The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
CVE-2026-76461:Critical Cisco Secure Email Gateway Vulnerability Exploited in the Wild
CVE-2026-85706:Critical GitLab Path Traversal Exploited in the Wild
CVE-2026-83548:Critical SonicWall SMA1000 Vulnerabilities CVE-2026-83548, CVE-2026-83549 Exploited in the Wild
CVE-2026-81578:PaperCut NG/MF Critical Zero-Day Exploited in the Wild
CVE-2026-63520:Rapid7 Analysis: Microsoft SharePoint Remote Code Execution (CVE-2026-63520)
CVE-2026-19490:Critical Vulnerability Affecting Citrix NetScaler ADC and NetScaler Gateway
TitleEitWModules
CVE-2025-9639: Relative Path Traversal7.5 High8.7 High1%Aug 29, 2025
CVE-2025-9619: Improper Control of Resource Identifiers5.3 Medium6.9 Medium0%Aug 29, 2025
CVE-2025-9610: Improper Neutralization of Special Elements used in an SQL Command7.3 High5.5 Medium0%Aug 29, 2025
CVE-2025-9609: Improper Authorization6.3 Medium2.1 Low0%Aug 29, 2025
CVE-2025-8861: Missing Authentication for Critical Function9.8 Critical9.3 Critical1%Aug 29, 2025
CVE-2025-8858: Improper Neutralization of Special Elements used in an SQL Command7.5 High8.7 High0%Aug 29, 2025
CVE-2025-8857: Use of Hard-coded Credentials9.8 Critical9.3 Critical1%Aug 29, 2025
CVE-2025-9608: Improper Neutralization of Special Elements used in an SQL Command6.3 Medium2.1 Low0%Aug 29, 2025
CVE-2025-9607: Improper Neutralization of Special Elements used in an SQL Command6.3 Medium2.1 Low0%Aug 29, 2025
CVE-2025-9606: Improper Neutralization of Special Elements used in an SQL Command8.8 High2.1 Low0%Aug 29, 2025
CVE-2025-9605: Stack-based Buffer Overflow9.8 Critical8.9 High5%Aug 29, 2025
CVE-2025-58333: Undefined Security WeaknessN/AN/AN/AAug 29, 2025
CVE-2025-58332: Undefined Security WeaknessN/AN/AN/AAug 29, 2025
CVE-2025-58331: Undefined Security WeaknessN/AN/AN/AAug 29, 2025
CVE-2025-58330: Undefined Security WeaknessN/AN/AN/AAug 29, 2025
CVE-2025-58329: Undefined Security WeaknessN/AN/AN/AAug 29, 2025
CVE-2025-58328: Undefined Security WeaknessN/AN/AN/AAug 29, 2025
CVE-2025-58327: Undefined Security WeaknessN/AN/AN/AAug 29, 2025
CVE-2025-58326: Undefined Security WeaknessN/AN/AN/AAug 29, 2025
CVE-2025-58323: Incorrect Privilege Assignment7.7 HighN/A0%Aug 29, 2025
CVE-2025-39247: Improper Access Control8.6 HighN/A0%Aug 29, 2025
CVE-2025-39246: Unquoted Search Path or Element5.3 MediumN/A0%Aug 29, 2025
CVE-2025-39245: Improper Neutralization of Formula Elements in a CSV File4.7 MediumN/A0%Aug 29, 2025
CVE-2025-9604: Use of Hard-coded Cryptographic Key3.7 Low6.3 Medium0%Aug 29, 2025
CVE-2025-9603: Improper Neutralization of Special Elements used in a Command6.3 Medium2.1 Low8%Aug 29, 2025
88326-88350 of 694552