The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
CVE-2026-76461:Critical Cisco Secure Email Gateway Vulnerability Exploited in the Wild
CVE-2026-85706:Critical GitLab Path Traversal Exploited in the Wild
CVE-2026-83548:Critical SonicWall SMA1000 Vulnerabilities CVE-2026-83548, CVE-2026-83549 Exploited in the Wild
CVE-2026-81578:PaperCut NG/MF Critical Zero-Day Exploited in the Wild
CVE-2026-63520:Rapid7 Analysis: Microsoft SharePoint Remote Code Execution (CVE-2026-63520)
CVE-2026-19490:Critical Vulnerability Affecting Citrix NetScaler ADC and NetScaler Gateway
TitleEitWModules
CVE-2025-58421: Undefined Security WeaknessN/AN/AN/ASep 2, 2025
CVE-2025-58420: Undefined Security WeaknessN/AN/AN/ASep 2, 2025
CVE-2025-58419: Undefined Security WeaknessN/AN/AN/ASep 2, 2025
CVE-2025-58418: Undefined Security WeaknessN/AN/AN/ASep 2, 2025
CVE-2025-58417: Undefined Security WeaknessN/AN/AN/ASep 2, 2025
CVE-2025-58416: Undefined Security WeaknessN/AN/AN/ASep 2, 2025
CVE-2025-58415: Undefined Security WeaknessN/AN/AN/ASep 2, 2025
CVE-2025-58414: Undefined Security WeaknessN/AN/AN/ASep 2, 2025
CVE-2025-9806: Use of Hard-coded Credentials1.9 Low0.9 Low0%Sep 2, 2025
CVE-2025-9805: Server-Side Request Forgery (SSRF)6.3 Medium2.1 Low0%Sep 2, 2025
CVE-2025-58178: Improper Neutralization of Special Elements used in a Command7.8 HighN/A1%Sep 2, 2025
CVE-2025-58162: Improper Limitation of a Pathname to a Restricted Directory6.5 MediumN/A1%Sep 2, 2025
CVE-2025-58161: Improper Limitation of a Pathname to a Restricted Directory4.3 Medium1.3 Low1%Sep 2, 2025
CVE-2025-57808: Incorrect Implementation of Authentication Algorithm8.1 HighN/A2%Sep 2, 2025
CVE-2025-9802: Improper Neutralization of Special Elements used in an SQL Command4.7 Medium5.1 Medium0%Sep 2, 2025
CVE-2025-9801: Improper Limitation of a Pathname to a Restricted Directory5.4 Medium2.1 Low1%Sep 1, 2025
CVE-2025-9800: Unrestricted Upload of File with Dangerous Type6.3 Medium2.1 Low0%Sep 1, 2025
CVE-2025-9799: Server-Side Request Forgery (SSRF)5.0 Medium1.3 Low0%Sep 1, 2025
CVE-2025-9797: Improper Neutralization of Special Elements in Output Used by a Downstream Component2.4 Low1.9 Low0%Sep 1, 2025
CVE-2025-9796: Improper Neutralization of Input During Web Page Generation3.5 Low2.0 Low0%Sep 1, 2025
CVE-2024-28988: Deserialization of Untrusted Data9.8 CriticalN/A39%Sep 1, 2025
CVE-2025-9795: Unrestricted Upload of File with Dangerous Type6.3 Medium2.1 Low0%Sep 1, 2025
CVE-2025-9794: Improper Neutralization of Special Elements used in an SQL Command7.3 High5.5 Medium0%Sep 1, 2025
CVE-2025-9793: Improper Neutralization of Special Elements used in an SQL Command7.3 High5.5 Medium0%Sep 1, 2025
CVE-2025-9792: Improper Neutralization of Special Elements used in an SQL Command7.3 High5.5 Medium0%Sep 1, 2025
88026-88050 of 398946