The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
CVE-2026-76461:Critical Cisco Secure Email Gateway Vulnerability Exploited in the Wild
CVE-2026-85706:Critical GitLab Path Traversal Exploited in the Wild
CVE-2026-83548:Critical SonicWall SMA1000 Vulnerabilities CVE-2026-83548, CVE-2026-83549 Exploited in the Wild
CVE-2026-81578:PaperCut NG/MF Critical Zero-Day Exploited in the Wild
CVE-2026-63520:Rapid7 Analysis: Microsoft SharePoint Remote Code Execution (CVE-2026-63520)
CVE-2026-19490:Critical Vulnerability Affecting Citrix NetScaler ADC and NetScaler Gateway
TitleEitWModules
CVE-2025-57060: Stack-based Buffer Overflow7.5 HighN/A0%Sep 9, 2025
CVE-2025-55730: Improper Encoding or Escaping of Output10.0 CriticalN/A1%Sep 9, 2025
CVE-2025-55729: Improper Encoding or Escaping of Output10.0 CriticalN/A1%Sep 9, 2025
CVE-2025-55728: Improper Neutralization of Directives in Dynamically Evaluated Code10.0 CriticalN/A1%Sep 9, 2025
CVE-2025-55727: Improper Neutralization of Directives in Dynamically Evaluated Code10.0 CriticalN/A1%Sep 9, 2025
CVE-2025-55052: Exposure of Sensitive Information to an Unauthorized Actor4.3 MediumN/A0%Sep 9, 2025
CVE-2025-55051: Use of Default Credentials10.0 CriticalN/A0%Sep 9, 2025
CVE-2025-55050: Inclusion of Undocumented Features or Chicken Bits9.8 CriticalN/A0%Sep 9, 2025
CVE-2025-55049: Use of Default Cryptographic Key9.1 CriticalN/A0%Sep 9, 2025
CVE-2025-55048: Improper Neutralization of Special Elements used in an OS Command9.8 CriticalN/A1%Sep 9, 2025
CVE-2025-55047: Use of Hard-coded Credentials8.4 HighN/A0%Sep 9, 2025
CVE-2025-54256: Cross-Site Request Forgery (CSRF)8.6 HighN/A0%Sep 9, 2025
CVE-2025-54242: Use After Free7.8 HighN/A0%Sep 9, 2025
CVE-2025-43781: Improper Neutralization of Input During Web Page Generation6.1 Medium5.3 Medium0%Sep 9, 2025
CVE-2025-43775: Improper Neutralization of Input During Web Page Generation5.4 Medium4.6 Medium0%Sep 9, 2025
CVE-2025-29089: Exposure of Sensitive Information to an Unauthorized Actor7.5 HighN/A0%Sep 9, 2025
CVE-2025-10164: Deserialization of Untrusted Data7.3 High5.5 Medium0%Sep 9, 2025
CVE-2025-9269: Server-Side Request Forgery (SSRF)N/A6.9 Medium0%Sep 9, 2025
CVE-2025-57665: Improper Neutralization of Input During Web Page Generation6.4 MediumN/A0%Sep 9, 2025
CVE-2025-57086: Stack-based Buffer Overflow7.5 HighN/A0%Sep 9, 2025
CVE-2025-57085: Stack-based Buffer Overflow9.8 CriticalN/A0%Sep 9, 2025
CVE-2025-57078: Stack-based Buffer Overflow7.5 HighN/A0%Sep 9, 2025
CVE-2025-10199: Unquoted Search Path or Element7.8 HighN/A0%Sep 9, 2025
CVE-2025-10198: Uncontrolled Search Path Element7.8 HighN/A0%Sep 9, 2025
CVE-2025-5500: Improper Export of Android Application Components5.3 Medium1.9 Low0%Sep 9, 2025
87151-87175 of 507429