The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
CVE-2026-76461:Critical Cisco Secure Email Gateway Vulnerability Exploited in the Wild
CVE-2026-85706:Critical GitLab Path Traversal Exploited in the Wild
CVE-2026-83548:Critical SonicWall SMA1000 Vulnerabilities CVE-2026-83548, CVE-2026-83549 Exploited in the Wild
CVE-2026-81578:PaperCut NG/MF Critical Zero-Day Exploited in the Wild
CVE-2026-63520:Rapid7 Analysis: Microsoft SharePoint Remote Code Execution (CVE-2026-63520)
CVE-2026-19490:Critical Vulnerability Affecting Citrix NetScaler ADC and NetScaler Gateway
TitleEitWModules
CVE-2025-58851: Improper Neutralization of Input During Web Page Generation6.5 MediumN/A0%Sep 5, 2025
CVE-2025-58850: Improper Neutralization of Input During Web Page Generation6.5 MediumN/A0%Sep 5, 2025
CVE-2025-58845: Cross-Site Request Forgery (CSRF)7.1 HighN/A0%Sep 5, 2025
CVE-2025-58843: Cross-Site Request Forgery (CSRF)7.1 HighN/A0%Sep 5, 2025
CVE-2025-58841: Incorrect Privilege Assignment5.5 MediumN/A0%Sep 5, 2025
CVE-2025-58834: Improper Neutralization of Input During Web Page Generation6.5 MediumN/A0%Sep 5, 2025
CVE-2025-58827: Improper Control of Generation of Code3.8 LowN/A0%Sep 5, 2025
CVE-2025-58823: Improper Neutralization of Input During Web Page Generation6.5 MediumN/A0%Sep 5, 2025
CVE-2025-58810: Improper Neutralization of Input During Web Page Generation5.9 MediumN/A0%Sep 5, 2025
CVE-2025-58809: Cross-Site Request Forgery (CSRF)7.1 HighN/A0%Sep 5, 2025
CVE-2025-58797: Exposure of Sensitive System Information to an Unauthorized Control Sphere5.3 MediumN/A0%Sep 5, 2025
CVE-2025-10011: Improper Neutralization of Special Elements used in an SQL Command6.3 Medium2.1 Low1%Sep 5, 2025
CVE-2025-58880: Improper Neutralization of Input During Web Page Generation6.5 MediumN/A0%Sep 5, 2025
CVE-2025-58876: Improper Neutralization of Input During Web Page Generation6.5 MediumN/A0%Sep 5, 2025
CVE-2025-58873: Improper Neutralization of Input During Web Page Generation5.9 MediumN/A0%Sep 5, 2025
CVE-2025-58872: Insertion of Sensitive Information Into Sent Data6.5 MediumN/A0%Sep 5, 2025
CVE-2025-58871: Improper Neutralization of Input During Web Page Generation6.5 MediumN/A0%Sep 5, 2025
CVE-2025-58870: Improper Neutralization of Input During Web Page Generation6.5 MediumN/A0%Sep 5, 2025
CVE-2025-58869: Cross-Site Request Forgery (CSRF)6.5 MediumN/A0%Sep 5, 2025
CVE-2025-58868: Improper Neutralization of Input During Web Page Generation6.5 MediumN/A0%Sep 5, 2025
CVE-2025-58866: Exposure of Sensitive System Information to an Unauthorized Control Sphere2.7 LowN/A0%Sep 5, 2025
CVE-2025-58865: Cross-Site Request Forgery (CSRF)4.3 MediumN/A0%Sep 5, 2025
CVE-2025-58864: Improper Neutralization of Input During Web Page Generation6.5 MediumN/A0%Sep 5, 2025
CVE-2025-58862: Improper Neutralization of Input During Web Page Generation6.5 MediumN/A0%Sep 5, 2025
CVE-2025-58861: Cross-Site Request Forgery (CSRF)7.1 HighN/A0%Sep 5, 2025
87551-87575 of 691462