The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
CVE-2026-63520:Rapid7 Analysis: Microsoft SharePoint Remote Code Execution (CVE-2026-63520)
CVE-2026-19490:Critical Vulnerability Affecting Citrix NetScaler ADC and NetScaler Gateway
CVE-2026-63520:Microsoft SharePoint Remote Code Execution (FIXED)
CVE-2026-55040:Rapid7 Analysis: Microsoft SharePoint JWT Token Authentication Bypass (CVE-2026-55040)
CVE-2026-63077:Rapid7 Analysis: Unauthenticated Remote Code Execution in JetBrains TeamCity (CVE-2026-63077)
CVE-2026-18577:N-able N-central Authentication Bypass Exploited in the Wild
TitleEitWModules
CVE-2025-4524: Improper Limitation of a Pathname to a Restricted Directory9.8 CriticalN/A1%May 21, 2025
CVE-2021-25262: Improper Encoding or Escaping of Output5.4 Medium6.9 Medium0%May 21, 2025
CVE-2021-25255: Improper Input Validation7.5 High8.3 High0%May 21, 2025
CVE-2021-25254: Improper Encoding or Escaping of Output5.3 Medium8.2 High0%May 21, 2025
CVE-2025-5013: Improper Neutralization of Input During Web Page Generation4.3 Medium5.3 Medium0%May 21, 2025
CVE-2025-4969: Out-of-bounds Read6.5 MediumN/A1%May 21, 2025
CVE-2025-4094: Undefined Security Weakness9.8 CriticalN/A2%May 21, 2025
CVE-2025-48427: Undefined Security WeaknessN/AN/AN/AMay 21, 2025
CVE-2025-48426: Undefined Security WeaknessN/AN/AN/AMay 21, 2025
CVE-2025-48425: Undefined Security WeaknessN/AN/AN/AMay 21, 2025
CVE-2025-48424: Undefined Security WeaknessN/AN/AN/AMay 21, 2025
CVE-2025-48423: Undefined Security WeaknessN/AN/AN/AMay 21, 2025
CVE-2025-48422: Undefined Security WeaknessN/AN/AN/AMay 21, 2025
CVE-2025-48421: Undefined Security WeaknessN/AN/AN/AMay 21, 2025
CVE-2025-48420: Undefined Security WeaknessN/AN/AN/AMay 21, 2025
CVE-2025-48419: Undefined Security WeaknessN/AN/AN/AMay 21, 2025
CVE-2025-5011: Improper Neutralization of Input During Web Page Generation2.4 Low4.8 Medium0%May 21, 2025
CVE-2025-5010: Improper Neutralization of Input During Web Page Generation2.4 Low4.8 Medium0%May 21, 2025
CVE-2025-5008: Improper Neutralization of Special Elements used in an SQL Command7.3 High6.9 Medium0%May 20, 2025
CVE-2025-5007: Improper Neutralization of Input During Web Page Generation3.5 Low5.1 Medium0%May 20, 2025
CVE-2025-5006: Improper Neutralization of Special Elements used in an SQL Command7.3 High6.9 Medium0%May 20, 2025
CVE-2025-5004: Improper Neutralization of Special Elements used in an SQL Command7.3 High6.9 Medium0%May 20, 2025
CVE-2025-4436: Undefined Security WeaknessN/AN/AN/AMay 20, 2025
CVE-2025-5003: Improper Neutralization of Special Elements used in an SQL Command7.3 High6.9 Medium0%May 20, 2025
CVE-2025-5002: Improper Neutralization of Special Elements used in an SQL Command7.3 High6.9 Medium0%May 20, 2025
89001-89025 of 383656