecting Citrix NetScaler ADC and NetScaler Gateway
TitleEitWModules
CVE-2025-10328: Improper Neutralization of Special Elements used in an OS Command6.3 Medium2.1 Low9%Sep 12, 2025
CVE-2025-10176: Improper Limitation of a Pathname to a Restricted Directory7.2 HighN/A1%Sep 12, 2025
CVE-2025-45587: Stack-based Buffer Overflow7.0 HighN/A0%Sep 12, 2025
CVE-2025-45586: Unrestricted Upload of File with Dangerous Type7.5 HighN/A0%Sep 12, 2025
CVE-2025-45585: Improper Neutralization of Input During Web Page Generation5.4 MediumN/A0%Sep 12, 2025
CVE-2025-45584: Improper Access Control7.5 HighN/A0%Sep 12, 2025
CVE-2025-45583: Improper Authentication9.1 CriticalN/A0%Sep 12, 2025
CVE-2025-10327: Improper Neutralization of Special Elements used in an OS Command6.3 Medium2.1 Low10%Sep 12, 2025
CVE-2025-10326: Improper Neutralization of Special Elements used in an OS Command6.3 Medium2.1 Low7%Sep 12, 2025
CVE-2025-43796: Uncontrolled Resource Consumption7.5 High7.1 High0%Sep 12, 2025
CVE-2025-43795: URL Redirection to Untrusted Site6.1 Medium5.1 Medium0%Sep 12, 2025
CVE-2025-10325: Improper Neutralization of Special Elements used in a Command6.3 Medium2.1 Low7%Sep 12, 2025
CVE-2025-10324: Improper Neutralization of Special Elements used in a Command7.3 High5.5 Medium8%Sep 12, 2025
CVE-2025-10323: Improper Neutralization of Special Elements used in a Command7.3 High5.5 Medium8%Sep 12, 2025
CVE-2025-58434: Missing Authentication for Critical Function9.8 CriticalN/A50%Sep 12, 2025
CVE-2025-4235: Exposure of Sensitive System Information to an Unauthorized Control SphereN/A7.2 High0%Sep 12, 2025
CVE-2025-4234: Insertion of Sensitive Information into Log FileN/A2.4 Low0%Sep 12, 2025
CVE-2025-10322: Weak Password Recovery Mechanism for Forgotten Password5.3 Medium5.5 Medium0%Sep 12, 2025
CVE-2025-10321: Exposure of Sensitive Information to an Unauthorized Actor5.3 Medium5.5 Medium1%Sep 12, 2025
CVE-2025-56467: Exposure of Sensitive Information to an Unauthorized Actor6.5 MediumN/A0%Sep 12, 2025
CVE-2025-52074: Improper Neutralization of Input During Web Page Generation6.1 MediumN/A0%Sep 12, 2025
CVE-2025-43787: Improper Neutralization of Input During Web Page Generation5.4 Medium5.1 Medium0%Sep 12, 2025
CVE-2024-45434: Use After Free9.8 CriticalN/A7%Sep 12, 2025
CVE-2024-45433: Incorrect Control Flow Scoping6.5 MediumN/A1%Sep 12, 2025
CVE-2024-45432: Improper Access Control7.5 HighN/A1%Sep 12, 2025
87001-87025 of 545471