The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
CVE-2026-76461:Critical Cisco Secure Email Gateway Vulnerability Exploited in the Wild
CVE-2026-85706:Critical GitLab Path Traversal Exploited in the Wild
CVE-2026-83548:Critical SonicWall SMA1000 Vulnerabilities CVE-2026-83548, CVE-2026-83549 Exploited in the Wild
CVE-2026-81578:PaperCut NG/MF Critical Zero-Day Exploited in the Wild
CVE-2026-63520:Rapid7 Analysis: Microsoft SharePoint Remote Code Execution (CVE-2026-63520)
CVE-2026-19490:Critical Vulnerability Affecting Citrix NetScaler ADC and NetScaler Gateway
TitleEitWModules
CVE-2025-55147: Cross-Site Request Forgery (CSRF)8.8 HighN/A1%Sep 9, 2025
CVE-2025-55146: Unchecked Return Value4.9 MediumN/A1%Sep 9, 2025
CVE-2025-55145: Missing Authorization8.9 HighN/A1%Sep 9, 2025
CVE-2025-55144: Missing Authorization5.4 MediumN/A1%Sep 9, 2025
CVE-2025-55143: Improper Neutralization of Input During Web Page Generation6.1 MediumN/A1%Sep 9, 2025
CVE-2025-55142: Missing Authorization8.8 HighN/A1%Sep 9, 2025
CVE-2025-55141: Missing Authorization8.8 HighN/A1%Sep 9, 2025
CVE-2025-55139: Server-Side Request Forgery (SSRF)6.8 MediumN/A1%Sep 9, 2025
CVE-2025-52915: Improper Privilege Management7.2 HighN/A1%Sep 9, 2025
CVE-2025-52322: Uncontrolled Resource Consumption7.5 HighN/A1%Sep 9, 2025
CVE-2025-52277: Improper Neutralization of Input During Web Page Generation6.1 MediumN/A0%Sep 9, 2025
CVE-2025-43776: Generation of Error Message Containing Sensitive Information5.4 Medium4.6 Medium0%Sep 9, 2025
CVE-2025-10183: Improper Restriction of XML External Entity Reference9.1 CriticalN/A0%Sep 9, 2025
CVE-2025-10107: Improper Neutralization of Special Elements used in a Command4.7 Medium2.0 Low4%Sep 9, 2025
CVE-2025-9994: Improper Authentication9.8 CriticalN/A1%Sep 9, 2025
CVE-2025-9951: Heap-based Buffer OverflowN/A7.2 High0%Sep 9, 2025
CVE-2025-54236: Improper Input Validation9.1 CriticalN/A95%Sep 9, 2025
CVE-2025-53609: Relative Path Traversal4.9 MediumN/A9%Sep 9, 2025
CVE-2025-47416: Incorrect ComparisonN/A5.9 Medium0%Sep 9, 2025
CVE-2025-33045: Write-what-where Condition8.2 HighN/A0%Sep 9, 2025
CVE-2024-45325: Improper Neutralization of Special Elements used in an OS Command6.7 MediumN/A0%Sep 9, 2025
CVE-2025-9364: Exposure of Sensitive System Information to an Unauthorized Control Sphere8.8 High8.7 High0%Sep 9, 2025
CVE-2025-9166: NULL Pointer Dereference7.5 High8.2 High0%Sep 9, 2025
CVE-2025-9161: Improper Neutralization of Special Elements used in a Command8.8 High7.3 High1%Sep 9, 2025
CVE-2025-9160: Missing Authentication for Critical FunctionN/A7.0 High0%Sep 9, 2025
87226-87250 of 788572