The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
CVE-2026-76461:Critical Cisco Secure Email Gateway Vulnerability Exploited in the Wild
CVE-2026-85706:Critical GitLab Path Traversal Exploited in the Wild
CVE-2026-83548:Critical SonicWall SMA1000 Vulnerabilities CVE-2026-83548, CVE-2026-83549 Exploited in the Wild
CVE-2026-81578:PaperCut NG/MF Critical Zero-Day Exploited in the Wild
CVE-2026-63520:Rapid7 Analysis: Microsoft SharePoint Remote Code Execution (CVE-2026-63520)
CVE-2026-19490:Critical Vulnerability Affecting Citrix NetScaler ADC and NetScaler Gateway
TitleEitWModules
CVE-2025-55037: Improper Neutralization of Special Elements used in an OS Command9.8 Critical9.3 Critical3%Sep 5, 2025
CVE-2025-41408: Improper Authorization in Handler for Custom URL Scheme4.3 Medium5.3 Medium0%Sep 5, 2025
CVE-2025-58401: Cleartext Storage of Sensitive Information6.8 Medium5.1 Medium0%Sep 5, 2025
CVE-2025-8684: Improper Neutralization of Input During Web Page Generation6.4 MediumN/A0%Sep 5, 2025
CVE-2025-9990: Improper Control of Filename for Include/Require Statement in PHP Program8.1 HighN/A1%Sep 5, 2025
CVE-2025-7445: Insertion of Sensitive Information into Log File6.5 MediumN/A0%Sep 5, 2025
CVE-2025-58362: Use of Incorrectly-Resolved Name or Reference7.5 HighN/A1%Sep 5, 2025
CVE-2025-58359: Missing Cryptographic StepN/A6.0 Medium0%Sep 5, 2025
CVE-2025-58352: Insufficient Session Expiration6.5 Medium2.1 Low0%Sep 5, 2025
CVE-2025-58179: Server-Side Request Forgery (SSRF)7.2 HighN/A1%Sep 5, 2025
CVE-2025-55739: Use of Hard-coded CredentialsN/A5.1 Medium0%Sep 5, 2025
CVE-2025-55305: Improper Control of Generation of Code6.1 MediumN/A0%Sep 4, 2025
CVE-2025-55244: Improper Access Control9.0 CriticalN/A1%Sep 4, 2025
CVE-2025-55242: Exposure of Sensitive Information to an Unauthorized Actor6.5 MediumN/A1%Sep 4, 2025
CVE-2025-55241: Improper Authentication10.0 CriticalN/A2%Sep 4, 2025
CVE-2025-55238: Improper Access Control7.5 HighN/A1%Sep 4, 2025
CVE-2025-55209: Improper Neutralization of Input During Web Page GenerationN/A5.1 Medium0%Sep 4, 2025
CVE-2025-55190: Exposure of Sensitive Information to an Unauthorized Actor9.9 CriticalN/A5%Sep 4, 2025
CVE-2025-54914: Improper Access Control10.0 CriticalN/A2%Sep 4, 2025
CVE-2025-58361: Improper Input Validation9.3 CriticalN/A0%Sep 4, 2025
CVE-2025-58353: Improper Neutralization of Input During Web Page Generation8.2 HighN/A0%Sep 4, 2025
CVE-2025-32322: Improper Input Validation7.8 HighN/A0%Sep 4, 2025
CVE-2025-26439: Protection Mechanism Failure7.8 HighN/A0%Sep 4, 2025
CVE-2025-26431: Protection Mechanism Failure7.8 HighN/A0%Sep 4, 2025
CVE-2025-26419: Authentication Bypass by Spoofing3.3 LowN/A0%Sep 4, 2025
87651-87675 of 691462