The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
CVE-2026-76461:Critical Cisco Secure Email Gateway Vulnerability Exploited in the Wild
CVE-2026-85706:Critical GitLab Path Traversal Exploited in the Wild
CVE-2026-83548:Critical SonicWall SMA1000 Vulnerabilities CVE-2026-83548, CVE-2026-83549 Exploited in the Wild
CVE-2026-81578:PaperCut NG/MF Critical Zero-Day Exploited in the Wild
CVE-2026-63520:Rapid7 Analysis: Microsoft SharePoint Remote Code Execution (CVE-2026-63520)
CVE-2026-19490:Critical Vulnerability Affecting Citrix NetScaler ADC and NetScaler Gateway
TitleEitWModules
CVE-2025-39683: Out-of-bounds Read7.8 HighN/A0%Sep 5, 2025
CVE-2025-39681: Undefined Security WeaknessN/AN/A0%Sep 5, 2025
CVE-2025-39680: Out-of-bounds Read7.8 HighN/A0%Sep 5, 2025
CVE-2025-39679: Missing Release of Memory after Effective Lifetime5.5 MediumN/A0%Sep 5, 2025
CVE-2025-39678: NULL Pointer Dereference5.5 MediumN/A0%Sep 5, 2025
CVE-2025-39677: Undefined Security Weakness7.8 HighN/A0%Sep 5, 2025
CVE-2025-39674: NULL Pointer Dereference5.5 MediumN/A0%Sep 5, 2025
CVE-2025-39673: Concurrent Execution using Shared Resource with Improper Synchronization9.8 CriticalN/A0%Sep 5, 2025
CVE-2025-38737: Use of Uninitialized Resource9.8 CriticalN/A0%Sep 5, 2025
CVE-2025-38736: Out-of-bounds ReadN/AN/A0%Sep 5, 2025
CVE-2025-38735: NULL Pointer Dereference7.8 HighN/A0%Sep 5, 2025
CVE-2025-38734: Use After Free9.8 CriticalN/A0%Sep 5, 2025
CVE-2025-38733: NULL Pointer Dereference7.8 HighN/A0%Sep 5, 2025
CVE-2025-38732: Undefined Security WeaknessN/AN/A0%Sep 5, 2025
CVE-2025-38731: Double Free7.8 HighN/A0%Sep 5, 2025
CVE-2025-9999: Improper Verification of Source of a Communication ChannelN/A7.6 High0%Sep 5, 2025
CVE-2025-9998: Improper Check for Unusual or Exceptional ConditionsN/A6.0 Medium0%Sep 5, 2025
CVE-2025-58628: Improper Neutralization of Special Elements used in an SQL Command9.3 CriticalN/A0%Sep 5, 2025
CVE-2025-58440: Undefined Security WeaknessN/AN/AN/ASep 5, 2025
CVE-2025-54744: Missing Authorization6.5 MediumN/A0%Sep 5, 2025
CVE-2025-53571: Missing Authorization6.5 MediumN/A0%Sep 5, 2025
CVE-2025-53307: Improper Neutralization of Input During Web Page Generation7.1 HighN/A0%Sep 5, 2025
CVE-2025-49401: Incorrect Privilege Assignment9.8 CriticalN/A0%Sep 5, 2025
CVE-2025-48317: Path Traversal: '.../...//'7.5 HighN/A0%Sep 5, 2025
CVE-2025-48105: Improper Neutralization of Input During Web Page Generation6.5 MediumN/A0%Sep 5, 2025
87501-87525 of 691462