The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
CVE-2026-76461:Critical Cisco Secure Email Gateway Vulnerability Exploited in the Wild
CVE-2026-85706:Critical GitLab Path Traversal Exploited in the Wild
CVE-2026-83548:Critical SonicWall SMA1000 Vulnerabilities CVE-2026-83548, CVE-2026-83549 Exploited in the Wild
CVE-2026-81578:PaperCut NG/MF Critical Zero-Day Exploited in the Wild
CVE-2026-63520:Rapid7 Analysis: Microsoft SharePoint Remote Code Execution (CVE-2026-63520)
CVE-2026-19490:Critical Vulnerability Affecting Citrix NetScaler ADC and NetScaler Gateway
TitleEitWModules
CVE-2023-43068: Improper Neutralization of Special Elements used in an OS Command7.8 HighN/A1%Oct 5, 2023
CVE-2023-43809: Improper Authentication7.5 HighN/A1%Oct 4, 2023
CVE-2023-43660: Improper Authentication4.8 MediumN/A0%Sep 27, 2023
CVE-2023-42818: Improper Authentication5.4 MediumN/A1%Sep 27, 2023
CVE-2023-43652: Missing Authorization8.2 HighN/A1%Sep 27, 2023
CVE-2023-20262: Undefined Security Weakness5.3 MediumN/A1%Sep 27, 2023
CVE-2023-35793: Cross-Site Request Forgery (CSRF)8.8 HighN/A1%Sep 26, 2023
CVE-2023-43631: Insufficiently Protected Credentials8.8 HighN/A0%Sep 21, 2023
CVE-2023-43633: Insufficiently Protected Credentials8.8 HighN/A0%Sep 21, 2023
CVE-2023-43619: Unrestricted Upload of File with Dangerous Type7.8 HighN/A0%Sep 20, 2023
CVE-2023-41160: Improper Neutralization of Input During Web Page Generation5.4 MediumN/A1%Sep 14, 2023
CVE-2023-41939: Improper Preservation of Permissions8.8 HighN/A1%Sep 6, 2023
CVE-2023-39982: Use of Hard-coded Cryptographic Key7.5 HighN/A0%Sep 2, 2023
CVE-2023-34039: Use of a Broken or Risky Cryptographic Algorithm9.8 CriticalN/A67%Aug 29, 2023
CVE-2023-41153: Improper Neutralization of Input During Web Page Generation5.4 MediumN/A1%Aug 29, 2023
CVE-2023-40371: Use of a Broken or Risky Cryptographic Algorithm6.2 MediumN/A0%Aug 24, 2023
CVE-2023-37426: Use of Hard-coded Credentials7.4 HighN/A0%Aug 22, 2023
CVE-2020-22218: Out-of-bounds Write7.5 HighN/A1%Aug 22, 2023
CVE-2023-39808: Use of Hard-coded Credentials9.8 CriticalN/A1%Aug 21, 2023
CVE-2023-40291: Undefined Security Weakness6.8 MediumN/A0%Aug 14, 2023
CVE-2023-28481: Authorization Bypass Through User-Controlled Key8.8 HighN/A1%Aug 14, 2023
CVE-2023-30702: Out-of-bounds Write6.7 MediumN/A0%Aug 10, 2023
CVE-2023-30695: Out-of-bounds Write6.7 MediumN/A0%Aug 10, 2023
CVE-2023-38951: Improper Limitation of a Pathname to a Restricted Directory9.8 CriticalN/A3%Aug 3, 2023
CVE-2023-3603: NULL Pointer Dereference3.1 LowN/A1%Jul 21, 2023
851-875 of 1969