The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
CVE-2026-76461:Critical Cisco Secure Email Gateway Vulnerability Exploited in the Wild
CVE-2026-85706:Critical GitLab Path Traversal Exploited in the Wild
CVE-2026-83548:Critical SonicWall SMA1000 Vulnerabilities CVE-2026-83548, CVE-2026-83549 Exploited in the Wild
CVE-2026-81578:PaperCut NG/MF Critical Zero-Day Exploited in the Wild
CVE-2026-63520:Rapid7 Analysis: Microsoft SharePoint Remote Code Execution (CVE-2026-63520)
CVE-2026-19490:Critical Vulnerability Affecting Citrix NetScaler ADC and NetScaler Gateway
TitleEitWModules
CVE-2025-7448: Authentication Bypass by SpoofingN/A8.6 High0%Sep 12, 2025
CVE-2025-10264: Exposure of Sensitive System Information to an Unauthorized Control Sphere10.0 Critical10.0 Critical0%Sep 12, 2025
CVE-2025-21043: Out-of-bounds Write8.8 HighN/A2%Sep 12, 2025
CVE-2025-21042: Out-of-bounds Write8.8 HighN/A33%Sep 12, 2025
CVE-2025-8575: Absolute Path Traversal7.2 HighN/A1%Sep 12, 2025
CVE-2025-8280: Undefined Security Weakness5.8 MediumN/A0%Sep 12, 2025
CVE-2025-7337: Allocation of Resources Without Limits or Throttling6.5 MediumN/A0%Sep 12, 2025
CVE-2025-6769: Exposure of Sensitive System Information to an Unauthorized Control Sphere4.3 MediumN/A0%Sep 12, 2025
CVE-2025-6454: Server-Side Request Forgery (SSRF)8.5 HighN/A1%Sep 12, 2025
CVE-2025-58781: Improper Certificate Validation4.8 Medium6.3 Medium0%Sep 12, 2025
CVE-2025-3650: Undefined Security Weakness3.5 LowN/A0%Sep 12, 2025
CVE-2025-2256: Improper Validation of Specified Quantity in Input7.5 HighN/A1%Sep 12, 2025
CVE-2025-1250: Allocation of Resources Without Limits or Throttling6.5 MediumN/A0%Sep 12, 2025
CVE-2025-10291: Improper Authorization6.3 Medium2.1 Low0%Sep 12, 2025
CVE-2025-10148: Generation of Predictable Numbers or Identifiers5.3 MediumN/A0%Sep 12, 2025
CVE-2025-10288: Improper Authentication5.3 Medium5.5 Medium0%Sep 12, 2025
CVE-2025-10287: Direct Request3.1 Low1.3 Low0%Sep 12, 2025
CVE-2025-10094: Improper Validation of Specified Quantity in Input6.5 MediumN/A0%Sep 12, 2025
CVE-2025-9086: Out-of-bounds ReadN/AN/A1%Sep 12, 2025
CVE-2025-9881: Cross-Site Request Forgery (CSRF)6.1 MediumN/A0%Sep 12, 2025
CVE-2025-9880: Cross-Site Request Forgery (CSRF)6.1 MediumN/A0%Sep 12, 2025
CVE-2025-9879: Improper Neutralization of Input During Web Page Generation6.4 MediumN/A0%Sep 12, 2025
CVE-2025-9877: Improper Neutralization of Input During Web Page Generation6.4 MediumN/A0%Sep 12, 2025
CVE-2025-10278: Improper Authorization6.3 Medium2.1 Low0%Sep 12, 2025
CVE-2025-43789: Incorrect Authorization5.3 Medium1.0 Low0%Sep 12, 2025
87051-87075 of 545471